--------[ AIDA64 Extreme ]----------------------------------------------------------------------------------------------

                                                AIDA64 v4.60.3100/ru
                                        4.1.611-x64
                                      http://www.aida64.com/
                                              
                                             BLACK_SOKOL
                                             Black_SOKOL
                                   Microsoft Windows 8.1 Professional 6.3.9600.17238 (Win8.1 RTM)
                                                  2014-08-17
                                                 23:23


--------[   ]----------------------------------------------------------------------------------------

    :
                                           ACPI    x64  (Mobile)
                                     Microsoft Windows 8.1 Professional
                                       -
      Internet Explorer                                 11.0.9600.17239
      DirectX                                           DirectX 11.2
                                           BLACK_SOKOL
                                         Black_SOKOL
                                              BLACK_SOKOL
       /                                       2014-08-17 / 23:23

     :
                                                   Mobile QuadCore AMD A6-3400M, 2300 MHz (23 x 100)
                                          Toshiba Satellite L755D
                                    AMD A60M, AMD K12
                                         3558   (DDR3-1333 DDR3 SDRAM)
      DIMM1: Samsung M471B5773DH0-CH9                   2  DDR3-1333 DDR3 SDRAM  (9-9-9-24 @ 666 )  (8-8-8-22 @ 609 )  (7-7-7-20 @ 533 )  (6-6-6-17 @ 457 )  (5-5-5-14 @ 380 )
      DIMM2: Samsung M471B5773DH0-CH9                   2  DDR3-1333 DDR3 SDRAM  (9-9-9-24 @ 666 )  (8-8-8-22 @ 609 )  (7-7-7-20 @ 533 )  (6-6-6-17 @ 457 )  (5-5-5-14 @ 380 )
       BIOS                                          Insyde (06/28/2012)
                                    LGE Bluetooth TransPort (COM3)

    :
                                            AMD Radeon HD 6520G  (512 )
                                            AMD Radeon HD 6520G  (512 )
      3D-                                    AMD Radeon HD 6450M/6470M/6490M (Seymour)
      3D-                                    AMD Radeon HD 6520G (Sumo)
                                                 LG Philips LP156WH4-TLA1  [15.6" LCD]

    :
                                         ATI Radeon HDMI @ AMD K12 - High Definition Audio Controller
                                         Conexant Cx20585 @ AMD Hudson-2 FCH - High Definition Audio Controller

     :
       IDE                                    AMD SATA Controller
                                   ()
                                      WDC WD5000BPKX-22HPJT0  (500 , 7200 RPM, SATA-III)
                                    DTSOFT Virtual CdRom Device
                                    TSSTcorp CDDVDW TS-L633F
      SMART-                         OK

    :
      C: (NTFS)                                         199.7  (104.7  )
      E: (NTFS)                                         265.8  (59.1  )
                                              465.4  (163.8  )

    :
                                                PS/2
                                                    HID- 
                                                    Synaptics PS/2 Port Compatible TouchPad

    :
        IP                                192.168.1.136
        MAC                               D0-DF-9A-66-47-2C
                                          Qualcomm Atheros AR8152 PCI-E Fast Ethernet Controller (NDIS 6.30)
                                          Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC  (192.168.1.136)
                                            Wi-Fi Direct ()
                                                   LGE Virtual Modem

     :
                                                 Fax
                                                 HP ePrint
                                                 HP LaserJet Professional CP1020 Series
                                                 Microsoft XPS Document Writer
                                                 NPIA72351 (HP LaserJet CP1025nw)
                                                   OneNote 2013
       USB1                                   AMD Hudson-2 FCH - USB OHCI Controller
       USB1                                   AMD Hudson-2 FCH - USB OHCI Controller
       USB1                                   AMD Hudson-2 FCH - USB OHCI Controller
       USB1                                   AMD Hudson-2 FCH - USB OHCI Controller
       USB2                                   AMD Hudson-2 FCH - USB 2.0 EHCI Controller
       USB2                                   AMD Hudson-2 FCH - USB 2.0 EHCI Controller
       USB2                                   AMD Hudson-2 FCH - USB 2.0 EHCI Controller
      USB-                                    Realtek USB 2.0 Card Reader
      USB-                                    TOSHIBA Web Camera - MP
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                     USB 
      USB-                                     USB 
                                                    ()
                                                   ACPI-  ()

    DMI:
      DMI  BIOS                                Insyde Corp.
      DMI  BIOS                                   2.10
      DMI                           TOSHIBA
      DMI                                        SATELLITE L755D
      DMI                                PSK36E-00E00MRU
      DMI                         7B323046W
      DMI  UUID                                A01F4CAC-68B1E011-91D2E89A-8F7F95FA
      DMI                    AMD
      DMI                                 Torpedo
      DMI                           Base Board Version
      DMI                    Base Board Serial Number
      DMI                             AMD
      DMI                                    None
      DMI                             None
      DMI Asset-                                No Asset Tag
      DMI                                       Notebook
      DMI  /                 2 / 0


--------[   ]----------------------------------------------------------------------------------------------

          
     NetBIOS                 BLACK_SOKOL
      DNS               Black_SOKOL
      DNS              
      DNS              Black_SOKOL
     NetBIOS                 BLACK_SOKOL
      DNS               Black_SOKOL
      DNS              
      DNS              Black_SOKOL


--------[ DMI ]---------------------------------------------------------------------------------------------------------

  [ BIOS ]

     BIOS:
                                           Insyde Corp.
                                                  2.10
                                             06/28/2012
                                                  2 
       BIOS                                2.10
                    1.80
                                   Floppy Disk, Hard Disk, CD-ROM
                                             Flash BIOS, Shadow BIOS, Selectable Boot, EDD
                                 DMI, ACPI, UEFI
                                   PCI, USB
                                       

     BIOS:
                                                   Insyde Software Corp.
                                     http://www.insydesw.com/products
       BIOS                                 http://www.aida64.com/bios-updates

  [  ]

     :
                                           TOSHIBA
                                                 SATELLITE L755D
                                                  PSK36E-00E00MRU
                                           7B323046W
      SKU#                                              PSK36E-00E00MRU
                                               Type1Family
        ID                       A01F4CAC-68B1E011-91D2E89A-8F7F95FA
                                           

  [   ]

      :
                                           AMD
                                                 Torpedo
                                                  Base Board Version
                                           Base Board Serial Number
                                            Base Board Asset Tag

  [  ]

     :
                                           AMD
                                                  
                                           
                                            No Asset Tag
                                                Notebook
                                     
                               
                                  
                                   

  [   ]

      :
                                  
                                         Single-bit
                              1-Way
                                1-Way
                             70ns, 60ns, 50ns
                                SPM, EDO, Parity, SIMM, DIMM, BEDO
                   5V, 3.3V
                           8192 
                                           2

  [  / AMD A6-3400M APU with Radeon(tm) HD Graphics ]

     :
                                           AMD processor
                                                  AMD A6-3400M APU with Radeon(tm) HD Graphics
                                           NotSupport
                                            FFFF
                                          100 
                                     1400 
                                          1400 
                                                     Central Processor
                                       1.0 V
                                                  
                                               Socket FS1
                                              Socket FS1
      HTT / CMP                                         1 / 4
                                             64-bit

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/processors
                                     http://www.aida64.com/driver-updates

  [ - / L1 Cache ]

     :
                                                     
                                                1 ns
                                                  
                                             Write-Back
                                         2-way Set-Associative
                                       512 
                                      512 
        SRAM                           Pipeline Burst
        SRAM                                  Pipeline Burst
                                         Multi-bit ECC
                                               L1

  [ - / L2 Cache ]

     :
                                                     
                                                1 ns
                                                  
                                             Write-Back
                                         16-way Set-Associative
                                       4096 
                                      4096 
        SRAM                           Pipeline Burst
        SRAM                                  Pipeline Burst
                                         Multi-bit ECC
                                               L2

  [   / System Memory ]

      :
                                               
                                     
                                         
      .                                  4 
                                        2

  [   / DIMM0 ]

      :
                                              DIMM0
                                                     FPM, DIMM
                                      2048 
                                         2048 

  [   / DIMM1 ]

      :
                                              DIMM1
                                                     SPM, FPM, DIMM
                                      2048 
                                         2048 

  [   / DIMM0 ]

      :
      -                                       SODIMM
                                                     DDR3
                                                     Synchronous
                                                  2 
      .                                      1334 
                                          1334 
                                             64 
                                            8 
      Ranks                                             1
                                              DIMM0
                                                    BANK0
                                           Samsung
                                           00500606
                                            
                                          M471B5773DH0-CH9

  [   / DIMM1 ]

      :
      -                                       SODIMM
                                                     DDR3
                                                     Synchronous
                                                  2 
      .                                      1334 
                                          1334 
                                             64 
                                            8 
      Ranks                                             1
                                              DIMM1
                                                    BANK0
                                           Samsung
                                           00500605
                                            
                                          M471B5773DH0-CH9

  [   / J6C1 ]

      :
                                       J6C1
                                                     PCI-E x16
                                           
                                        x16
                                                   

  [   / J8C1 ]

      :
                                       J8C1
                                                     PCI-E x1
                                           
                                        x1
                                                   

  [   / J7C1 ]

      :
                                       J7C1
                                                     PCI-E x1
                                           
                                        x1
                                                   

  [   / J8D1 ]

      :
                                       J8D1
                                                     PCI-E x1
                                           
                                        x1
                                                   

  [   / J8B1 ]

      :
                                       J8B1
                                                     PCI
                                           
                                        32-bit
                                                   

  [   / Keyboard ]

      :
                                                Keyboard Port
                                   J1A1
                                    
                                      
                                       PS/2

  [   / Mouse ]

      :
                                                Mouse Port
                                   J1A1
                                    
                                      
                                       PS/2

  [   / COM 1 ]

      :
                                                Serial Port 16550A Compatible
                                   J2A2
                                    
                                      COM 1
                                       DB-9 pin male

  [   / USB ]

      :
                                                USB
                                   J3A1
                                    
                                      USB
                                       USB

  [   / USB ]

      :
                                                USB
                                   J3A1
                                    
                                      USB
                                       USB

  [   / USB ]

      :
                                                USB
                                   J3A1
                                    
                                      USB
                                       USB

  [   / USB ]

      :
                                                USB
                                   J5A1
                                    
                                      USB
                                       USB

  [   / USB ]

      :
                                                USB
                                   J5A1
                                    
                                      USB
                                       USB

  [   / Network ]

      :
                                                Network Port
                                   J5A1
                                    
                                      
                                       RJ-45

  [   / OnBoard Floppy Type ]

      :
                                   J9G2
                                    On-Board Floppy
                                      OnBoard Floppy Type
                                       

  [   / OnBoard Primary IDE ]

      :
                                   J7J1
                                    On-Board IDE
                                      OnBoard Primary IDE
                                       

  [   / TV OUT ]

      :
                                                Video Port
                                   J2A1
                                    
                                      TV OUT
                                       Mini-DIN

  [   / CRT ]

      :
                                                Video Port
                                   J2A2
                                    
                                      CRT
                                       DB-15 pin female

  [   / Microphone In ]

      :
                                                Audio Port
                                   J30
                                    
                                      Microphone In
                                       Mini-jack (headphones)

  [   / Line In ]

      :
                                                Audio Port
                                   J30
                                    
                                      Line In
                                       Mini-jack (headphones)

  [   / Speaker Out ]

      :
                                                Audio Port
                                   J30
                                    
                                      Speaker Out
                                       Mini-jack (headphones)

  [   / Touch Pad ]

     :
                                           Touch Pad
                                               PS/2
                                             4

  [   / 82567LM Gigabit Network Connection ]

      :
                                                82567LM Gigabit Network Connection
                                                     Ethernet
                                                  
       /  /                        0 / 0 / 1

  [   / Voltage Probe Description. ]

     :
                                      Voltage Probe Description.

  [  ]

    :
      OEM String                                        SSK3600E00MRU,R15743RU
      OEM String                                        TEZUG9qUkwZou
      OEM String                                        zLabdpLBrgdEP
      OEM String                                        -U3cBSU1nTYsE
      System Configuration Option                       NVR:00707902
      System Configuration Option                       DSN: WD-WXH1E93WLD88
      System Configuration Option                       DSN:M471B5773DH0-CH9 00500606
      System Configuration Option                       DSN:PANASONIC03DD2011/05/07


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   Mobile QuadCore AMD A6-3400M
                                             Llano
                                              LN-B0
      Engineering Sample                                
        CPUID                                      AMD A6-3400M APU with Radeon(tm) HD Graphics
       CPUID                                      00300F10h
      CPU VID                                           1.0125 V
        VID                                 0.9875 V

     :
                                               1397.1 MHz  (: 1400 MHz)
                                             14x
      CPU FSB                                           99.8 MHz  (: 100 MHz)
                                   665.3 MHz
                                              665.3 MHz
       DRAM:FSB                              20:3

     :
       L1                                        64  per core
       L1                                      64  per core
       L2                                            1  per core  (On-Die, ECC, Full-Speed)

      :
      ID                                  <DMI>
                                          Toshiba Satellite L755D

       ():
                                    AMD A60M, AMD K12
                                          9-9-9-24  (CL-RCD-RP-RAS)
      Command Rate (CR)                                 1T
      DIMM1: Samsung M471B5773DH0-CH9                   2  DDR3-1333 DDR3 SDRAM  (9-9-9-24 @ 666 )  (8-8-8-22 @ 609 )  (7-7-7-20 @ 533 )  (6-6-6-17 @ 457 )  (5-5-5-14 @ 380 )
      DIMM2: Samsung M471B5773DH0-CH9                   2  DDR3-1333 DDR3 SDRAM  (9-9-9-24 @ 666 )  (8-8-8-22 @ 609 )  (7-7-7-20 @ 533 )  (6-6-6-17 @ 457 )  (5-5-5-14 @ 380 )

     BIOS:
       BIOS                                  06/28/2012
       BIOS                            05/10/11
      DMI  BIOS                                   2.10

      :
                                            AMD Radeon HD 6520G (Sumo)
                                       Sumo (BeaverCreek)  (Integrated 1002 / 9647, Rev 00)
                                               278   (original: 400 MHz)


--------[  ]----------------------------------------------------------------------------------------------

     :
                                  
                                        100 % ( )
                              
                          

     :
                                           PA3817U-1BRS
                                           Panasonic
                                           989
                                           989PanasonicPA3817U-1BRS
                                               Li-Ion
                                       54947 mWh
                                 27386 mWh
                                          27386 mWh  (100 %)
                                       12.488 V
                                     50 %
                                               


--------[   ]----------------------------------------------------------------------------------------------

    Centrino (Carmel)  :
      : Intel Pentium M (Banias/Dothan)                 (Mobile AMD A6-3400M)
      : Intel i855GM/PM                             (AMD A60M, AMD K12)
      WLAN: Intel PRO/Wireless                          
      : Centrino-                     

    Centrino (Sonoma)  :
      : Intel Pentium M (Dothan)                        (Mobile AMD A6-3400M)
      : Intel i915GM/PM                             (AMD A60M, AMD K12)
      WLAN: Intel PRO/Wireless 2200/2915                
      : Centrino-                     

    Centrino (Napa)  :
      : Intel Core (Yonah) / Core 2 (Merom)             (Mobile AMD A6-3400M)
      : Intel i945GM/PM                             (AMD A60M, AMD K12)
      WLAN: Intel PRO/Wireless 3945/3965                
      : Centrino-                     

    Centrino (Santa Rosa)  :
      : Intel Core 2 (Merom/Penryn)                     (Mobile AMD A6-3400M)
      : Intel GM965/PM965                           (AMD A60M, AMD K12)
      WLAN: Intel Wireless WiFi Link 4965               
      : Centrino-                     

    Centrino 2 (Montevina)  :
      : Intel Core 2 (Penryn)                           (Mobile AMD A6-3400M)
      : Mobile Intel 4 Series                       (AMD A60M, AMD K12)
      WLAN: Intel WiFi Link 5000 Series                 
      : Centrino 2-                   

    Centrino (Calpella)  :
      : Intel Core i3/i5/i7 (Arrandale/Clarksfield)     (Mobile AMD A6-3400M)
      : Mobile Intel 5 Series                       (AMD A60M, AMD K12)
      WLAN: Intel Centrino Advanced-N / Ultimate-N / Wireless-N
      : Centrino-                     

    Centrino (Huron River)  :
      : Intel Core i3/i5/i7 (Sandy Bridge-MB)           (Mobile AMD A6-3400M)
      : Mobile Intel 6 Series                       (AMD A60M, AMD K12)
      WLAN: Intel Centrino Advanced-N / Ultimate-N / Wireless-N
      : Centrino-                     

    Centrino (Chief River)  :
      : Intel Core i3/i5/i7 (Ivy Bridge-MB)             (Mobile AMD A6-3400M)
      : Mobile Intel 7 Series                       (AMD A60M, AMD K12)
      WLAN: Intel Centrino Advanced-N / Ultimate-N / Wireless-N
      : Centrino-                     

    Centrino (Shark Bay-MB)  :
      : Intel Core i3/i5/i7 (Haswell-MB)                (Mobile AMD A6-3400M)
      : Mobile Intel 8/9 Series                     (AMD A60M, AMD K12)
      WLAN: Intel Centrino Advanced-N / Ultimate-N / Wireless-N
      : Centrino-                     


--------[  ]-----------------------------------------------------------------------------------------------------

     :
                                              CPU, HDD, ACPI, TVALZ
                                            Diode  (ATI-Diode)

    :
                                                      65 C  (149 F)
       1 /  1                                     67 C  (153 F)
       1 /  2                                     67 C  (153 F)
       1 /  3                                     67 C  (153 F)
       1 /  4                                     67 C  (153 F)
                                                  65 C  (149 F)
      WDC WD5000BPKX-22HPJT0                            41 C  (106 F)

    :
                                                      3498 RPM  (83%)

    :
                                                  1.012 V
                                                 12.488 V
                                                  0.888 V

     :
                                  


--------[  ]----------------------------------------------------------------------------------------------------------

     :
                                                   Mobile QuadCore AMD A6-3400M, 2300 MHz (23 x 100)
                                             Llano
                                              LN-B0
                                        x86, x86-64, MMX, 3DNow!, SSE, SSE2, SSE3, SSE4A
                                         1400 
      ./.                             4x / 40x
      Engineering Sample                                
       L1                                        64  per core
       L1                                      64  per core
       L2                                            1  per core  (On-Die, ECC, Full-Speed)

       :
                                              722 Pin uOPGA
                                          35 mm x 35 mm
                                       1178 .
                                  11Mi, 32 nm CMOS, Cu, HKMG, SOI, Immersion Lithography
                                         228 mm2
                                   0.450 - 1.275 V

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/processors
                                     http://www.aida64.com/driver-updates

    Multi CPU:
      ID                                  Insyde Sabine
      CPU #1                                            AMD A6-3400M APU with Radeon(tm) HD Graphics, 1397 
      CPU #2                                            AMD A6-3400M APU with Radeon(tm) HD Graphics, 1397 
      CPU #3                                            AMD A6-3400M APU with Radeon(tm) HD Graphics, 1397 
      CPU #4                                            AMD A6-3400M APU with Radeon(tm) HD Graphics, 1397 

     :
       1 /  1                                     66%
       1 /  2                                     0%
       1 /  3                                     100%
       1 /  4                                     33%


--------[ CPUID ]-------------------------------------------------------------------------------------------------------

     CPUID:
       CPUID                               AuthenticAMD
        CPUID                                      AMD A6-3400M APU with Radeon(tm) HD Graphics
       CPUID                                      00300F10h
        CPUID                          00300F10h
       AMD                                 1811h  (A6-3400M)
                                  E0h  (Socket FS1r1)
                               03000027h
      HTT / CMP                                         0 / 4
      HTC Temperature Limit (TctlMax)                   115 C  (239 F)

     :
      64- x86- (AMD64, Intel64)            
      AMD 3DNow!                                        
      AMD 3DNow! Professional                           
      AMD 3DNowPrefetch                                 
      AMD Enhanced 3DNow!                               
      AMD Extended MMX                                  
      AMD FMA4                                           
      AMD MisAligned SSE                                
      AMD SSE4A                                         
      AMD XOP                                            
      Cyrix Extended MMX                                 
      Enhanced REP MOVSB/STOSB                           
      Float-16 Conversion Instructions                   
      IA-64                                              
      IA AES Extensions                                  
      IA AVX                                             
      IA AVX2                                            
      IA AVX-512                                         
      IA AVX-512 Conflict Detection Instructions         
      IA AVX-512 Exponential and Reciprocal Instructions 
      IA AVX-512 Prefetch Instructions                   
      IA BMI1                                            
      IA BMI2                                            
      IA FMA                                             
      IA MMX                                            
      IA SHA Extensions                                  
      IA SSE                                            
      IA SSE2                                           
      IA SSE3                                           
      IA Supplemental SSE3                               
      IA SSE4.1                                          
      IA SSE4.2                                          
      VIA Alternate Instruction Set                      
       ADCX / ADOX                             
       CLFLUSH                                
       CLFLUSHOPT                              
       CMPXCHG8B                              
       CMPXCHG16B                             
       Conditional Move                       
       INVPCID                                 
       LAHF / SAHF                            
       LZCNT                                  
       MONITOR / MWAIT                        
       MONITORX / MWAITX                       
       MOVBE                                   
       PCLMULQDQ                               
       POPCNT                                 
       PREFETCHWT1                             
       RDFSBASE / RDGSBASE / WRFSBASE / WRGSBASE 
       RDRAND                                  
       RDSEED                                  
       RDTSCP                                 
       SKINIT / STGI                          
       SYSCALL / SYSRET                       
       SYSENTER / SYSEXIT                     
      Trailing Bit Manipulation Instructions             
       VIA FEMMS                               

     :
      Advanced Cryptography Engine (ACE)                 
      Advanced Cryptography Engine 2 (ACE2)              
         (DEP, NX, EDB)           
      Hardware Random Number Generator (RNG)             
      Hardware Random Number Generator 2 (RNG2)          
      Memory Protection Extensions (MPX)                 
      PadLock Hash Engine (PHE)                          
      PadLock Hash Engine 2 (PHE2)                       
      PadLock Montgomery Multiplier (PMM)                
      PadLock Montgomery Multiplier 2 (PMM2)             
         (PSN)                    
      Safer Mode Extensions (SMX)                        
      Software Guard Extensions (SGX)                    
      Supervisor Mode Access Prevention (SMAP)           
      Supervisor Mode Execution Protection (SMEP)        

     :
      Application Power Management (APM)                 
      Automatic Clock Control                            
      Core C6 State (CC6)                               , 
      Digital Thermometer                               
      Dynamic FSB Frequency Switching                    
      Enhanced Halt State (C1E)                          
      Enhanced SpeedStep Technology (EIST, ESS)          
      Frequency ID Control                               
      Hardware P-State Control                          
      Hardware Thermal Control (HTC)                    , 
      LongRun                                            
      LongRun Table Interface                            
      Overstress                                         
      Package C6 State (PC6)                            , 
      Parallax                                           
      PowerSaver 1.0                                     
      PowerSaver 2.0                                     
      PowerSaver 3.0                                     
      Processor Duty Cycle Control                       
      Software Thermal Control                          
                                               
      Thermal Monitor 1                                  
      Thermal Monitor 2                                  
      Thermal Monitor 3                                  
      Thermal Monitoring                                
      Thermal Trip                                      
      Voltage ID Control                                 

     :
      Extended Page Table (EPT)                          
      Hypervisor                                        
       INVEPT                                  
       INVVPID                                 
      Nested Paging (NPT, RVI)                          
      Secure Virtual Machine (SVM, Pacifica)            
      Virtual Machine Extensions (VMX, Vanderpool)       
      Virtual Processor ID (VPID)                        

     CPUID:
      1 GB Page Size                                    
      36-bit Page Size Extension                        
      64-bit DS Area                                     
      Adaptive Overclocking                              
      Address Region Registers (ARR)                     
      Configurable TDP (cTDP)                            
      Core Performance Boost (CPB)                      , 
      Core Performance Counters                          
      CPL Qualified Debug Store                          
      Data Breakpoint Extension                          
      Debug Trace Store                                  
      Debugging Extension                               
      Deprecated FPU CS and FPU DS                       
      Direct Cache Access                                
      Dynamic Acceleration Technology (IDA)              
      Dynamic Configurable TDP (DcTDP)                   
      Extended APIC Register Space                      
      Fast Save & Restore                               
      Hardware Lock Elision (HLE)                        
      Hybrid Boost                                       
      Hyper-Threading Technology (HTT)                   
      Instruction Based Sampling                        
      Invariant Time Stamp Counter                      
      L1 Context ID                                      
      L2I Performance Counters                           
      Lightweight Profiling                              
      Local APIC On Chip                                
      Machine Check Architecture (MCA)                  
      Machine Check Exception (MCE)                     
      Memory Configuration Registers (MCR)               
      Memory Type Range Registers (MTRR)                
      Model Specific Registers (MSR)                    
      NB Performance Counters                            
      Page Attribute Table (PAT)                        
      Page Global Extension                             
      Page Size Extension (PSE)                         
      Pending Break Event (PBE)                          
      Performance Time Stamp Counter (PTSC)              
      Physical Address Extension (PAE)                  
      Platform Quality of Service Enforcement (PQE)      
      Platform Quality of Service Monitoring (PQM)       
      Process Context Identifiers (PCID)                 
      Processor Feedback Interface                       
      Processor Trace (PT)                               
      Restricted Transactional Memory (RTM)              
      Self-Snoop                                         
      Time Stamp Counter (TSC)                          
      Turbo Boost                                        
      Virtual Mode Extension                            
      Watchdog Timer                                    
      x2APIC                                             
      XGETBV / XSETBV OS Enabled                         
      XSAVE / XRSTOR / XSETBV / XGETBV Extended States   
      XSAVEOPT                                           

    CPUID Registers (CPU #1):
      CPUID 00000000                                    00000006-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00300F10-00040800-00802009-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000000
      CPUID 00000006                                    00000000-00000000-00000001-00000000
      CPUID 80000000                                    8000001B-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00300F10-10001811-000037FF-EFD3FBFF
      CPUID 80000002                                    20444D41-332D3641-4D303034-55504120 [AMD A6-3400M APU]
      CPUID 80000003                                    74697720-61522068-6E6F6564-296D7428 [ with Radeon(tm)]
      CPUID 80000004                                    20444820-70617247-73636968-00000000 [ HD Graphics]
      CPUID 80000005                                    FF30FF10-FF30FF20-40020140-40020140
      CPUID 80000006                                    20800000-44004200-04008140-00000000
      CPUID 80000007                                    00000000-00000000-00000000-000003F9
      CPUID 80000008                                    00003028-00000000-00002003-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00000040-00000000-0000040F
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F0300000-60100000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000000FF-00000000-00000000-00000000

    CPUID Registers (CPU #2):
      CPUID 00000000                                    00000006-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00300F10-01040800-00802009-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000000
      CPUID 00000006                                    00000000-00000000-00000001-00000000
      CPUID 80000000                                    8000001B-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00300F10-10001811-000037FF-EFD3FBFF
      CPUID 80000002                                    20444D41-332D3641-4D303034-55504120 [AMD A6-3400M APU]
      CPUID 80000003                                    74697720-61522068-6E6F6564-296D7428 [ with Radeon(tm)]
      CPUID 80000004                                    20444820-70617247-73636968-00000000 [ HD Graphics]
      CPUID 80000005                                    FF30FF10-FF30FF20-40020140-40020140
      CPUID 80000006                                    20800000-44004200-04008140-00000000
      CPUID 80000007                                    00000000-00000000-00000000-000003F9
      CPUID 80000008                                    00003028-00000000-00002003-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00000040-00000000-0000040F
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F0300000-60100000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000000FF-00000000-00000000-00000000

    CPUID Registers (CPU #3):
      CPUID 00000000                                    00000006-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00300F10-02040800-00802009-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000000
      CPUID 00000006                                    00000000-00000000-00000001-00000000
      CPUID 80000000                                    8000001B-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00300F10-10001811-000037FF-EFD3FBFF
      CPUID 80000002                                    20444D41-332D3641-4D303034-55504120 [AMD A6-3400M APU]
      CPUID 80000003                                    74697720-61522068-6E6F6564-296D7428 [ with Radeon(tm)]
      CPUID 80000004                                    20444820-70617247-73636968-00000000 [ HD Graphics]
      CPUID 80000005                                    FF30FF10-FF30FF20-40020140-40020140
      CPUID 80000006                                    20800000-44004200-04008140-00000000
      CPUID 80000007                                    00000000-00000000-00000000-000003F9
      CPUID 80000008                                    00003028-00000000-00002003-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00000040-00000000-0000040F
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F0300000-60100000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000000FF-00000000-00000000-00000000

    CPUID Registers (CPU #4):
      CPUID 00000000                                    00000006-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00300F10-03040800-00802009-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000000
      CPUID 00000006                                    00000000-00000000-00000001-00000000
      CPUID 80000000                                    8000001B-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00300F10-10001811-000037FF-EFD3FBFF
      CPUID 80000002                                    20444D41-332D3641-4D303034-55504120 [AMD A6-3400M APU]
      CPUID 80000003                                    74697720-61522068-6E6F6564-296D7428 [ with Radeon(tm)]
      CPUID 80000004                                    20444820-70617247-73636968-00000000 [ HD Graphics]
      CPUID 80000005                                    FF30FF10-FF30FF20-40020140-40020140
      CPUID 80000006                                    20800000-44004200-04008140-00000000
      CPUID 80000007                                    00000000-00000000-00000000-000003F9
      CPUID 80000008                                    00003028-00000000-00002003-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00000040-00000000-0000040F
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F0300000-60100000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000000FF-00000000-00000000-00000000

    MSR Registers:
      CPB PStates                                       1
      CPU Clock (Normal)                                1397 MHz
      CPU Clock (TSC)                                   1397 MHz
      CPU Multiplier                                    14.0x
      MSR 0000001B                                      0000-0000-FEE0-0900
      MSR 0000008B                                      0000-0000-0300-0027
      MSR 000000E7                                      0000-0000-015C-BDB7
      MSR 000000E8                                      0000-0000-017D-7A3B
      MSR C0010004                                      0000-0D11-9028-24A8
      MSR C0010005                                      0000-1168-4E1A-E11B
      MSR C0010006                                      0000-0920-0F90-8D36
      MSR C0010007                                      0000-0FE3-E2B7-DCFF
      MSR C0010015                                      0000-0000-0100-0011
      MSR C001001F                                      0400-4000-0000-0200
      MSR C0010055                                      0000-0000-4000-0408
      MSR C0010058                                      0000-0000-F800-0019
      MSR C0010061                                      0000-0000-0000-0060
      MSR C0010062                                      0000-0000-0000-0000
      MSR C0010063                                      0000-0000-0000-0000
      MSR C0010064                                      8000-017D-0000-2DE2 [23.00x] [1.2750 V] [12.50 A] [PState Pb0]
      MSR C0010065                                      8000-0140-0000-57A3 [14.00x] [1.0125 V] [ 6.40 A] [PState P0]
      MSR C0010066                                      8000-0137-0000-5B73 [13.00x] [0.9875 V] [ 5.50 A] [PState P1]
      MSR C0010067                                      8000-0132-0000-5F43 [12.00x] [0.9625 V] [ 5.00 A] [PState P2]
      MSR C0010068                                      8000-012E-0000-6113 [11.00x] [0.9500 V] [ 4.60 A] [PState P3]
      MSR C0010069                                      8000-012B-0000-60E3 [10.00x] [0.9500 V] [ 4.30 A] [PState P4]
      MSR C001006A                                      8000-0127-0000-62B3 [ 9.00x] [0.9375 V] [ 3.90 A] [PState P5]
      MSR C001006B                                      8000-0125-0000-6304 [ 8.00x] [0.9375 V] [ 3.70 A] [PState P6]
      MSR C0010070                                      0000-0000-0000-0000
      MSR C0010071                                      0031-60B7-5A01-57A3 [14.00x] [1.0125V]
      MSR C0010071                                      0031-60B7-5A01-57A3 [14.00x] [1.0125V]
      MSR C0010071                                      0031-60B7-5A01-57A3 [14.00x] [1.0125V]
      MSR C0010071                                      0031-60B7-5A01-57A3 [14.00x] [1.0125V]
      MSR C0010071                                      0031-60B7-6A01-57A3 [14.00x] [1.0125V]
      MSR C0010140                                      0000-0000-0000-0004
      MSR C0010141                                      0000-0000-0000-0000
      MSR C0011023                                      0000-0000-1020-0020


--------[   ]---------------------------------------------------------------------------------------------

      :
      ID                                  <DMI>
                                          Toshiba Satellite L755D

      FSB:
                                                 AMD K12
                                         100 
                                      100 
                                   667 

      :
                                                 Dual DDR3 SDRAM
                                              128 
       DRAM:FSB                              20:3
                                         667  (DDR)
                                      1333 
                                   21333 /


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   3559 
                                                  2528 
                                                1031 
                                                71 %

       :
                                                   7143 
                                                  3958 
                                                3184 
                                                55 %

     :
                                                   10702 
                                                  6487 
                                                4215 
                                                61 %

     :
                                            C:\pagefile.sys
                                           3584 
      /                           628  / 718 
                                                18 %

    Physical Address Extension (PAE):
                                        
                                        
                                                


--------[ SPD ]---------------------------------------------------------------------------------------------------------

  [ DIMM1: Samsung M471B5773DH0-CH9 ]

      :
                                               Samsung M471B5773DH0-CH9
                                           00500606h (101076992)
                                              25 / 2011
                                            2  (1 rank, 8 banks)
                                               SO-DIMM
                                               DDR3 SDRAM
                                          DDR3-1333 (667 )
                                            64 bit
                                        1.5 V
                                  
                                       (7.8 us)
       DRAM                                Samsung

     :
      @ 666                                          9-9-9-24  (CL-RCD-RP-RAS) / 33-107-4-10-5-5-20  (RC-RFC-RRD-WR-WTR-RTP-FAW)
      @ 609                                          8-8-8-22  (CL-RCD-RP-RAS) / 30-98-4-10-5-5-19  (RC-RFC-RRD-WR-WTR-RTP-FAW)
      @ 533                                          7-7-7-20  (CL-RCD-RP-RAS) / 27-86-4-8-4-4-16  (RC-RFC-RRD-WR-WTR-RTP-FAW)
      @ 457                                          6-6-6-17  (CL-RCD-RP-RAS) / 23-74-3-7-4-4-14  (RC-RFC-RRD-WR-WTR-RTP-FAW)
      @ 380                                          5-5-5-14  (CL-RCD-RP-RAS) / 19-61-3-6-3-3-12  (RC-RFC-RRD-WR-WTR-RTP-FAW)

      :
      Auto Self Refresh (ASR)                            
      DLL-Off Mode                                      
      Extended Temperature Range                        
      Extended Temperature Refresh Rate                  
      On-Die Thermal Sensor Readout (ODTS)               
      Partial Array Self Refresh (PASR)                  
      RZQ/6                                             
      RZQ/7                                             

      :
                                                   Samsung
                                     http://www.samsung.com/global/business/semiconductor

  [ DIMM2: Samsung M471B5773DH0-CH9 ]

      :
                                               Samsung M471B5773DH0-CH9
                                           00500605h (84299776)
                                              25 / 2011
                                            2  (1 rank, 8 banks)
                                               SO-DIMM
                                               DDR3 SDRAM
                                          DDR3-1333 (667 )
                                            64 bit
                                        1.5 V
                                  
                                       (7.8 us)
       DRAM                                Samsung

     :
      @ 666                                          9-9-9-24  (CL-RCD-RP-RAS) / 33-107-4-10-5-5-20  (RC-RFC-RRD-WR-WTR-RTP-FAW)
      @ 609                                          8-8-8-22  (CL-RCD-RP-RAS) / 30-98-4-10-5-5-19  (RC-RFC-RRD-WR-WTR-RTP-FAW)
      @ 533                                          7-7-7-20  (CL-RCD-RP-RAS) / 27-86-4-8-4-4-16  (RC-RFC-RRD-WR-WTR-RTP-FAW)
      @ 457                                          6-6-6-17  (CL-RCD-RP-RAS) / 23-74-3-7-4-4-14  (RC-RFC-RRD-WR-WTR-RTP-FAW)
      @ 380                                          5-5-5-14  (CL-RCD-RP-RAS) / 19-61-3-6-3-3-12  (RC-RFC-RRD-WR-WTR-RTP-FAW)

      :
      Auto Self Refresh (ASR)                            
      DLL-Off Mode                                      
      Extended Temperature Range                        
      Extended Temperature Refresh Rate                  
      On-Die Thermal Sensor Readout (ODTS)               
      Partial Array Self Refresh (PASR)                  
      RZQ/6                                             
      RZQ/7                                             

      :
                                                   Samsung
                                     http://www.samsung.com/global/business/semiconductor


--------[  ]------------------------------------------------------------------------------------------------------

  [  : AMD K12 IMC ]

      :
                                            AMD K12 IMC
                                DDR3-800, DDR3-1066, DDR3-1333 SDRAM
                                                  00
                                  32 nm

     :
                                                     Dual Channel  (128 )
                                           Dual Channel  (128 )

     :
      CAS Latency (CL)                                  9T
      RAS To CAS Delay (tRCD)                           9T
      RAS Precharge (tRP)                               9T
      RAS Active Time (tRAS)                            24T
      Row Cycle Time (tRC)                              33T
      Row Refresh Cycle Time (tRFC)                     DIMM1: 160 ns, DIMM3: 160 ns
      Command Rate (CR)                                 1T
      RAS To RAS Delay (tRRD)                           4T
      Write Recovery Time (tWR)                         10T
      Write To Read Delay (tWTR)                        5T
      Read To Precharge Delay (tRTP)                    5T
      Four Activate Window Delay (tFAW)                 20T
      Write CAS Latency (tWCL)                          7T
      Refresh Period (tREF)                             7.8 us
      DRAM Drive Strength                               0.75x
      DRAM Data Drive Strength                          0.75x
      Clock Drive Strength                              1.25x
      CKE Drive Strength                                1.5x
      Idle Cycle Limit                                  96

     :
       DRAM #1                                    2   (DDR3-1333 DDR3 SDRAM)
       DRAM #2                                    2   (DDR3-1333 DDR3 SDRAM)

      :
                              AMD Radeon HD 6520G (Sumo)
                           
        -                  512 

    High Definition Audio:
                                               ATI Radeon HDMI
      ID                                          1002AA01h / 00AA0100h
                                            1002h
                                               Audio

     PCI Express:
      PCI-E 2.0 x16 port #0                              @ x1  (AMD Radeon HD 6450M/6470M/6490M (Seymour) Video Adapter)
      PCI-E 2.0 x1 port #1                               @ x1  (Atheros AR8152/8158 PCI-E Fast Ethernet Controller)
      PCI-E 2.0 x1 port #2                               @ x1  (Realtek RTL8188CE Wireless LAN 802.11n PCI-E Network Adapter)

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/chipsets
                                       http://support.amd.com
       BIOS                                 http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [  : AMD A60M (Hudson-M2) ]

      :
                                               AMD A60M (Hudson-M2)
                                                  11
                                              656 Pin FC-BGA
                                          24.5 mm x 24.5 mm
                                         49.25 mm2
                                   1.1 V
      Debug Info                                        Hudson/Bolton ID = 07h

    High Definition Audio:
                                               Conexant Cx20585
      ID                                          14F15069h / 1179FC50h
                                            1003h
                                               Audio

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/chipsets
                                       http://support.amd.com
       BIOS                                 http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates


--------[ BIOS ]--------------------------------------------------------------------------------------------------------

     BIOS:
       BIOS                                          Insyde EFI
       BIOS                                       2.10
       AGESA                                      LlanoPI V1.1.0.6
       BIOS                                  06/28/2012
       BIOS                            05/10/11

     BIOS:
                                                   Insyde Software Corp.
                                     http://www.insydesw.com/products
       BIOS                                 http://www.aida64.com/bios-updates


--------[ ACPI ]--------------------------------------------------------------------------------------------------------

  [ APIC: Multiple APIC Description Table ]

      ACPI:
       ACPI                                      APIC
                                         Multiple APIC Description Table
                                             CFEF2000h
                                           132 
      OEM ID                                            TOSQCI
      OEM Table ID                                      TOSQCI00
      OEM Revision                                      00000001h
      Creator ID                                        ACPI
      Creator Revision                                  00040000h
      Local APIC Address                                FEE00000h

    Processor Local APIC:
      ACPI Processor ID                                 00h
      APIC ID                                           00h
                                                  

    Processor Local APIC:
      ACPI Processor ID                                 01h
      APIC ID                                           01h
                                                  

    Processor Local APIC:
      ACPI Processor ID                                 02h
      APIC ID                                           02h
                                                  

    Processor Local APIC:
      ACPI Processor ID                                 03h
      APIC ID                                           03h
                                                  

    I/O APIC:
      I/O APIC ID                                       04h
      I/O APIC Address                                  FEC00000h
      Global System Interrupt Base                      00000000h

    Interrupt Source Override:
                                                    ISA
                                                IRQ0
      Global System Interrupt                           00000002h
                                              Conforms to the specifications of the bus
      Trigger Mode                                      Conforms to the specifications of the bus

    Interrupt Source Override:
                                                    ISA
                                                IRQ9
      Global System Interrupt                           00000009h
                                              Active Low
      Trigger Mode                                      Level-Triggered

    Local APIC NMI:
      ACPI Processor ID                                 00h
      Local ACPI LINT#                                  01h
                                              Active High
      Trigger Mode                                      Edge-Triggered

    Local APIC NMI:
      ACPI Processor ID                                 01h
      Local ACPI LINT#                                  01h
                                              Active High
      Trigger Mode                                      Edge-Triggered

    Local APIC NMI:
      ACPI Processor ID                                 02h
      Local ACPI LINT#                                  01h
                                              Active High
      Trigger Mode                                      Edge-Triggered

    Local APIC NMI:
      ACPI Processor ID                                 03h
      Local ACPI LINT#                                  01h
                                              Active High
      Trigger Mode                                      Edge-Triggered

  [ ASF!: Alert Standard Format Table ]

      ACPI:
       ACPI                                      ASF!
                                         Alert Standard Format Table
                                             CFEF0000h
                                           165 
      OEM ID                                            TOSQCI
      OEM Table ID                                      TOSQCI00
      OEM Revision                                      00000001h
      Creator ID                                        ACPI
      Creator Revision                                  00040000h

    ASF_INFO:
      Min Watchdog Reset Value                          0 
      Min ASF Sensor Interpoll Wait Time                1275 msec
      System ID                                         0001h
      IANA Manufacturer ID                              00-00-01-57h

    ASF_ALRT:
      Numer of Alerts                                   3
      Array Element Length                              12

    ASF_RCTL:
      Numer of Controls                                 4
      Array Element Length                              4

    ASF_RMCP:
      Remote Control Capabilities                       21-F8-00-00-00-1B-F0h
      RMCP Boot Options Completion Code                 00h  (Successful)
      RMCP IANA Enterprise ID                           00-00-01-57h
      RMCP Special Command                              00h
      RMCP Special Command Parameter                    0100h
      RMCP Boot Options                                 7000h
      RMCP OEM Parameters                               1600h

    ASF_INFO:
      Min Watchdog Reset Value                          162 
      Min ASF Sensor Interpoll Wait Time                820 msec
      System ID                                         0000h
      IANA Manufacturer ID                              00-00-00-00h

  [ BOOT: Simple Boot Flag Table ]

      ACPI:
       ACPI                                      BOOT
                                         Simple Boot Flag Table
                                             CFEDD000h
                                           40 
      OEM ID                                            TOSQCI
      OEM Table ID                                      TOSQCI00
      OEM Revision                                      00000001h
      Creator ID                                        ACPI
      Creator Revision                                  00040000h

  [ DSDT: Differentiated System Description Table ]

      ACPI:
       ACPI                                      DSDT
                                         Differentiated System Description Table
                                             00000000-CFEDE000h
                                           70373 
      OEM ID                                            TOSQCI
      OEM Table ID                                      TOSQCI00
      OEM Revision                                      F0000000h
      Creator ID                                        ACPI
      Creator Revision                                  00040000h

    nVIDIA SLI:
      SLI Certification                                 
      PCI 0-0-0-0 (Direct I/O)                          1022-1705
      PCI 0-0-0-0 (HAL)                                 1022-1705

    Lucid Virtu:
      Virtu Certification                               

  [ FACP: Fixed ACPI Description Table ]

      ACPI:
       ACPI                                      FACP
                                         Fixed ACPI Description Table
                                             CFEF4000h
                                           244 
      OEM ID                                            TOSQCI
      OEM Table ID                                      TOSQCI00
      OEM Revision                                      00000001h
      Creator ID                                        ACPI
      Creator Revision                                  00040000h
      FACS Address                                      CFC97000h / 00000000-CFC97000h
      DSDT Address                                      CFEDE000h / 00000000-CFEDE000h
      SMI Command Port                                  000000B0h
      PM Timer                                          00000408h

  [ FACS: Firmware ACPI Control Structure ]

      ACPI:
       ACPI                                      FACS
                                         Firmware ACPI Control Structure
                                             00000000-CFC97000h
                                           64 
      Hardware Signature                                00000000h
      Waking Vector                                     00000000h
      Global Lock                                       00000000h

  [ HPET: IA-PC High Precision Event Timer Table ]

      ACPI:
       ACPI                                      HPET
                                         IA-PC High Precision Event Timer Table
                                             CFEF3000h
                                           56 
      OEM ID                                            TOSQCI
      OEM Table ID                                      TOSQCI00
      OEM Revision                                      00000001h
      Creator ID                                        ACPI
      Creator Revision                                  00040000h
      HPET Address                                      00000000-FED00000h
      Vendor ID                                         1022h
      Revision ID                                       10h
      Number of Timers                                  3
      Counter Size                                      32 
      Minimum Clock Ticks                               128
      Page Protection                                   No Guarantee
      OEM Attribute                                     0h
      LegacyReplacement IRQ Routing                     

  [ MCFG: Memory Mapped Configuration Space Base Address Description Table ]

      ACPI:
       ACPI                                      MCFG
                                         Memory Mapped Configuration Space Base Address Description Table
                                             CFEF1000h
                                           60 
      OEM ID                                            TOSQCI
      OEM Table ID                                      TOSQCI00
      OEM Revision                                      00000001h
      Creator ID                                        ACPI
      Creator Revision                                  00040000h
      Config Space Address                              00000000-F8000000h
      PCI Segment                                       0000h
      Start Bus Number                                  00h
      End Bus Number                                    3Fh

  [ MSDM: Microsoft Data Management Table ]

      ACPI:
       ACPI                                      MSDM
                                         Microsoft Data Management Table
                                             CFEDA000h
                                           85 
      OEM ID                                            TOSQCI
      OEM Table ID                                      TOSQCI00
      OEM Revision                                      00000001h
      Creator ID                                        ACPI
      Creator Revision                                  00040000h
      SLS Version                                       1
      SLS Data Type                                     1
      SLS Data Length                                   29
      SLS Data                                          BH3RN-B7FDM-C7WGT-4CR4X-6CKHM

  [ RSD PTR: Root System Description Pointer ]

      ACPI:
       ACPI                                      RSD PTR
                                         Root System Description Pointer
                                             000FE020h
                                           36 
      OEM ID                                            TOSQCI
      RSDP Revision                                     2  (ACPI 2.0+)
      RSDT Address                                      CFEF50ACh
      XSDT Address                                      00000000-CFEF5120h

  [ RSDT: Root System Description Table ]

      ACPI:
       ACPI                                      RSDT
                                         Root System Description Table
                                             CFEF50ACh
                                           80 
      OEM ID                                            TOSQCI
      OEM Table ID                                      TOSQCI00
      OEM Revision                                      00000001h
      Creator Revision                                  01000013h
      RSDT Entry #0                                     CFEF4000h  (FACP)
      RSDT Entry #1                                     CFEF3000h  (HPET)
      RSDT Entry #2                                     CFEF2000h  (APIC)
      RSDT Entry #3                                     CFEF1000h  (MCFG)
      RSDT Entry #4                                     CFEF0000h  (ASF!)
      RSDT Entry #5                                     CFEDD000h  (BOOT)
      RSDT Entry #6                                     CFEDC000h  (SLIC)
      RSDT Entry #7                                     CFEDB000h  (WDRT)
      RSDT Entry #8                                     CFEDA000h  (MSDM)
      RSDT Entry #9                                     CFED9000h  (SSDT)
      RSDT Entry #10                                    CFED7000h  (SSDT)

  [ SLIC: Software Licensing Description Table ]

      ACPI:
       ACPI                                      SLIC
                                         Software Licensing Description Table
                                             CFEDC000h
                                           374 
      OEM ID                                            TOSQCI
      OEM Table ID                                      TOSQCI00
      OEM Revision                                      00000001h
      Creator ID                                        ACPI
      Creator Revision                                  00040000h
       SLIC                                       v2.1

    OEM Public Key:
      Key Type                                          06h
                                                  02h
      Algorithm                                         00002400h
      Magic                                             RSA1
      Bit Length                                        1024
      Exponent                                          65537

    SLIC Marker:
                                                  00020001h
      OEM ID                                            TOSQCI
      OEM Table ID                                      TOSQCI00
      Windows Flag                                      WINDOWS

  [ SSDT: Secondary System Description Table ]

      ACPI:
       ACPI                                      SSDT
                                         Secondary System Description Table
                                             CFED7000h
                                           6461 
      OEM ID                                            AMD
      OEM Table ID                                      ALIB
      OEM Revision                                      00000001h
      Creator ID                                        MSFT
      Creator Revision                                  04000000h

  [ SSDT: Secondary System Description Table ]

      ACPI:
       ACPI                                      SSDT
                                         Secondary System Description Table
                                             CFED9000h
                                           3624 
      OEM ID                                            AMD
      OEM Table ID                                      POWERNOW
      OEM Revision                                      00000001h
      Creator ID                                        AMD
      Creator Revision                                  00000001h

  [ WDRT: Watchdog Resource Table ]

      ACPI:
       ACPI                                      WDRT
                                         Watchdog Resource Table
                                             CFEDB000h
                                           71 
      OEM ID                                            TOSQCI
      OEM Table ID                                      TOSQCI00
      OEM Revision                                      00000001h
      Creator ID                                        ACPI
      Creator Revision                                  00040000h

  [ XSDT: Extended System Description Table ]

      ACPI:
       ACPI                                      XSDT
                                         Extended System Description Table
                                             00000000-CFEF5120h
                                           124 
      OEM ID                                            TOSQCI
      OEM Table ID                                      TOSQCI00
      OEM Revision                                      00000001h
      Creator Revision                                  01000013h
      XSDT Entry #0                                     00000000-CFEF4000h  (FACP)
      XSDT Entry #1                                     00000000-CFEF3000h  (HPET)
      XSDT Entry #2                                     00000000-CFEF2000h  (APIC)
      XSDT Entry #3                                     00000000-CFEF1000h  (MCFG)
      XSDT Entry #4                                     00000000-CFEF0000h  (ASF!)
      XSDT Entry #5                                     00000000-CFEDD000h  (BOOT)
      XSDT Entry #6                                     00000000-CFEDC000h  (SLIC)
      XSDT Entry #7                                     00000000-CFEDB000h  (WDRT)
      XSDT Entry #8                                     00000000-CFEDA000h  (MSDM)
      XSDT Entry #9                                     00000000-CFED9000h  (SSDT)
      XSDT Entry #10                                    00000000-CFED7000h  (SSDT)


--------[   ]----------------------------------------------------------------------------------------

      :
                                              Microsoft Windows 8.1 Professional
                                                   ()
                                        ()
                                               Multiprocessor Free (64-bit)
                                                6.3.9600.17238 (Win8.1 RTM)
                                       -
                                         26.07.2014
                                         C:\Windows

     :
                          nicksab1491@mail.ru
                           
      ID                                        00261-50000-00000-AA989
                                            GCRJD-8NW9H-F2CDX-CCM8D-9D6T9
        (WPA)                           

     :
                                           BLACK_SOKOL
                                         Black_SOKOL
                                              BLACK_SOKOL
                                             1484  (0 ., 0 , 24 , 44 )

     :
      Common Controls                                   6.16
      Windows Mail                                      6.3.9600.16384 (winblue_rtm.130821-1623)
       Windows Media                       12.0.9600.16384 (winblue_rtm.130821-1623)
      Windows Messenger                                 -
      MSN Messenger                                     -
      Internet Information Services (IIS)               -
      .NET Framework                                    4.0.30319.33440 built by: FX45W81RTMREL
       Novell                                     -
      DirectX                                           DirectX 11.2
      OpenGL                                            6.3.9600.16384 (winblue_rtm.130821-1623)
      ASPI                                              -

      :
                                        
       DBCS                                       
                                        
                                     
                                             
                                         
                                         
                                      
                                      


--------[  ]----------------------------------------------------------------------------------------------------

    AdAppMgr.exe             C:\Users\Black_SOKOL\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe   32         54872             29 
    AdAppMgrSvc.exe          C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe  32          7924              2 
    AdSync.exe               C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe                            64         23048              7 
    afwServ.exe              C:\Program Files\AVAST Software\Avast\afwServ.exe                             32         11576              9 
    aida64.exe               C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe                    32         70012             57 
    ASCService.exe           C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe             32         11324             26 
    ASCTray.exe              C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe                32         20552             15 
    atieclxx.exe             C:\Windows\system32\atieclxx.exe                                              64          7124              1 
    atiesrxx.exe             C:\Windows\system32\atiesrxx.exe                                              64          2952              0 
    audiodg.exe                                                                                            64          8244              5 
    AvastSvc.exe             C:\Program Files\AVAST Software\Avast\AvastSvc.exe                            32         40092            106 
    avastui.exe              C:\Program Files\AVAST Software\Avast\avastui.exe                             32         11596             21 
    Azureus.exe              C:\Program Files\Vuze\Azureus.exe                                             64           173            187 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32         44684             47 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32         74068             76 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32           105             83 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32         26660             26 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32         37436             40 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32         32192             32 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32           100            108 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32         33928             32 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32         32980             31 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32         38096             38 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32         36788             36 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32         33536             34 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32         37728             38 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32         29500             30 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32           110            107 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32         29064             26 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32           144            144 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32         69556             65 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32           170            117 
    browser.exe              C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  32         20144             15 
    BrowserManager.exe       C:\Users\Black_SOKOL\AppData\Local\Yandex\Updater2\BrowserManager.exe         32         13212              4 
    CCC.exe                  C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe           64          8688             96 
    Connect.Service.ContentService.exe  C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe  32         17096             20 
    crash_service.exe        C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\34.0.1847.18825\crash_service.exe  32          5088              1 
    csrss.exe                                                                                              64          3656              1 
    csrss.exe                                                                                              64         10660              3 
    dasHost.exe              C:\Windows\system32\dashost.exe                                               32         11580              4 
    dllhost.exe              C:\Windows\system32\DllHost.exe                                               64          8592              3 
    dllhost.exe              C:\Windows\system32\DllHost.exe                                               64          6360              1 
    dmaster.exe              C:\Program Files (x86)\Download Master\dmaster.exe                            32          3176             13 
    DTLite.exe               C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe                           32          8932              4 
    dwm.exe                  C:\Windows\system32\dwm.exe                                                   32         29096             20 
    elements64.exe           C:\Users\Black_SOKOL\AppData\Local\Yandex\Elements\elements.exe\8.4.0.9140\elements64.exe  64          8980              2 
    explorer.exe             C:\Windows\Explorer.EXE                                                       64           124             85 
    Fuel.Service.exe         C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe               64         10092              4 
    GameCenter@Mail.Ru.exe   C:\Users\Black_SOKOL\AppData\Local\Mail.Ru\GameCenter\GameCenter@Mail.Ru.exe  32         27904             33 
    GameCenter@Mail.Ru.exe   C:\Users\Black_SOKOL\AppData\Local\Mail.Ru\GameCenter\GameCenter@Mail.Ru.exe  32         16448             15 
    GameCenter@Mail.Ru.exe   C:\Users\Black_SOKOL\AppData\Local\Mail.Ru\GameCenter\GameCenter@Mail.Ru.exe  32         29504             33 
    GameCenter@Mail.Ru.exe   C:\Users\Black_SOKOL\AppData\Local\Mail.Ru\GameCenter\GameCenter@Mail.Ru.exe  32         30100             32 
    GameCenter@Mail.Ru.exe   C:\Users\Black_SOKOL\AppData\Local\Mail.Ru\GameCenter\GameCenter@Mail.Ru.exe  32         65600             43 
    HPLaserJetService.exe    C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe             32          4956             22 
    HPSIsvc.exe              C:\Windows\system32\HPSIsvc.exe                                               64          3280              0 
    InstallServices64.exe    C:\Program Files (x86)\IObit\Start Menu 8\InstallServices64.exe               64         11684              5 
    jusched.exe              C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe              32          4552              0 
    livecomm.exe             C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20573_x64__8wekyb3d8bbwe\LiveComm.exe  64          4876             29 
    lsass.exe                C:\Windows\system32\lsass.exe                                                 64         10264              5 
    mDNSResponder.exe        C:\Program Files\Bonjour\mDNSResponder.exe                                    64          4204              1 
    mitsijm.exe              C:\Program Files\Autodesk\Inventor 2015\Moldflow\bin\mitsijm.exe              64          4080              2 
    MOM.exe                  C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe           64          3488             24 
    notepad.exe              C:\Windows\system32\NOTEPAD.EXE                                               64          7332              1 
    RuntimeBroker.exe        C:\Windows\System32\RuntimeBroker.exe                                         64         11700              3 
    SearchFilterHost.exe     C:\Windows\system32\SearchFilterHost.exe                                      64          5872              2 
    SearchIndexer.exe        C:\Windows\system32\SearchIndexer.exe                                         64         63100             39 
    SearchProtocolHost.exe   C:\Windows\system32\SearchProtocolHost.exe                                    64          6700              2 
    services.exe                                                                                           64          6108              2 
    SettingSyncHost.exe      C:\Windows\System32\SettingSyncHost.exe                                       64          2512              5 
    SkyDrive.exe             C:\Windows\System32\skydrive.exe                                              64         10400              8 
    smss.exe                                                                                               64           836              0 
    splwow64.exe             C:\Windows\splwow64.exe                                                       64          5844              1 
    spoolsv.exe              C:\Windows\System32\spoolsv.exe                                               64         10628              5 
    sppsvc.exe                                                                                             64         11716              2 
    StartMenu_Hook.exe       C:\Program Files (x86)\IObit\Start Menu 8\StartMenu_Hook.exe                  32          6464              2 
    StartMenu8.exe           C:\Program Files (x86)\IObit\Start Menu 8\StartMenu8.exe                      32         18800             15 
    StartMenuServices.exe    C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe               32          7392              5 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         42844             28 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         17568             11 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         13188              6 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         19368             16 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          4012              1 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          5184              1 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         14072              5 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64         10516              4 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64         23048             18 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         10340              4 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          7620              4 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64         76748             68 
    SynTPEnh.exe             C:\Program Files\Synaptics\SynTP\SynTPEnh.exe                                 64          7548              3 
    SynTPHelper.exe          C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE                              64          2772              0 
    System Idle Process                                                                                                      4              0 
    System                                                                                                 64           928              3 
    taskhostex.exe           C:\Windows\system32\taskhostex.exe                                            64          7536              2 
    unsecapp.exe             C:\Windows\system32\wbem\unsecapp.exe                                         64          5260              1 
    USBSafelyRemove.exe      C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe                  32         14900             18 
    USBSRService.exe         C:\Program Files (x86)\USB Safely Remove\USBSRService.exe                     64          3520              2 
    wininit.exe              C:\Windows\system32\wininit.exe                                               64          3308              0 
    winlogon.exe             C:\Windows\system32\winlogon.exe                                              64          5156              1 
    WmiPrvSE.exe             C:\Windows\system32\wbem\wmiprvse.exe                                         64         10928              5 
    WmiPrvSE.exe             C:\Windows\sysWOW64\wbem\wmiprvse.exe                                         32          6700              2 
    wmpnetwk.exe             C:\Program Files\Windows Media Player\wmpnetwk.exe                            64         18340              5 
    YandexDisk.exe           C:\Users\Black_SOKOL\AppData\Roaming\Yandex\YandexDisk\YandexDisk.exe         64         53224             36 
    YandexDiskStarter.exe    C:\Users\Black_SOKOL\AppData\Roaming\Yandex\YandexDisk\wow64\YandexDiskStarter.exe  32          4048              0 
    YandexDiskStarter.exe    C:\Users\Black_SOKOL\AppData\Roaming\Yandex\YandexDisk\YandexDiskStarter.exe  64          3540              0 


--------[   ]------------------------------------------------------------------------------------------

    1394ohci         1394 OHCI- -                                   1394ohci.sys          6.3.9600.16384                        
    3ware            3ware                                                                   3ware.sys             5.1.0.51                              
    ACPI              Microsoft ACPI                                                  ACPI.sys              6.3.9600.17031                        
    acpiex           Microsoft ACPIEx Driver                                                 acpiex.sys            6.3.9600.16384                        
    acpipagr            ACPI                                      acpipagr.sys          6.3.9600.16384                        
    AcpiPmi              ACPI                              acpipmi.sys           6.3.9600.16384                        
    acpitime          ACPI Wake Alarm                                                 acpitime.sys          6.3.9600.16384                        
    ADP80XX          ADP80XX                                                                 ADP80XX.SYS           1.0.0.254                             
    AFD                  Winsock                              afd.sys               6.3.9600.17194                        
    agp440           Intel -   AGP                                                 agp440.sys            6.3.9600.16384                        
    ahcache          Application Compatibility Cache                                         ahcache.sys           6.3.9600.16384                        
    AIDA64Driver     FinalWire AIDA64 Kernel Driver                                          kerneld.x64                                                 
    amd_sata         amd_sata                                                                amd_sata.sys          1.3.1.220                             
    amd_xata         amd_xata                                                                amd_xata.sys          1.3.1.220                             
    AmdK8            AMD K8                                                 amdk8.sys             6.3.9600.16384                        
    amdkmdag         amdkmdag                                                                atikmdag.sys          8.1.1.1360                            
    amdkmdap         amdkmdap                                                                atikmpag.sys          8.14.1.6354                           
    AmdPPM             AMD                                                  amdppm.sys            6.3.9600.16384                        
    amdsata          amdsata                                                                 amdsata.sys           1.1.4.14                              
    amdsbs           amdsbs                                                                  amdsbs.sys            3.7.1540.43                           
    amdxata          amdxata                                                                 amdxata.sys           1.1.4.14                              
    andnetadb        ADB Interface DriverNet                                                 lgandnetadb.sys       3.12.0.0                              
    AndNetDiag       LGE AndroidNet USB Serial Port                                          lgandnetdiag64.sys    3.12.0.0                              
    ANDNetModem      LGE AndroidNet USB Modem                                                lgandnetmodem64.sys   3.12.0.0                              
    andnetndis       LGE AndroidNet NDIS Ethernet Adapter                                    lgandnetndis64.sys    3.12.0.0                              
    AODDriver4.2.0   AODDriver4.2.0                                                          AODDriver2.sys        4.2.0.0                               
    AppID             AppID                                                           appid.sys             6.3.9600.16404                        
    arcsas           Adaptec SAS/SATA-II RAID -   Storport                   arcsas.sys            7.2.0.30261                           
    aswHwid          avast! HardwareID                                                       aswHwid.sys           9.0.2021.515                          
    aswKbd           aswKbd                                                                  aswKbd.sys            9.0.2021.515                          
    aswMonFlt        aswMonFlt                                                               aswMonFlt.sys         9.0.2021.515               
    aswNdisFlt       Avast! Firewall Driver                                                  aswNdisFlt.sys        9.0.2021.515                          
    aswRdr           aswRdr                                                                  aswRdr2.sys           9.0.2021.515                          
    aswRvrt          avast! Revert                                                                                                                       
    aswSnx           aswSnx                                                                  aswSnx.sys            9.0.2021.515               
    aswSP            aswSP                                                                   aswSP.sys             9.0.2021.522               
    aswStm           aswStm                                                                  aswStm.sys            9.0.2021.515                          
    aswVmm           avast! VM Monitor                                                                                                                   
    AsyncMac            RAS                                       asyncmac.sys          6.3.9600.16384                        
    atapi             IDE                                                               atapi.sys             6.3.9600.16384                        
    AtiHDAudioService  AMD Function Driver for HD Audio Service                                AtihdWB6.sys          9.0.0.9905                            
    b06bdrv          Broadcom NetXtreme II VBD                                               bxvbda.sys            7.4.14.0                              
    BasicDisplay     BasicDisplay                                                            BasicDisplay.sys      6.3.9600.16384                        
    BasicRender      BasicRender                                                             BasicRender.sys       6.3.9600.17031                        
    bcmfn2           bcmfn2 Service                                                          bcmfn2.sys            6.3.9391.6                            
    Beep             Beep                                                                                                                                
    bowser                                                           bowser.sys            6.3.9600.16384             
    BthAvrcpTg       HID       Bluetooth            BthAvrcpTg.sys        6.3.9600.16384                        
    BthHFEnum         HID       c  Bluetooth  bthhfenum.sys         6.3.9600.16384                        
    bthhfhid         HID      Bluetooth            BthHFHid.sys          6.3.9600.16384                        
    BTHMODEM                Bluetooth      bthmodem.sys          6.3.9600.16520                        
    cdfs             CD/DVD File System Reader                                               cdfs.sys              6.3.9600.16384             
    cdrom             CD-ROM                                                 cdrom.sys             6.3.9600.16384                        
    circlass          -                                           circlass.sys          6.3.9600.16384                        
    CLFS             Common Log (CLFS)                                                       CLFS.sys              6.3.9600.17055                        
    CmBatt              ACPI- ()                         CmBatt.sys            6.3.9600.16384                        
    CNG              CNG                                                                     cng.sys               6.3.9600.17193                        
    CompositeBus                                          CompositeBus.sys      6.3.9600.16384                        
    condrv           Console Driver                                                          condrv.sys            6.3.9600.16384                        
    CSC                                                               csc.sys               6.3.9600.16384                        
    dam              Desktop Activity Moderator Driver                                       dam.sys               6.3.9600.16384                        
    Dfsc                 DFS                                   dfsc.sys              6.3.9600.17041             
    disk                                                                         disk.sys              6.3.9600.16384                        
    dmvsc            dmvsc                                                                   dmvsc.sys             6.3.9600.16384                        
    drmkaud                                                 drmkaud.sys           6.3.9600.16384                        
    dtsoftbus01      DAEMON Tools Virtual Bus Driver                                         dtsoftbus01.sys       4.49.1.352                            
    DXGKrnl          LDDM Graphics Subsystem                                                 dxgkrnl.sys           6.3.9600.17210                        
    ebdrv            Broadcom NetXtreme II 10 GigE VBD                                       evbda.sys             7.4.33.1                              
    EhStorClass      Enhanced Storage Filter Driver                                          EhStorClass.sys       6.3.9600.16384                        
    EhStorTcgDrv         ,   IEEE 1667  TCG  EhStorTcgDrv.sys      6.3.9600.16384                        
    ErrDev           Microsoft Hardware Error Device Driver                                  errdev.sys            6.3.9600.16384                        
    exfat            exFAT File System Driver                                                                                                 
    fastfat          FAT12/16/32 File System Driver                                                                                           
    fdc                                                        fdc.sys               6.3.9600.16384                        
    FileInfo         File Information FS MiniFilter                                          fileinfo.sys          6.3.9600.17031             
    Filetrace        Filetrace                                                               filetrace.sys         6.3.9600.16384             
    flpydisk                                                     flpydisk.sys          6.3.9600.16384                        
    FltMgr                                                                  fltmgr.sys            6.3.9600.17090             
    FsDepends        File System Dependency Minifilter                                       FsDepends.sys         6.3.9600.16384             
    fvevol               BitLocker                              fvevol.sys            6.3.9600.17091                        
    FxPPM                                              fxppm.sys             6.3.9600.16384                        
    gagp30kx         Microsoft  AGPv3.0     K8-   gagp30kx.sys          6.3.9600.16384                        
    gencounter         Microsoft Hyper-V                                      vmgencounter.sys      6.3.9600.16384                        
    GPIOClx0101      Microsoft GPIO Class Extension Driver                                   msgpioclx.sys         6.3.9600.17227                        
    HdAudAddService    UAA   High Definition Audio (Microsoft),  1.1  HdAudio.sys           6.3.9600.16384                        
    HDAudBus            UAA  High Definition Audio (Microsoft)              HDAudBus.sys          6.3.9600.17238                        
    HidBatt             HID                                                 HidBatt.sys           6.3.9600.16384                        
    HidBth           Microsoft Bluetooth HID                                         hidbth.sys            6.3.9600.16384                        
    hidi2c              HID-   I2C ()            hidi2c.sys            6.3.9600.16384                        
    HidIr            Microsoft Infrared HID                                           hidir.sys             6.3.9600.16384                        
    HidUsb             HID Microsoft                                            hidusb.sys            6.3.9600.17041                        
    HpSAMD           HpSAMD                                                                  HpSAMD.sys            8.0.4.0                               
    HTTP             HTTP-                                                             HTTP.sys              6.3.9600.16520                        
    hwpolicy         Hardware Policy Driver                                                  hwpolicy.sys          6.3.9600.16384                        
    hyperkbd         hyperkbd                                                                hyperkbd.sys          6.3.9600.16384                        
    HyperVideo       HyperVideo                                                              HyperVideo.sys        6.3.9600.16384                        
    i8042prt               PS/2                                i8042prt.sys          6.3.9600.16384                        
    iaLPSSi_GPIO       Intel(R) Serial IO GPIO                             iaLPSSi_GPIO.sys      1.1.163.0                             
    iaLPSSi_I2C       Intel(R) Serial IO I2C Controller                               iaLPSSi_I2C.sys       1.1.163.0                             
    iaStorAV         RAID- Intel(R) SATA  Windows                               iaStorAV.sys          12.0.1.1018                           
    iaStorV          RAID- Intel  Windows 7                                     iaStorV.sys           8.6.2.1019                            
    intelide         intelide                                                                intelide.sys          6.3.9600.16384                        
    intelpep              Intel(R)               intelpep.sys          6.3.9600.16459                        
    intelppm          Intel                                                 intelppm.sys          6.3.9600.16384                        
    IpFilterDriver     IP-                                              ipfltdrv.sys          6.3.9600.16384                        
    IPMIDRV          IPMIDRV                                                                 IPMIDrv.sys           6.3.9600.17238                        
    IPNAT            IP Network Address Translator                                           ipnat.sys             6.3.9600.16477                        
    IRENUM           IR Bus Enumerator                                                       irenum.sys            6.3.9600.16384                        
    isapnp           isapnp                                                                  isapnp.sys            6.3.9600.16384                        
    iScsiPrt          iScsiPort                                                       msiscsi.sys           6.3.9600.17090                        
    kbdclass                                                          kbdclass.sys          6.3.9600.16384                        
    kbdhid             HID                                                  kbdhid.sys            6.3.9600.16384                        
    kbldfltr         kbldfltr                                                                kbldfltr.sys          6.3.9600.16384                        
    kdnic            -      () (NDIS 6.20)    kdnic.sys             6.1.0.0                               
    KSecDD           KSecDD                                                                  ksecdd.sys            6.3.9600.16408                        
    KSecPkg          KSecPkg                                                                 ksecpkg.sys           6.3.9600.17042                        
    ksthunk          Kernel Streaming Thunks                                                 ksthunk.sys           6.3.9600.16384                        
    L1C              NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller  L1C63x64.sys          2.1.0.21                              
    LgBttPort        LGE Bluetooth TransPort                                                 lgbtpt64.sys          1.1.0.0                               
    lgbusenum        LG Bluetooth Bus Enumerator                                             lgbtbs64.sys          1.1.0.0                               
    LGVMODEM         LGE Virtual Modem                                                       lgvmdm64.sys          1.1.0.0                               
    lltdio                                       lltdio.sys            6.3.9600.16384                        
    LSI_SAS          LSI_SAS                                                                 lsi_sas.sys           1.34.3.82                             
    LSI_SAS2         LSI_SAS2                                                                lsi_sas2.sys          2.0.60.82                             
    LSI_SAS3         LSI_SAS3                                                                lsi_sas3.sys          2.50.65.1                             
    LSI_SSS          LSI_SSS                                                                 lsi_sss.sys           2.10.61.81                            
    luafv                                            luafv.sys             6.3.9600.17031             
    megasas          megasas                                                                 megasas.sys           6.3.9466.0                            
    megasr           megasr                                                                  megasr.sys            15.2.2013.129                         
    Modem            Modem                                                                   modem.sys             6.3.9600.16384                        
    monitor          Microsoft Monitor Class Function Driver Service                         monitor.sys           6.3.9600.16384                        
    mouclass                                                                mouclass.sys          6.3.9600.16384                        
    mouhid             HID                                                        mouhid.sys            6.3.9600.16384                        
    mountmgr                                                        mountmgr.sys          6.3.9600.16384                        
    mpsdrv              Windows                                 mpsdrv.sys            6.3.9600.16384                        
    MRxDAV              WebDav                                 mrxdav.sys            6.3.9600.17041             
    mrxsmb              - SMB                              mrxsmb.sys            6.3.9600.17111             
    mrxsmb10         - SMB 1.x                                            mrxsmb10.sys          6.3.9600.17041             
    mrxsmb20         - SMB 2.0                                            mrxsmb20.sys          6.3.9600.17216             
    MsBridge         MAC- ()                                                   bridge.sys            6.3.9600.17238                        
    Msfs             Msfs                                                                                                                     
    msgpiowin32         ,     /  msgpiowin32.sys       6.3.9600.16384                        
    mshidkmdf        Pass-through HID to KMDF Filter Driver                                  mshidkmdf.sys         6.3.9600.16384                        
    mshidumdf          HID-UMDF                                               mshidumdf.sys         6.3.9600.16384                        
    msisadrv         msisadrv                                                                msisadrv.sys          6.3.9600.16384                        
    MSKSSRV             Microsoft                                   MSKSSRV.sys           6.3.9600.16384                        
    MsLldp            Microsoft LLDP                                                 mslldp.sys            6.3.9600.16384                        
    MSPCLOCK            Microsoft                               MSPCLOCK.sys          6.3.9600.16384                        
    MSPQM                Microsoft                     MSPQM.sys             6.3.9600.16384                        
    MsRPC            MsRPC                                                                                                                               
    mssmbios          Microsoft System Management BIOS                                mssmbios.sys          6.3.9600.16384                        
    MSTEE              Tee/Sink-to-Sink Microsoft                      MSTEE.sys             6.3.9600.16384                        
    MTConfig         Microsoft Input Configuration Driver                                    MTConfig.sys          6.3.9600.16384                        
    Mup              Mup                                                                     mup.sys               6.3.9600.16384             
    mvumis           mvumis                                                                  mvumis.sys            1.0.5.1015                            
    NativeWifiP       NativeWiFi                                                       nwifi.sys             6.3.9600.17238                        
    NDIS               NDIS                                                  ndis.sys              6.3.9600.17199                        
    NdisCap           Microsoft NDIS                                                   ndiscap.sys           6.3.9600.16384                        
    NdisImPlatform       ()                  NdisImPlatform.sys    6.3.9600.17238                        
    NdisTapi         NDIS- TAPI                                      ndistapi.sys          6.3.9600.16384                        
    Ndisuio          NDIS- -                       ndisuio.sys           6.3.9600.16384                        
    NdisVirtualBus       ()                NdisVirtualBus.sys    6.3.9600.16384                        
    NdisWan          NDIS-                          ndiswan.sys           6.3.9600.16384                        
    NdisWanLegacy      NDIS-       ndiswan.sys           6.3.9600.16384                        
    NDProxy          NDIS Proxy                                                                                                                          
    Ndu              Windows Network Data Usage Monitoring Driver                            Ndu.sys               6.3.9600.16384                        
    NetBIOS          NetBIOS Interface                                                       netbios.sys           6.3.9600.16384             
    NetBT            NetBT                                                                   netbt.sys             6.3.9600.16384                        
    netvsc           netvsc                                                                  netvsc63.sys          6.3.9600.16384                        
    Npfs             Npfs                                                                                                                     
    npsvctrig        Named pipe service trigger provider                                     npsvctrig.sys         6.3.9600.16384                        
    nsiproxy         NSI Proxy Service Driver                                                nsiproxy.sys          6.3.9600.16384                        
    Ntfs             Ntfs                                                                                                                     
    Null             Null                                                                                                                                
    nv_agp           NVIDIA nForce   AGP                                           nv_agp.sys            6.3.9600.16384                        
    nvraid           nvraid                                                                  nvraid.sys            10.6.0.22                             
    nvstor           nvstor                                                                  nvstor.sys            10.6.0.22                             
    Parport                                                         parport.sys           6.3.9600.16384                        
    partmgr                                                                 partmgr.sys           6.3.9600.16384                        
    pci               PCI                                                         pci.sys               6.3.9600.17238                        
    pciide           pciide                                                                  pciide.sys            6.3.9600.16384                        
    pcmcia           pcmcia                                                                  pcmcia.sys            6.3.9600.16384                        
    pcw              Performance Counters for Windows Driver                                 pcw.sys               6.3.9600.16384                        
    pdc              pdc                                                                     pdc.sys               6.3.9600.16453                        
    PEAUTH           PEAUTH                                                                  peauth.sys            6.3.9600.17031                        
    PptpMiniport     -   (PPTP)                                        raspptp.sys           6.3.9600.16384                        
    Processor                                                               processr.sys          6.3.9600.16384                        
    Psched             QoS                                                 pacer.sys             6.3.9600.16384                        
    QIOMem           Generic IO & Memory Access                                              QIOMem.sys            3.1.0.0                               
    QWAVEdrv          QWAVE                                                           qwavedrv.sys          6.3.9600.16384                        
    RasAcd           Remote Access Auto Connection Driver                                    rasacd.sys            6.3.9600.16384                        
    RasAgileVpn      -   (IKEv2)                                       AgileVpn.sys          6.3.9600.17111                        
    Rasl2tp          -   (L2TP)                                        rasl2tp.sys           6.3.9600.16384                        
    RasPppoe          PPPOE                                          raspppoe.sys          6.3.9600.16384                        
    RasSstp          -   (SSTP)                                        rassstp.sys           6.3.9600.16384                        
    rdbss                                               rdbss.sys             6.3.9600.16493             
    rdpbus                          rdpbus.sys            6.3.9600.16384                        
    RDPDR                               rdpdr.sys             6.3.9600.16384                        
    RdpVideoMiniport  Remote Desktop Video Miniport Driver                                    rdpvideominiport.sys  6.3.9600.16384                        
    rdyboost         ReadyBoost                                                              rdyboost.sys          6.3.9600.17031                        
    ReFS             ReFS                                                                                                                     
    rspndr                           rspndr.sys            6.3.9600.16384                        
    RSUSBSTOR        RtsUStor.Sys Realtek USB Card Reader                                    RtsUStor.sys          6.3.9600.30175                        
    RTWlanE          Realtek Wireless LAN 802.11n PCI-E Network Adapter                      rtwlane.sys           2012.14.417.2014                       
    s3cap            s3cap                                                                   vms3cap.sys           6.3.9600.16384                        
    sbp2port         SBP-2   /                                   sbp2port.sys          6.3.9600.16384                        
    scfilter           -  PnP                                  scfilter.sys          6.3.9600.16384                        
    sdbus            sdbus                                                                   sdbus.sys             6.3.9600.17031                        
    sdstor             SD Storage                                                sdstor.sys            6.3.9600.17031                        
    secdrv           Security Driver                                                                                                                     
    SerCx            Serial UART Support Library                                             SerCx.sys             6.3.9600.16384                        
    SerCx2           Serial UART Support Library                                             SerCx2.sys            6.3.9600.16444                        
    Serenum            Serenum                                                 serenum.sys           6.3.9600.16384                        
    Serial                                                      serial.sys            6.3.9600.16384                        
    sermouse            .                                             sermouse.sys          6.3.9600.16384                        
    sfloppy                                                            sfloppy.sys           6.3.9600.16384                        
    SiSRaid2         SiSRaid2                                                                SiSRaid2.sys          5.1.1039.2600                         
    SiSRaid4         SiSRaid4                                                                sisraid4.sys          5.1.1039.3600                         
    SmartDefragDriver  SmartDefragDriver                                                       SmartDefragDriver.sys  2.0.2.0                               
    spaceport                                                    spaceport.sys         6.3.9600.17238                        
    SpbCx            Simple Peripheral Bus Support Library                                   SpbCx.sys             6.3.9600.16384                        
    srv                Server SMB 1.xxx                                        srv.sys               6.3.9600.17238             
    srv2               Server SMB 2.xxx                                        srv2.sys              6.3.9600.17238             
    srvnet           srvnet                                                                  srvnet.sys            6.3.9600.17222             
    stexstor         stexstor                                                                stexstor.sys          5.1.0.10                              
    storahci           SATA AHCI ()                              storahci.sys          6.3.9600.16384                        
    storflt            Hyper-V                                            vmstorfl.sys          6.3.9600.16384                        
    stornvme           NVM Express ()                            stornvme.sys          6.3.9600.16421                        
    storvsc          storvsc                                                                 storvsc.sys           6.3.9600.16384                        
    storvsp          storvsp                                                                 storvsp.sys           6.3.9600.16384                        
    swenum                                                             swenum.sys            6.3.9600.16384                        
    SynTP            Synaptics TouchPad Driver                                               SynTP.sys             18.0.7.0                              
    tap0901          TAP-Win32 Adapter V9                                                    tap0901.sys           9.0.0.9                               
    Tcpip              TCP/IP                                                tcpip.sys             6.3.9600.17238                        
    TCPIP6             IPv6 (Microsoft)                                      tcpip.sys             6.3.9600.17238                        
    tcpipreg         TCP/IP Registry Compatibility                                           tcpipreg.sys          6.3.9600.17041                        
    tdx                NetIO Legacy TDI                                      tdx.sys               6.3.9600.16384                        
    terminpt         Microsoft Remote Desktop Input Driver                                   terminpt.sys          6.3.9600.16384                        
    Thotkey          Toshiba Hotkey Driver                                                   Thotkey.sys           8.0.0.0                               
    TPM              TPM                                                                     tpm.sys               6.3.9600.16384                        
    TsUsbFlt         TsUsbFlt                                                                tsusbflt.sys          6.3.9600.16384                        
    TsUsbGD           USB-                     TsUsbGD.sys           6.3.9600.16384                        
    tunnel                Microsoft                        tunnel.sys            6.3.9600.16384                        
    TVALZ            TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver  TVALZ_O.SYS           2.0.0.3                               
    uagp35           Microsoft AGPv3.5                                                 uagp35.sys            6.3.9600.16384                        
    UASPStor          USB- SCSI (UAS)                                       uaspstor.sys          6.3.9600.16384                        
    UCX01000         USB Controller Extension                                                ucx01000.sys          6.3.9600.17031                        
    udfs             udfs                                                                    udfs.sys              6.3.9600.16384             
    UEFI              UEFI ()                                               UEFI.sys              6.3.9600.16384                        
    uliagpkx         Uli-   AGP                                                    uliagpkx.sys          6.3.9600.16384                        
    umbus            UMBus                                               umbus.sys             6.3.9600.16384                        
    UmPass            UMPass Microsoft                                                umpass.sys            6.3.9600.16384                        
    usbccgp              USB (Microsoft)         usbccgp.sys           6.3.9600.17238                        
    usbcir           eHome   (USBCIR)                                     usbcir.sys            6.3.9600.16384                        
    usbehci            Microsoft USB 2.0  -       usbehci.sys           6.3.9600.17195                        
    usbhub             USB- ()                      usbhub.sys            6.3.9600.17238                        
    USBHUB3           SuperSpeed                                                 UsbHub3.sys           6.3.9600.17238                        
    usbohci            Microsoft USB  -              usbohci.sys           6.3.9600.16384                        
    usbprint           Microsoft USB                                           usbprint.sys          6.3.9600.16384                        
    USBSTOR              USB                                  USBSTOR.SYS           6.3.9600.17031                        
    usbuhci            Microsoft USB  -         usbuhci.sys           6.3.9600.17195                        
    usbvideo         USB- (WDM)                                               usbvideo.sys          6.3.9600.16384                        
    USBXHCI          xHCI- - USB                                    USBXHCI.SYS           6.3.9600.17031                        
    vdrvroot            ()                           vdrvroot.sys          6.3.9600.16384                        
    VerifierExt      VerifierExt                                                             VerifierExt.sys       6.3.9600.16404                        
    vhdmp            vhdmp                                                                   vhdmp.sys             6.3.9600.16521                        
    viaide           viaide                                                                  viaide.sys            6.0.6000.170                          
    Vid              Vid                                                                     Vid.sys               6.3.9600.16384                        
    vmbus             VMBus                                                              vmbus.sys             6.3.9600.16384                        
    VMBusHID         VMBusHID                                                                VMBusHID.sys          6.3.9600.16384                        
    vmbusr           Virtual Machine Bus Provider                                            vmbusr.sys            6.3.9600.16384                        
    volmgr                                                             volmgr.sys            6.3.9600.16384                        
    volmgrx                                                        volmgrx.sys           6.3.9600.16384                        
    volsnap                                                         volsnap.sys           6.3.9600.17215                        
    vpci             Microsoft Hyper-V Virtual PCI Bus                                       vpci.sys              6.3.9600.16384                        
    vpcivsp           PCI Microsoft Hyper-V                                            vpcivsp.sys           6.3.9600.16384                        
    vsmraid          vsmraid                                                                 vsmraid.sys           7.0.9200.6320                         
    VSTXRAID          RAID-   VIA StorX  Windows  vstxraid.sys          8.0.9200.8110                         
    vwifibus           Virtual WiFi                                               vwifibus.sys          6.3.9600.16384                        
    vwififlt         Virtual WiFi Filter Driver                                              vwififlt.sys          6.3.9600.17111                        
    vwifimp          Virtual WiFi Miniport Service                                           vwifimp.sys           6.3.9600.17111                        
    WacomPen         Wacom -                                wacompen.sys          6.3.9600.16384                        
    Wanarp              IP ARP                                       wanarp.sys            6.3.9600.16384                        
    Wanarpv6            IPv6 ARP                                     wanarp.sys            6.3.9600.16384                        
    WdBoot              Windows                                      WdBoot.sys            4.5.218.0                             
    Wdf01000                                                 Wdf01000.sys          1.13.9600.16384                       
    WdFilter          -  Windows                                  WdFilter.sys          4.5.218.0                  
    WdNisDrv              Windows                       WdNisDrv.sys          4.5.218.0                             
    WFPLWFS            Microsoft Windows                                  wfplwfs.sys           6.3.9600.17042                        
    WIMMount         WIMMount                                                                wimmount.sys          6.3.9600.16384             
    WinDivert1.1     WinDivert1.1                                                            WinDivert.sys         1.0.0.0                               
    WinRing0_1_2_0   WinRing0_1_2_0                                                                                                           
    WinUsb           WinUsb                                                                  WinUsb.sys            6.3.9600.16384                        
    WmiAcpi          Microsoft Windows Management Interface for ACPI                         wmiacpi.sys           6.3.9600.16384                        
    Wof              Windows Overlay File System Filter Driver                                                                                
    wpcfltr          Family Safety Filter Driver                                             wpcfltr.sys           6.3.9600.17112                        
    WpdUpFltr        WPD Upper Class Filter Driver                                           WpdUpFltr.sys         6.3.9600.16384                        
    ws2ifsl           WinSock IFS                                                     ws2ifsl.sys           6.3.9600.16384                        
    WSDPrintDevice     WSD                                                    WSDPrint.sys          6.3.9600.16384                        
    WudfPf           User Mode Driver Frameworks Platform Driver                             WudfPf.sys            6.3.9600.17195                        
    WUDFRd           Windows Driver Foundation        WUDFRd.sys            6.3.9600.17195                        
    WUDFWpdFs        WUDFWpdFs                                                               WUDFRd.sys            6.3.9600.17195                        
    WUDFWpdMtp       WUDFWpdMtp                                                              WUDFRd.sys            6.3.9600.17195                        


--------[  ]------------------------------------------------------------------------------------------------------

    AdAppMgrSvc                        Autodesk Application Manager Service                                    AdAppMgrSvc.exe       3.0.155.0                      LocalSystem
    AdvancedSystemCareService7         Advanced SystemCare Service 7                                           ASCService.exe        7.0.0.12                       LocalSystem
    AeLookupSvc                                                              svchost.exe           6.3.9600.16384                       localSystem
    ALG                                                                             alg.exe               6.3.9600.16384                 NT AUTHORITY\LocalService
    AMD External Events Utility        AMD External Events Utility                                             atiesrxx.exe          6.14.11.1164                   LocalSystem
    AMD FUEL Service                   AMD FUEL Service                                                        Program                                              LocalSystem
    AppIDSvc                                                                            svchost.exe           6.3.9600.16384                       NT Authority\LocalService
    Appinfo                                                                                 svchost.exe           6.3.9600.16384                       LocalSystem
    AppMgmt                                                                              svchost.exe           6.3.9600.16384                       LocalSystem
    AppReadiness                                                                           svchost.exe           6.3.9600.16384                       LocalSystem
    AppXSvc                              AppX (AppXSVC)                                     svchost.exe           6.3.9600.16384                       LocalSystem
    AudioEndpointBuilder                   Windows Audio                        svchost.exe           6.3.9600.16384                       LocalSystem
    Audiosrv                           Windows Audio                                                           svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    Autodesk Content Service           Autodesk Content Service                                                Connect.Service.ContentService.exe  20.0.51.0                      LocalSystem
    avast! Antivirus                   avast! Antivirus                                                        AvastSvc.exe          9.0.2021.515                         LocalSystem
    avast! Firewall                    avast! Firewall                                                         afwServ.exe           9.0.2021.515                         LocalSystem
    AxInstSV                            ActiveX (AxInstSV)                                           svchost.exe           6.3.9600.16384                       LocalSystem
    BDESVC                                BitLocker                                      svchost.exe           6.3.9600.16384                       localSystem
    BFE                                                                                 svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    BITS                                   (BITS)                         svchost.exe           6.3.9600.16384                       LocalSystem
    Bonjour Service                     Bonjour                                                          mDNSResponder.exe     3.0.0.10                       LocalSystem
    BrokerInfrastructure                                                       svchost.exe           6.3.9600.16384                       LocalSystem
    Browser                                                                                  svchost.exe           6.3.9600.16384                       LocalSystem
    bthserv                              Bluetooth                                              svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    CertPropSvc                                                                      svchost.exe           6.3.9600.16384                       LocalSystem
    COMSysApp                            COM+                                               dllhost.exe           6.3.9600.16384                 LocalSystem
    CryptSvc                                                                                 svchost.exe           6.3.9600.16384                       NT Authority\NetworkService
    CscService                                                                                  svchost.exe           6.3.9600.16384                       LocalSystem
    DcomLaunch                            DCOM-                                   svchost.exe           6.3.9600.16384                       LocalSystem
    defragsvc                                                                                 svchost.exe           6.3.9600.16384                 localSystem
    DeviceAssociationService                                                       svchost.exe           6.3.9600.16384                       LocalSystem
    DeviceInstall                                                                      svchost.exe           6.3.9600.16384                       LocalSystem
    Dhcp                               DHCP-                                                             svchost.exe           6.3.9600.16384                       NT Authority\LocalService
    Dnscache                           DNS-                                                              svchost.exe           6.3.9600.16384                       NT AUTHORITY\NetworkService
    dot3svc                                                                              svchost.exe           6.3.9600.16384                       localSystem
    DPS                                                                               svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    DsmSvc                                                                          svchost.exe           6.3.9600.16384                       LocalSystem
    Eaphost                                (EAP)                         svchost.exe           6.3.9600.16384                       localSystem
    EFS                                   (EFS)                                      lsass.exe             6.3.9600.16384                       LocalSystem
    EventLog                             Windows                                                  svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    EventSystem                          COM+                                                    svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    Fax                                                                                                    fxssvc.exe            6.3.9600.16384                 NT AUTHORITY\NetworkService
    fdPHost                                                                    svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    FDResPub                                                               svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    fhsvc                                                                                   svchost.exe           6.3.9600.16384                       LocalSystem
    FlexNet Licensing Service 64       FlexNet Licensing Service 64                                            FNPLicensingService64.exe  11.12.0.0                      LocalSystem
    FontCache                             Windows                                             svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    FontCache3.0.0.0                     Windows Presentation Foundation 3.0.0.0                     PresentationFontCache.exe  3.0.6920.7903                  NT Authority\LocalService
    gpsvc                                                                               svchost.exe           6.3.9600.16384                       LocalSystem
    hidserv                              HID-                                                svchost.exe           6.3.9600.16384                       LocalSystem
    hkmsvc                                                      svchost.exe           6.3.9600.16384                       localSystem
    HomeGroupListener                                                              svchost.exe           6.3.9600.16384                       LocalSystem
    HomeGroupProvider                                                                   svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    HP LaserJet Service                HP LaserJet Service                                                     HPLaserJetService.exe  7.15.635.0                     LocalSystem
    HPSIService                        HP SI Service                                                           HPSIsvc.exe           2012.1225.1.63009                LocalSystem
    IEEtwCollectorService                ETW Internet Explorer                                   IEEtwCollector.exe    11.0.9600.16438                LocalSystem
    IKEEXT                               IPsec        IP     svchost.exe           6.3.9600.16384                       LocalSystem
    iphlpsvc                             IP                                               svchost.exe           6.3.9600.16384                       LocalSystem
    KeyIso                               CNG                                                     lsass.exe             6.3.9600.16384                       LocalSystem
    KtmRm                              KtmRm                            svchost.exe           6.3.9600.16384                       NT AUTHORITY\NetworkService
    LanmanServer                                                                                         svchost.exe           6.3.9600.16384                       LocalSystem
    LanmanWorkstation                                                                            svchost.exe           6.3.9600.16384                       NT AUTHORITY\NetworkService
    lfsvc                                  Windows                     svchost.exe           6.3.9600.16384                       LocalSystem
    LiveUpdateSvc                      LiveUpdate                                                              LiveUpdate.exe        2.1.0.1051                     LocalSystem
    lltdsvc                                                                             svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    lmhosts                              NetBIOS  TCP/IP                                   svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    LSM                                                                               svchost.exe           6.3.9600.16384                       LocalSystem
    mitsijm2015                          Autodesk Simulation Moldflow MITSI 2015               mitsijm.exe           13.41.5.0                      LocalSystem
    MMCSS                                                                         svchost.exe           6.3.9600.16384                       LocalSystem
    MpsSvc                              Windows                                                      svchost.exe           6.3.9600.16384                       NT Authority\LocalService
    MSDTC                                                                   msdtc.exe             2001.12.10530.16384                NT AUTHORITY\NetworkService
    MSiSCSI                               iSCSI                                      svchost.exe           6.3.9600.16384                       LocalSystem
    msiserver                           Windows                                                      msiexec.exe           5.0.9600.16384                 LocalSystem
    MsKeyboardFilter                   Microsoft Keyboard Filter                                               svchost.exe           6.3.9600.16384                       LocalSystem
    napagent                                                                         svchost.exe           6.3.9600.16384                       NT AUTHORITY\NetworkService
    NcaSvc                                                                           svchost.exe           6.3.9600.16384                       LocalSystem
    NcbService                                                                        svchost.exe           6.3.9600.16384                       LocalSystem
    NcdAutoSetup                                                        svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    Netlogon                                                                                lsass.exe             6.3.9600.16384                       LocalSystem
    Netman                                                                                   svchost.exe           6.3.9600.16384                       LocalSystem
    netprofm                                                                                  svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    NetTcpPortSharing                       Net.Tcp                                  SMSvcHost.exe         4.0.30319.33440                      NT AUTHORITY\LocalService
    NlaSvc                                                                     svchost.exe           6.3.9600.16384                       NT AUTHORITY\NetworkService
    nsi                                                                          svchost.exe           6.3.9600.16384                       NT Authority\LocalService
    ose                                Office  Source Engine                                                   OSE.EXE               15.0.4454.1000                 LocalSystem
    p2pimsvc                                                            svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    p2psvc                                                                         svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    PcaSvc                                                               svchost.exe           6.3.9600.16384                       LocalSystem
    PeerDistSvc                        BranchCache                                                             svchost.exe           6.3.9600.16384                       NT AUTHORITY\NetworkService
    PerfHost                                                           perfhost.exe          6.3.9600.16384                 NT AUTHORITY\LocalService
    pla                                                                    svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    PlugPlay                           Plug and Play                                                           svchost.exe           6.3.9600.16384                       LocalSystem
    PNRPAutoReg                            PNRP                                 svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    PNRPsvc                             PNRP                                                           svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    PolicyAgent                          IPsec                                                    svchost.exe           6.3.9600.16384                       NT Authority\NetworkService
    Power                                                                                               svchost.exe           6.3.9600.16384                       LocalSystem
    PrintNotify                                                              svchost.exe           6.3.9600.16384                       LocalSystem
    ProfSvc                                                                         svchost.exe           6.3.9600.16384                       LocalSystem
    QWAVE                              Quality Windows Audio Video Experience                                  svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    RasAuto                                                 svchost.exe           6.3.9600.16384                       localSystem
    RasMan                                                                svchost.exe           6.3.9600.16384                       localSystem
    RemoteAccess                                                                  svchost.exe           6.3.9600.16384                       localSystem
    RemoteRegistry                                                                              svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    RpcEptMapper                          RPC                                        svchost.exe           6.3.9600.16384                       NT AUTHORITY\NetworkService
    RpcLocator                             (RPC)                                locator.exe           6.3.9600.16384                 NT AUTHORITY\NetworkService
    RpcSs                                 (RPC)                                          svchost.exe           6.3.9600.16384                       NT AUTHORITY\NetworkService
    SamSs                                                                   lsass.exe             6.3.9600.16384                       LocalSystem
    SCardSvr                           -                                                             svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    ScDeviceEnum                           -                         svchost.exe           6.3.9600.16384                       LocalSystem
    Schedule                                                                                 svchost.exe           6.3.9600.16384                       LocalSystem
    SCPolicySvc                          -                                            svchost.exe           6.3.9600.16384                       LocalSystem
    seclogon                                                                              svchost.exe           6.3.9600.16384                       LocalSystem
    SENS                                                                    svchost.exe           6.3.9600.16384                       LocalSystem
    SensrSvc                                                                        svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    SessionEnv                                                           svchost.exe           6.3.9600.16384                       localSystem
    SharedAccess                             (ICS)                            svchost.exe           6.3.9600.16384                       LocalSystem
    ShellHWDetection                                                            svchost.exe           6.3.9600.16384                       LocalSystem
    smphost                            SMP   ()                                   svchost.exe           6.3.9600.16384                 NT AUTHORITY\NetworkService
    SNMPTRAP                            SNMP                                                            snmptrap.exe          6.3.9600.16384                 NT AUTHORITY\LocalService
    Spooler                                                                                     spoolsv.exe           6.3.9600.17238                 LocalSystem
    sppsvc                                                                        sppsvc.exe            6.3.9600.16497                 NT AUTHORITY\NetworkService
    SSDPSRV                             SSDP                                                        svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    SstpSvc                             SSTP                                                             svchost.exe           6.3.9600.16384                       NT Authority\LocalService
    StartMenuService                   StartMenu8 Service                                                      StartMenuServices.exe  1.0.0.0                        LocalSystem
    Steam Client Service               Steam Client Service                                                    SteamService.exe      2.32.45.1                      LocalSystem
    stisvc                                Windows (WIA)                               svchost.exe           6.3.9600.16384                 NT Authority\LocalService
    StorSvc                                                                                     svchost.exe           6.3.9600.16384                       LocalSystem
    svsvc                                                                                       svchost.exe           6.3.9600.16384                       LocalSystem
    swprv                                  (Microsoft)                  svchost.exe           6.3.9600.16384                 LocalSystem
    SysMain                            Superfetch                                                              svchost.exe           6.3.9600.16384                       LocalSystem
    SystemEventsBroker                                                                   svchost.exe           6.3.9600.16384                       LocalSystem
    TabletInputService                                         svchost.exe           6.3.9600.16384                       LocalSystem
    TapiSrv                                                                                           svchost.exe           6.3.9600.16384                       NT AUTHORITY\NetworkService
    TermService                                                                    svchost.exe           6.3.9600.16384                       NT Authority\NetworkService
    Themes                                                                                                 svchost.exe           6.3.9600.16384                       LocalSystem
    THREADORDER                                                                       svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    TimeBroker                                                                                    svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    TrkWks                                                                 svchost.exe           6.3.9600.16384                       LocalSystem
    TrustedInstaller                     Windows                                              TrustedInstaller.exe  6.3.9600.17031                 localSystem
    UI0Detect                                                                     UI0Detect.exe         6.3.9600.16384                 LocalSystem
    UmRdpService                                svchost.exe           6.3.9600.16384                       localSystem
    upnphost                             PNP-                                        svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    USBSafelyRemoveService             USB Safely Remove Assistant                                             USBSRService.exe      5.2.3.1205                     LocalSystem
    VaultSvc                                                                             lsass.exe             6.3.9600.16384                       LocalSystem
    vds                                                                                         vds.exe               6.3.9600.17031                 LocalSystem
    vmicguestinterface                    Hyper-V                                       svchost.exe           6.3.9600.16384                       LocalSystem
    vmicheartbeat                        (Hyper-V)                                                 svchost.exe           6.3.9600.16384                       LocalSystem
    vmickvpexchange                       (Hyper-V)                                         svchost.exe           6.3.9600.16384                       LocalSystem
    vmicrdv                                 Hyper-V                   svchost.exe           6.3.9600.16384                       LocalSystem
    vmicshutdown                             (Hyper-V)                     svchost.exe           6.3.9600.16384                       LocalSystem
    vmictimesync                          Hyper-V                                    svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    vmicvss                                  Hyper-V                    svchost.exe           6.3.9600.16384                       LocalSystem
    VSS                                                                                  vssvc.exe             6.3.9600.17083                 LocalSystem
    W32Time                              Windows                                                  svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    wbengine                                                                wbengine.exe          6.3.9600.17031                 localSystem
    WbioSrvc                             Windows                                           svchost.exe           6.3.9600.16384                       LocalSystem
    Wcmsvc                               Windows                                           svchost.exe           6.3.9600.16384                       NT Authority\LocalService
    wcncsvc                              Windows -                   svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    WcsPlugInService                     Windows (WCS)                                          svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    WdiServiceHost                                                                        svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    WdiSystemHost                                                                        svchost.exe           6.3.9600.16384                       LocalSystem
    WdNisSvc                               Windows                                  NisSrv.exe                                           NT AUTHORITY\LocalService
    WebClient                          -                                                              svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    Wecsvc                               Windows                                                 svchost.exe           6.3.9600.16384                       NT AUTHORITY\NetworkService
    WEPHOSTSVC                             Windows                               svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    wercplsupport                          "     "  svchost.exe           6.3.9600.16384                       localSystem
    WerSvc                                Windows                                       svchost.exe           6.3.9600.16384                 localSystem
    WiaRpc                                                               svchost.exe           6.3.9600.16384                       LocalSystem
    WinDefend                            Windows                                                MsMpEng.exe                                          LocalSystem
    WinHttpAutoProxySvc                   - WinHTTP                   svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    Winmgmt                              Windows                                       svchost.exe           6.3.9600.16384                       localSystem
    WinRM                                 Windows (WS-Management)                    svchost.exe           6.3.9600.16384                       NT AUTHORITY\NetworkService
    WlanSvc                              WLAN                                               svchost.exe           6.3.9600.16384                       LocalSystem
    wlidsvc                                                             svchost.exe           6.3.9600.16384                       LocalSystem
    wmiApSrv                             WMI                                          WmiApSrv.exe          6.3.9600.16384                 localSystem
    WMPNetworkSvc                           Windows Media               wmpnetwk.exe                                         NT AUTHORITY\NetworkService
    workfolderssvc                                                                                 svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    WPCSvc                                                                                 svchost.exe           6.3.9600.16384                       NT Authority\LocalService
    WPDBusEnum                                                           svchost.exe           6.3.9600.16384                       LocalSystem
    wscsvc                                                                         svchost.exe           6.3.9600.16384                       NT AUTHORITY\LocalService
    WSearch                            Windows Search                                                          SearchIndexer.exe     7.0.9600.17031                 LocalSystem
    WSService                            Windows (WSService)                                     svchost.exe           6.3.9600.16384                       LocalSystem
    wuauserv                             Windows                                                svchost.exe           6.3.9600.16384                       LocalSystem
    wudfsvc                            Windows Driver Foundation - User-mode Driver Framework                  svchost.exe           6.3.9600.16384                       LocalSystem
    WwanSvc                             WWAN                                                      svchost.exe           6.3.9600.16384                       NT Authority\LocalService


--------[  AX ]----------------------------------------------------------------------------------------------------

    bdaplgin.ax                6.3.9600.16384              Microsoft BDA Device Control Plug-in for MPEG2 based networks.
    g711codc.ax                6.3.9600.16384              Intel G711 CODEC
    iac25_32.ax                2.0.5.53                      Indeo audio
    ir41_32.ax                 6.3.9600.16384              IR41_32 WRAPPER DLL
    ivfsrc.ax                  5.10.2.51                    Intel Indeo video IVF  5.10
    ksproxy.ax                 6.3.9600.16384              WDM Streaming ActiveMovie Proxy
    kstvtune.ax                6.3.9600.16384               - WDM
    kswdmcap.ax                6.3.9600.16384                WDM
    ksxbar.ax                  6.3.9600.16384              WDM Streaming Crossbar
    mpeg2data.ax               6.6.9600.16384              Microsoft MPEG-2 Section and Table Acquisition Module
    mpg2splt.ax                6.6.9600.16384              DirectShow MPEG-2 Splitter.
    msdvbnp.ax                 6.6.9600.16384              Microsoft Network Provider for MPEG2 based networks.
    msnp.ax                    6.6.9600.16384              Microsoft Network Provider for MPEG2 based networks.
    psisrndr.ax                6.6.9600.16384              Microsoft Transport Information Filter for MPEG2 based networks.
    realmediasplitter.ax       1.0.1.1                     RealMedia Splitter
    vbicodec.ax                6.6.9600.16384              Microsoft VBI Codec
    vbisurf.ax                 6.3.9600.16384              VBI Surface Allocator Filter
    vidcap.ax                  6.3.9600.16384              Video Capture Interface Server
    wstpager.ax                6.6.9600.16384              Microsoft Teletext Server


--------[  DLL ]---------------------------------------------------------------------------------------------------

    accessibilitycpl.dll       6.3.9600.16384                 
    acctres.dll                6.3.9600.16384                     (Microsoft)
    acledit.dll                6.3.9600.16384                 ACL
    aclui.dll                  6.3.9600.17199                
    acppage.dll                6.3.9600.17031                  ""
    actioncenter.dll           6.3.9600.17238               
    actioncentercpl.dll        6.3.9600.16384                 
    activeds.dll               6.3.9600.16384               DLL   AD
    actxprxy.dll               6.3.9600.17238              ActiveX Interface Marshaling Library
    admtmpl.dll                6.3.9600.17039               " "
    adprovider.dll             6.3.9600.16384               DLL adprovider
    adrclient.dll              6.3.9600.16384                 "  " ()
    adsldp.dll                 6.3.9600.16384              ADs LDAP Provider DLL
    adsldpc.dll                6.3.9600.16384               DLL  LDAP AD
    adsmsext.dll               6.3.9600.16384              ADs LDAP Provider DLL
    adsnt.dll                  6.3.9600.16384               DLL    Windows NT
    adtschema.dll              6.3.9600.17193                 
    advapi32.dll               6.3.9600.17031                API Windows 32
    advapi32res.dll            6.3.9600.16384                API Windows 32
    advpack.dll                11.0.9600.16384             ADVPACK
    aeevts.dll                 6.3.9600.16384                  
    amdhdl32.dll                                           
    amdocl.dll                 10.0.1348.5                 AMD Accelerated Parallel Processing OpenCL 1.2 Runtime
    amdpcom32.dll              8.14.10.23                  Radeon PCOM Universal Driver
    amstream.dll               6.6.9600.16384              DirectShow Runtime.
    apds.dll                   6.3.9600.16384                  Microsoft
    api-ms-win-appmodel-identity-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-appmodel-runtime-internal-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-appmodel-runtime-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-appmodel-runtime-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-appmodel-state-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-appmodel-state-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-base-bootconfig-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-base-util-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-apiquery-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-appcompat-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-appcompat-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-appinit-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-atoms-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-bem-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-bicltapi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-bicltapi-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-biplmapi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-biplmapi-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-biptcltapi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-biptcltapi-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-calendar-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-com-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-com-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-comm-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-com-private-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-console-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-console-l2-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-crt-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-crt-l2-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-datetime-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-datetime-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-debug-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-debug-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-delayload-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-delayload-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-errorhandling-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-errorhandling-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-fibers-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-fibers-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-fibers-l2-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-fibers-l2-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-file-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-file-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-file-l1-2-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-file-l2-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-file-l2-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-firmware-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-handle-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-heap-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-heap-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-heap-obsolete-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-interlocked-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-interlocked-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-io-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-io-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-job-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-job-l2-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-kernel32-legacy-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-kernel32-legacy-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-kernel32-private-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-libraryloader-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-libraryloader-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-libraryloader-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-libraryloader-private-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-localization-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-localization-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-localization-l1-2-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-localization-l2-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-localization-obsolete-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-localization-obsolete-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-localization-private-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-localregistry-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-memory-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-memory-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-memory-l1-1-2.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-multipleproviderrouter-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-namedpipe-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-namedpipe-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-namespace-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-normalization-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-path-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-privateprofile-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-processenvironment-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-processenvironment-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-processsecurity-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-processthreads-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-processthreads-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-processthreads-l1-1-2.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-processtopology-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-processtopology-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-processtopology-obsolete-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-processtopology-private-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-profile-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-psapi-ansi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-psapi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-psapi-obsolete-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-psm-app-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-psm-appnotify-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-psm-info-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-psm-key-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-psm-plm-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-psm-plm-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-quirks-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-realtime-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-registry-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-registry-l2-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-registry-private-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-registryuserspecific-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-rtlsupport-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-rtlsupport-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-shlwapi-legacy-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-shlwapi-obsolete-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-shutdown-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-sidebyside-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-stringansi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-string-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-string-l2-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-stringloader-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-stringloader-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-string-obsolete-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-synch-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-synch-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-sysinfo-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-sysinfo-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-sysinfo-l1-2-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-systemtopology-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-threadpool-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-threadpool-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-threadpool-legacy-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-threadpool-private-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-timezone-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-timezone-private-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-toolhelp-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-url-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-util-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-versionansi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-version-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-version-private-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-windowserrorreporting-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-winrt-error-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-winrt-error-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-winrt-errorprivate-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-winrt-errorprivate-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-winrt-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-winrt-propertysetprivate-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-winrt-registration-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-winrt-robuffer-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-winrt-roparameterizediid-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-winrt-string-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-wow64-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-xstate-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-xstate-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-core-xstate-l2-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-devices-config-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-devices-config-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-devices-query-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-devices-query-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-devices-swdevice-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-devices-swdevice-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-advapi32-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-advapi32-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-advapi32-l2-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-advapi32-l2-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-advapi32-l3-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-advapi32-l4-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-kernel32-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-kernel32-l2-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-normaliz-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-ole32-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-ole32-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-shell32-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-shlwapi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-shlwapi-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-shlwapi-l2-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-shlwapi-l2-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-user32-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-user32-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-downlevel-version-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-dx-d3dkmt-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-eventing-classicprovider-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-eventing-consumer-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-eventing-controller-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-eventing-legacy-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-eventing-obsolete-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-eventing-provider-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-eventlog-legacy-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-eventlog-private-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-gdi-dpiinfo-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-http-time-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-input-ie-interactioncontext-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-mm-joystick-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-mm-mci-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-mm-misc-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-mm-misc-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-mm-misc-l2-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-mm-mme-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-mm-playsound-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-mm-time-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-net-isolation-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-net-isolation-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-ntuser-ie-message-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-ntuser-ie-window-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-ntuser-ie-wmpointer-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-oobe-notification-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-perf-legacy-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-power-base-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-power-setting-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-ro-typeresolution-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-rtcore-navigation-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-rtcore-ntuser-clipboard-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-rtcore-ntuser-private-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-rtcore-ntuser-synch-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-rtcore-ntuser-window-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-rtcore-ntuser-windowstation-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-rtcore-ntuser-winevent-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-rtcore-ntuser-wmpointer-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-rtcore-ole32-clipboard-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-rtcore-session-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-activedirectoryclient-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-appcontainer-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-audit-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-audit-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-base-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-base-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-base-private-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-base-private-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-credentials-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-credentials-l2-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-cryptoapi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-grouppolicy-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-logon-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-lsalookup-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-lsalookup-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-lsalookup-l2-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-lsalookup-l2-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-lsapolicy-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-provider-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-sddl-ansi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-sddl-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-sddlparsecond-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-systemfunctions-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-trustee-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-security-trustee-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-service-core-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-service-core-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-service-management-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-service-management-l2-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-service-private-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-service-winsvc-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-service-winsvc-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-shcore-comhelpers-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-shcore-obsolete-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-shcore-registry-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-shcore-scaling-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-shcore-scaling-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-shcore-stream-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-shcore-stream-winrt-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-shcore-sysinfo-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-shcore-thread-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-shcore-unicodeansi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-shell-shellcom-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    api-ms-win-shell-shellfolders-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    apphelp.dll                6.3.9600.17031                 
    apphlpdm.dll               6.3.9600.16384                 
    appidapi.dll               6.3.9600.16384               API-  
    appidpolicyengineapi.dll   6.3.9600.16384              AppId Policy Engine API Module
    appmgmts.dll               6.3.9600.16384                
    appmgr.dll                 6.3.9600.16457                 
    apprepapi.dll              6.3.9600.16384              Application Reputation APIs Dll
    apprepsync.dll             6.3.9600.16384               AppRepSync
    appxalluserstore.dll       6.3.9600.17042              AppX All User Store DLL
    appxapplicabilityengine.dll  6.3.9600.16384              AppX Applicability Engine
    appxdeploymentclient.dll   6.3.9600.17042              DLL-   AppX
    appxpackaging.dll          6.3.9600.17227                  Appx
    appxsip.dll                6.3.9600.17227              Appx Subject Interface Package
    asferror.dll               12.0.9600.16384               ASF
    aspnet_counters.dll        4.0.30319.33440             Microsoft ASP.NET Performance Counter Shim DLL
    asycfilt.dll               6.3.9600.16384              
    atiadlxy.dll               6.14.10.1129                ADL
    aticalcl.dll               6.14.10.1848                ATI CAL compiler runtime
    aticaldd.dll               6.14.10.1848                ATI CAL DD
    aticalrt.dll               6.14.10.1848                ATI CAL runtime
    aticfx32.dll               8.17.10.1247                aticfx32.dll
    atidxx32.dll               8.17.10.525                 atidxx32.dll
    atigktxx.dll               8.14.1.6354                 atigktxx.dll
    atiglpxx.dll               8.14.1.6354                 atiglpxx.dll
    atimpc32.dll               8.14.10.23                  Radeon PCOM Universal Driver
    atioglxx.dll               6.14.10.12618               AMD OpenGL driver
    atiu9pag.dll               8.14.1.6354                 atiu9pag.dll
    atiumdag.dll               9.14.10.1001                atiumdag.dll
    atiumdva.dll               8.14.10.429                 Radeon Video Acceleration Universal Driver
    atiuxpag.dll               8.14.1.6354                 atiuxpag.dll
    atl.dll                    3.5.2284.0                  ATL Module for Windows XP (Unicode)
    atl100.dll                 10.0.40219.325              ATL Module for Windows
    atl110.dll                 11.0.60610.1                ATL Module for Windows
    atmfd.dll                  5.1.2.238                   Windows NT OpenType/Type 1 Font Driver
    atmlib.dll                 5.1.2.238                   Windows NT OpenType/Type 1 API Library.
    audiodev.dll               6.3.9600.16384                   
    audioeng.dll               6.3.9600.17090              Audio Engine
    audiokse.dll               6.3.9600.17090              Audio Ks Endpoint
    audioses.dll               6.3.9600.17090                
    auditnativesnapin.dll      6.3.9600.16384                    
    auditpolicygpinterop.dll   6.3.9600.16384                 
    auditpolmsg.dll            6.3.9600.16384                MMC  
    authbroker.dll             6.3.9600.17031              API WinRT  - 
    authext.dll                6.3.9600.16384                 
    authfwcfg.dll              6.3.9600.16384               Windows      
    authfwgp.dll               6.3.9600.16384               Windows c      
    authfwsnapin.dll           6.3.9600.16384              Microsoft.WindowsFirewall.SnapIn
    authfwwizfwk.dll           6.3.9600.16384              Wizard Framework
    authui.dll                 6.3.9600.17238                
    authz.dll                  6.3.9600.17031              Authorization Framework
    autoplay.dll               6.3.9600.16384               ( )
    avicap32.dll               6.3.9600.16384                 AVI
    avifil32.dll               6.3.9600.16384                 AVI
    avrt.dll                   6.3.9600.16384              Multimedia Realtime Runtime
    azroles.dll                6.3.9600.16384              azroles Module
    azroleui.dll               6.3.9600.16384               
    azsqlext.dll               6.3.9600.16384              AzMan Sql Audit Extended Stored Procedures Dll
    basecsp.dll                6.3.9600.16384                 - (Microsoft)
    batmeter.dll               6.3.9600.16384              Battery Meter Helper DLL
    bcd.dll                    6.3.9600.17031              BCD DLL
    bcp47langs.dll             6.3.9600.16384              BCP47 Language Classes
    bcrypt.dll                 6.3.9600.17031                 Windows
    bcryptprimitives.dll       6.3.9600.17120              Windows Cryptographic Primitives Library
    bidispl.dll                6.3.9600.16384              Bidispl DLL
    biocredprov.dll            6.3.9600.17031                 WinBio
    bitsperf.dll               7.7.9600.16384              Perfmon Counter Access
    bitsprx2.dll               7.7.9600.16384              Background Intelligent Transfer Service Proxy
    bitsprx3.dll               7.7.9600.16384              Background Intelligent Transfer Service 2.0 Proxy
    bitsprx4.dll               7.7.9600.16384              Background Intelligent Transfer Service 2.5 Proxy
    bitsprx5.dll               7.7.9600.16384              Background Intelligent Transfer Service 3.0 Proxy
    bitsprx6.dll               7.7.9600.16384              Background Intelligent Transfer Service 4.0 Proxy
    bitsprx7.dll               7.7.9600.16384              Background Intelligent Transfer Service 5.0 Proxy
    biwinrt.dll                6.3.9600.16384              Windows Background Broker Infrastructure
    blackbox.dll               11.0.9600.16384             BlackBox DLL
    bluetoothapis.dll          6.3.9600.17238              Bluetooth Usermode Api host
    bootvid.dll                6.3.9600.16384              VGA Boot Driver
    browcli.dll                6.3.9600.16384              Browser Service Client DLL
    browseui.dll               6.3.9600.16384              Shell Browser UI Library
    btpanui.dll                6.3.9600.16384                Bluetooth   
    bwcontexthandler.dll       1.0.0.1                      ContextH
    c_g18030.dll               6.3.9600.16384              GB18030 DBCS-Unicode Conversion DLL
    c_is2022.dll               6.3.9600.16384              ISO-2022 Code Page Translation DLL
    c_iscii.dll                6.3.9600.16384              ISCII Code Page Translation DLL
    cabinet.dll                6.3.9600.16384              Microsoft Cabinet File API
    cabview.dll                6.3.9600.16384                 CAB-
    callbuttons.dll            6.3.9600.16384              Windows Runtime CallButtonsServer DLL
    callbuttons.proxystub.dll  6.3.9600.16384              Windows Runtime CallButtonsServer ProxyStub DLL
    capiprovider.dll           6.3.9600.16384               DLL capiprovider
    capisp.dll                 6.3.9600.16384              Sysprep cleanup dll for CAPI
    catsrv.dll                 2001.12.10530.16384         COM+ Configuration Catalog Server
    catsrvps.dll               2001.12.10530.16384         COM+ Configuration Catalog Server Proxy/Stub
    catsrvut.dll               2001.12.10530.16384         COM+ Configuration Catalog Server Utilities
    cca.dll                    6.6.9600.16384              CCA DirectShow Filter.
    cdosys.dll                 6.6.9600.16384              Microsoft CDO for Windows Library
    certca.dll                 6.3.9600.16384                 Microsoft Active Directory
    certcli.dll                6.3.9600.17231                 Microsoft Active Directory
    certcredprovider.dll       6.3.9600.16384                 
    certenc.dll                6.3.9600.16384              Active Directory Certificate Services Encoding
    certenroll.dll             6.3.9600.16384                  Active Directory Microsoft
    certenrollui.dll           6.3.9600.16384                  X509
    certmgr.dll                6.3.9600.16384                
    certpoleng.dll             6.3.9600.16384                
    cewmdm.dll                 12.0.9600.16384               Windows CE WMDM
    cfgbkend.dll               6.3.9600.16384              Configuration Backend Interface
    cfgmgr32.dll               6.3.9600.16384              Configuration Manager DLL
    cfmifs.dll                 6.3.9600.16384              FmIfs Engine
    cfmifsproxy.dll            6.3.9600.16384              Microsoft FmIfs Proxy Library
    chartv.dll                 6.3.9600.16384              Chart View
    chxreadingstringime.dll    6.3.9600.16384              CHxReadingStringIME
    cic.dll                    6.3.9600.16384                CIC - MMC   
    clb.dll                    6.3.9600.16384                
    clbcatq.dll                2001.12.10530.16384         COM+ Configuration Catalog
    clfsw32.dll                6.3.9600.16384              Common Log Marshalling Win32 DLL
    cliconfg.dll               6.3.9600.16384              SQL Client Configuration Utility DLL
    clrhost.dll                6.3.9600.17031              In Proc server for managed servers in the Windows Runtime
    clusapi.dll                6.3.9600.17193               API 
    cmcfg32.dll                7.2.9600.16384                  Microsoft
    cmdext.dll                 6.3.9600.16384              cmd.exe Extension DLL
    cmdial32.dll               7.2.9600.16384               
    cmifw.dll                  6.3.9600.16384              Windows Firewall rule configuration plug-in
    cmipnpinstall.dll          6.3.9600.16384              PNP plugin installer for CMI
    cmlua.dll                  7.2.9600.16384                API   
    cmpbk32.dll                7.2.9600.16384              Microsoft Connection Manager Phonebook
    cmstplua.dll               7.2.9600.16384                API      
    cmutil.dll                 7.2.9600.16384                  (Microsoft)
    cngcredui.dll              6.3.9600.16384               Microsoft CNG CredUI
    cngprovider.dll            6.3.9600.16384               DLL cngprovider
    cnvfat.dll                 6.3.9600.16384              FAT File System Conversion Utility DLL
    colbact.dll                2001.12.10530.16384         COM+
    colorcnv.dll               6.3.9600.16384              Windows Media Color Conversion
    colorui.dll                6.3.9600.16384                 
    combase.dll                6.3.9600.17031              Microsoft COM  Windows
    comcat.dll                 6.3.9600.16384              Microsoft Component Category Manager Library
    comctl32.dll               5.82.9600.16384                  
    comdlg32.dll               6.3.9600.17238                 
    commondl.dll               1.0.0.30                    CommonDL DLL
    compobj.dll                3.10.0.103                  Windows Win16 Application Launcher
    comppkgsup.dll             12.0.9600.16384             Component Package Support DLL
    compstui.dll               6.3.9600.16384                   
    comrepl.dll                2001.12.10530.16384         COM+
    comres.dll                 2001.12.10530.16384          COM+
    comsnap.dll                2001.12.10530.16384         COM+ Explorer MMC Snapin
    comsvcs.dll                2001.12.10530.16384         COM+ Services
    comuid.dll                 2001.12.10530.16384         COM+ Explorer UI
    configureexpandedstorage.dll  6.3.9600.17031              ConfigureExpandedStorage
    connect.dll                6.3.9600.16384               
    connectedaccountstate.dll  6.3.9600.16384              ConnectedAccountState.dll
    console.dll                6.3.9600.16384                 
    coremmres.dll              6.3.9600.16384              General Core Multimedia Resources
    cpfilters.dll              6.6.9600.16384               PTFilter & Encypter/Decrypter Tagger Filters.
    credentialmigrationhandler.dll  6.3.9600.17039              Credential Migration Handler
    credssp.dll                6.3.9600.16384              Credential Delegation Security Package
    credui.dll                 6.3.9600.16384                 
    crtdll.dll                 4.0.1183.1                  Microsoft C Runtime Library
    crypt32.dll                6.3.9600.16431              API32 
    cryptbase.dll              6.3.9600.16384              Base cryptographic API DLL
    cryptdlg.dll               6.3.9600.16384                
    cryptdll.dll               6.3.9600.16384              Cryptography Manager
    cryptext.dll               6.3.9600.16384                
    cryptnet.dll               6.3.9600.16384              Crypto Network Related API
    cryptowinrt.dll            6.3.9600.16397              Crypto WinRT Library
    cryptsp.dll                6.3.9600.16384              Cryptographic Service Provider API
    crypttpmeksvc.dll          6.3.9600.16384              Cryptographic TPM Endorsement Key Services
    cryptui.dll                6.3.9600.16384                
    cryptuiwizard.dll          6.3.9600.16384                 (Microsoft)
    cryptxml.dll               6.3.9600.16384              API- XML DigSig
    cscapi.dll                 6.3.9600.16384              Offline Files Win32 API
    cscdll.dll                 6.3.9600.16384              Offline Files Temporary Shim
    cscobj.dll                 6.3.9600.16384               COM-   CSC API
    ctl3d32.dll                2.31.0.0                    Ctl3D 3D Windows Controls
    d2d1.dll                   6.3.9600.16473               Microsoft D2D
    d3d10.dll                  6.3.9600.16384              Direct3D 10 Runtime
    d3d10_1.dll                6.3.9600.16384              Direct3D 10.1 Runtime
    d3d10_1core.dll            6.3.9600.16384              Direct3D 10.1 Runtime
    d3d10core.dll              6.3.9600.16384              Direct3D 10 Runtime
    d3d10level9.dll            6.3.9600.16421              Direct3D 10 to Direct3D9 Translation Runtime
    d3d10warp.dll              6.3.9600.17211              Direct3D 10 Rasterizer
    d3d11.dll                  6.3.9600.17041              Direct3D 11 Runtime
    d3d8.dll                   6.3.9600.16384              Microsoft Direct3D
    d3d8thk.dll                6.3.9600.17095              Microsoft Direct3D OS Thunk Layer
    d3d9.dll                   6.3.9600.17095              Direct3D 9 Runtime
    d3dcompiler_33.dll         9.18.904.15                 Microsoft Direct3D
    d3dcompiler_34.dll         9.19.949.46                 Microsoft Direct3D
    d3dcompiler_35.dll         9.19.949.1104               Microsoft Direct3D
    d3dcompiler_36.dll         9.19.949.2111               Microsoft Direct3D
    d3dcompiler_37.dll         9.22.949.2248               Microsoft Direct3D
    d3dcompiler_38.dll         9.23.949.2378               Microsoft Direct3D
    d3dcompiler_39.dll         9.24.949.2307               Microsoft Direct3D
    d3dcompiler_40.dll         9.24.950.2656               Direct3D HLSL Compiler
    d3dcompiler_41.dll         9.26.952.2844               Direct3D HLSL Compiler
    d3dcompiler_42.dll         9.27.952.3022               Direct3D HLSL Compiler
    d3dcompiler_43.dll         9.29.952.3111               Direct3D HLSL Compiler
    d3dcompiler_47.dll         6.3.9600.16384              Direct3D HLSL Compiler
    d3dcsx_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dcsx_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dim.dll                  6.3.9600.16384              Microsoft Direct3D
    d3dim700.dll               6.3.9600.16384              Microsoft Direct3D
    d3dramp.dll                6.3.9600.16384              Microsoft Direct3D
    d3dx10.dll                 9.16.843.0                  Microsoft Direct3D
    d3dx10_33.dll              9.18.904.21                 Microsoft Direct3D
    d3dx10_34.dll              9.19.949.46                 Microsoft Direct3D
    d3dx10_35.dll              9.19.949.1104               Microsoft Direct3D
    d3dx10_36.dll              9.19.949.2009               Microsoft Direct3D
    d3dx10_37.dll              9.19.949.2187               Microsoft Direct3D
    d3dx10_38.dll              9.23.949.2378               Microsoft Direct3D
    d3dx10_39.dll              9.24.949.2307               Microsoft Direct3D
    d3dx10_40.dll              9.24.950.2656               Direct3D 10.1 Extensions
    d3dx10_41.dll              9.26.952.2844               Direct3D 10.1 Extensions
    d3dx10_42.dll              9.27.952.3001               Direct3D 10.1 Extensions
    d3dx10_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx11_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dx11_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx9_24.dll               9.5.132.0                   Microsoft DirectX for Windows
    d3dx9_25.dll               9.6.168.0                   Microsoft DirectX for Windows
    d3dx9_26.dll               9.7.239.0                   Microsoft DirectX for Windows
    d3dx9_27.dll               9.8.299.0                   Microsoft DirectX for Windows
    d3dx9_28.dll               9.10.455.0                  Microsoft DirectX for Windows
    d3dx9_29.dll               9.11.519.0                  Microsoft DirectX for Windows
    d3dx9_30.dll               9.12.589.0                  Microsoft DirectX for Windows
    d3dx9_31.dll               9.15.779.0                  Microsoft DirectX for Windows
    d3dx9_32.dll               9.16.843.0                  Microsoft DirectX for Windows
    d3dx9_33.dll               9.18.904.15                 Microsoft DirectX for Windows
    d3dx9_34.dll               9.19.949.46                 Microsoft DirectX for Windows
    d3dx9_35.dll               9.19.949.1104               Microsoft DirectX for Windows
    d3dx9_36.dll               9.19.949.2111               Microsoft DirectX for Windows
    d3dx9_37.dll               9.22.949.2248               Microsoft DirectX for Windows
    d3dx9_38.dll               9.23.949.2378               Microsoft DirectX for Windows
    d3dx9_39.dll               9.24.949.2307               Microsoft DirectX for Windows
    d3dx9_40.dll               9.24.950.2656               Direct3D 9 Extensions
    d3dx9_41.dll               9.26.952.2844               Direct3D 9 Extensions
    d3dx9_42.dll               9.27.952.3001               Direct3D 9 Extensions
    d3dx9_43.dll               9.29.952.3111               Direct3D 9 Extensions
    d3dxof.dll                 6.3.9600.16384              DirectX Files DLL
    dabapi.dll                 6.3.9600.16384              Desktop Activity Broker API
    dafprintprovider.dll       6.3.9600.17238               DLL   DAF
    daotpcredentialprovider.dll  6.3.9600.17136                ,    DirectAccess
    dataclen.dll               6.3.9600.17031                 Windows
    davclnt.dll                6.3.9600.17041              Web DAV Client DLL
    davhlpr.dll                6.3.9600.16384              DAV Helper DLL
    dbgeng.dll                 6.3.9600.16520              Windows Symbolic Debugger Engine
    dbghelp.dll                6.3.9600.16520              Windows Image Helper
    dbnetlib.dll               6.3.9600.16384              Winsock Oriented Net DLL for SQL Clients
    dbnmpntw.dll               6.3.9600.16384              Named Pipes Net DLL for SQL Clients
    dciman32.dll               6.3.9600.16384              DCI Manager
    dcomp.dll                  6.3.9600.17042              Microsoft DirectComposition Library
    ddaclsys.dll               6.3.9600.16384              SysPrep module for Resetting Data Drive ACL 
    ddoiproxy.dll              6.3.9600.16384              DDOI Interface Proxy
    ddores.dll                 6.3.9600.16384                  
    ddraw.dll                  6.3.9600.16384              Microsoft DirectDraw
    ddrawex.dll                6.3.9600.16384              Direct Draw Ex
    defaultdevicemanager.dll   6.3.9600.16384              Default Device Manager
    defaultprinterprovider.dll  6.3.9600.16384                Microsoft Windows  
    delegatorprovider.dll      6.3.9600.16384              WMI PassThru Provider for Storage Management
    deskadp.dll                6.3.9600.16384                 
    deskmon.dll                6.3.9600.16384                
    devdispitemprovider.dll    6.3.9600.16384               DeviceItem inproc devquery
    devenum.dll                6.6.9600.16384               .
    deviceaccess.dll           6.3.9600.16519              Device Broker And Policy COM Server
    deviceassociation.dll      6.3.9600.17031              Device Association Client DLL
    devicecenter.dll           6.3.9600.16397                
    devicedisplaystatusmanager.dll  6.3.9600.16384                 
    devicepairing.dll          6.3.9600.16384               ,   
    devicepairingfolder.dll    6.3.9600.16384                 
    devicepairingproxy.dll     6.3.9600.16384              Device Pairing Proxy Dll
    devicesetupstatusprovider.dll  6.3.9600.16384              DLL    
    deviceuxres.dll            6.3.9600.16384              Windows Device User Experience Resource File
    devmgr.dll                 6.3.9600.16384                 
    devobj.dll                 6.3.9600.16384              Device Information Set DLL
    devrtl.dll                 6.3.9600.16384              Device Management Run Time Library
    dfscli.dll                 6.3.9600.16384              Windows NT Distributed File System Client DLL
    dfshim.dll                 6.3.9600.16384              ClickOnce Application Deployment Support Library
    dfsshlex.dll               6.3.9600.16384                   DFS
    dhcpcmonitor.dll           6.3.9600.16384               (DLL)   DHCP
    dhcpcore.dll               6.3.9600.17111               DHCP-
    dhcpcore6.dll              6.3.9600.17111               DHCPv6
    dhcpcsvc.dll               6.3.9600.17111               DHCP-
    dhcpcsvc6.dll              6.3.9600.17111               DHCPv6
    dhcpqec.dll                6.3.9600.16384                   Microsoft DHCP
    dhcpsapi.dll               6.3.9600.16384               API  DHCP-c
    difxapi.dll                2.1.0.0                     Driver Install Frameworks for API library module
    dimsjob.dll                6.3.9600.16384               DLL  DIMS
    dimsroam.dll               6.3.9600.16384               DLL  DIMS  
    dinput.dll                 6.3.9600.16384              Microsoft DirectInput
    dinput8.dll                6.3.9600.16384              Microsoft DirectInput
    directdb.dll               6.3.9600.16384              Microsoft Direct Database API
    diskcopy.dll               6.3.9600.16384              Windows DiskCopy
    dismapi.dll                6.3.9600.17031              DISM API Framework
    dispex.dll                 5.8.9600.16384              Microsoft  DispEx
    display.dll                6.3.9600.17238                
    dlnashext.dll              12.0.9600.16384             DLNA Namespace DLL
    dmband.dll                 6.3.9600.16384              Microsoft DirectMusic Band
    dmcompos.dll               6.3.9600.16384              Microsoft DirectMusic Composer
    dmdlgs.dll                 6.3.9600.16384              Disk Management Snap-in Dialogs
    dmdskmgr.dll               6.3.9600.17031              Disk Management Snap-in Support Library
    dmdskres.dll               6.3.9600.16384                 
    dmdskres2.dll              6.3.9600.16384                 
    dmime.dll                  6.3.9600.16384              Microsoft DirectMusic Interactive Engine
    dmintf.dll                 6.3.9600.16384              Disk Management DCOM Interface Stub
    dmloader.dll               6.3.9600.16384              Microsoft DirectMusic Loader
    dmocx.dll                  6.3.9600.16384              TreeView OCX
    dmscript.dll               6.3.9600.16384              Microsoft DirectMusic Scripting
    dmstyle.dll                6.3.9600.16384              Microsoft DirectMusic Style Engline
    dmsynth.dll                6.3.9600.16384              Microsoft DirectMusic Software Synthesizer
    dmusic.dll                 6.3.9600.16384                Microsoft DirectMusic
    dmutil.dll                 6.3.9600.16384                 
    dmvdsitf.dll               6.3.9600.17031              Disk Management Snap-in Support Library
    dnsapi.dll                 6.3.9600.17039                API DNS-
    dnscmmc.dll                6.3.9600.16384               DLL  DNS  MMC
    dnssd.dll                  3.0.0.10                    Bonjour Client Library
    dnssdx.dll                 3.0.0.10                    Bonjour COM Component Library
    docprop.dll                6.3.9600.16384                OLE
    dot3api.dll                6.3.9600.16384              802.3 Autoconfiguration API
    dot3cfg.dll                6.3.9600.16384               Netsh  802.3
    dot3dlg.dll                6.3.9600.16384                UI  802.3
    dot3gpclnt.dll             6.3.9600.16384                   802.3
    dot3gpui.dll               6.3.9600.16384               "   802.3"
    dot3hc.dll                 6.3.9600.16384                 Dot3
    dot3msm.dll                6.3.9600.16384                   802.3
    dot3ui.dll                 6.3.9600.16384                802.3
    dpapi.dll                  6.3.9600.16384              Data Protection API
    dpapiprovider.dll          6.3.9600.16384               DLL dpapiprovider
    dplayx.dll                 6.3.9600.16384              DirectPlay Stub
    dpmodemx.dll               6.3.9600.16384              DirectPlay Stub
    dpnaddr.dll                6.3.9600.16384              DirectPlay Stub
    dpnathlp.dll               6.3.9600.16384              DirectPlay Stub
    dpnet.dll                  6.3.9600.16384              DirectPlay Stub
    dpnhpast.dll               6.3.9600.16384              DirectPlay Stub
    dpnhupnp.dll               6.3.9600.16384              DirectPlay Stub
    dpnlobby.dll               6.3.9600.16384              DirectPlay Stub
    dpwsockx.dll               6.3.9600.16384              DirectPlay Stub
    dpx.dll                    6.3.9600.16384              Microsoft(R) Delta Package Expander
    drmmgrtn.dll               11.0.9600.16384             DRM Migration DLL
    drmv2clt.dll               11.0.9600.16384             DRMv2 Client DLL
    drprov.dll                 6.3.9600.16384                   ,        ()
    drt.dll                    6.3.9600.16384                
    drtprov.dll                6.3.9600.16384              Distributed Routing Table Providers
    drttransport.dll           6.3.9600.16384              Distributed Routing Table Transport Provider
    drvstore.dll               6.3.9600.16384              Driver Store API
    dsauth.dll                 6.3.9600.16384              DS Authorization for Services
    dsdmo.dll                  6.3.9600.16384              DirectSound Effects
    dskquota.dll               6.3.9600.16384               DLL    Windows
    dskquoui.dll               6.3.9600.16384               DLL   
    dsound.dll                 6.3.9600.16384              DirectSound
    dsparse.dll                6.3.9600.16384              Active Directory Domain Services API
    dsprop.dll                 6.3.9600.16384                Active Directory
    dsquery.dll                6.3.9600.16384                 
    dsrole.dll                 6.3.9600.16384              DS Setup Client DLL
    dssec.dll                  6.3.9600.16384                 
    dssenh.dll                 6.3.9600.16384              Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider
    dsui.dll                   6.3.9600.16384                  
    dsuiext.dll                6.3.9600.16384                 
    dswave.dll                 6.3.9600.16384              Microsoft DirectMusic Wave
    dtsh.dll                   6.3.9600.16384               API     
    dui70.dll                  6.3.9600.17031               DirectUI Windows
    duser.dll                  6.3.9600.16384              Windows DirectUser Engine
    dwmapi.dll                 6.3.9600.17238               API     ()
    dwmcore.dll                6.3.9600.17041                Microsoft DWM
    dwrite.dll                 6.3.9600.17111               Microsoft DirectX Typography
    dxdiagn.dll                6.3.9600.16384                Microsoft DirectX
    dxgi.dll                   6.3.9600.17201              DirectX Graphics Infrastructure
    dxmasf.dll                 12.0.9600.16384             Microsoft Windows Media Component Removal File.
    dxptasksync.dll            6.3.9600.16384               Microsoft Windows DXP
    dxtmsft.dll                11.0.9600.17239             DirectX Media -- Image DirectX Transforms
    dxtrans.dll                11.0.9600.17239             DirectX Media -- DirectX Transform Core
    dxva2.dll                  6.3.9600.16384              DirectX Video Acceleration 2.0 DLL
    eapp3hst.dll               6.3.9600.16402              Microsoft ThirdPartyEapDispatcher
    eappcfg.dll                6.3.9600.16402                EAP
    eappgnui.dll               6.3.9600.16402                 EAP
    eapphost.dll               6.3.9600.16402                 EAPHost 
    eappprxy.dll               6.3.9600.16384              Microsoft EAPHost Peer Client DLL
    eapprovp.dll               6.3.9600.16384              EAP extension DLL
    eapqec.dll                 6.3.9600.16384                   Microsoft EAP
    easwrt.dll                 6.3.9600.17031              Exchange ActiveSync Windows Runtime DLL
    efsadu.dll                 6.3.9600.16384                
    efscore.dll                6.3.9600.16384                EFS
    efsutil.dll                6.3.9600.16384              EFS Utility Library
    efswrt.dll                 6.3.9600.16408              Storage Protection Windows Runtime DLL
    ehstorapi.dll              6.3.9600.16384              Windows Enhanced Storage API
    ehstorpwdmgr.dll           6.3.9600.16384                Microsoft Enhanced Storage
    els.dll                    6.3.9600.16384                
    elscore.dll                6.3.9600.16384               DLL   Els
    elshyph.dll                6.3.9600.16384              ELS Hyphenation Service
    elslad.dll                 6.3.9600.16384              ELS Language Detection
    elstrans.dll               6.3.9600.16384              ELS Transliteration Service
    encapi.dll                 6.3.9600.16384              Encoder API
    encdec.dll                 6.6.9600.16384                XDS     .
    eqossnap.dll               6.3.9600.16384                EQoS
    es.dll                     2001.12.10530.16384         COM+
    esent.dll                  6.3.9600.16384                  ESE  Microsoft(R) Windows(R)
    esentprf.dll               6.3.9600.16384              Extensible Storage Engine Performance Monitoring Library for Microsoft(R) Windows(R)
    etweseproviderresources.dll  6.3.9600.16384              Microsoft ESE ETW
    eventcls.dll               6.3.9600.16384              Microsoft Volume Shadow Copy Service event class
    evr.dll                    6.3.9600.16384                DLL   
    explorerframe.dll          6.3.9600.17031              ExplorerFrame
    expsrv.dll                 6.0.72.9589                 Visual Basic for Applications Runtime - Expression Service
    ext-ms-win-advapi32-auth-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-advapi32-encryptedfile-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-advapi32-eventingcontroller-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-advapi32-eventlog-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-advapi32-idletask-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-advapi32-lsa-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-advapi32-msi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-advapi32-ntmarta-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-advapi32-psm-app-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-advapi32-registry-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-advapi32-safer-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-advapi32-shutdown-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-appmodel-deployment-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-appxdeploymentclient-appxdeploy-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-audiocore-pal-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-authz-claimpolicies-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-authz-context-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-authz-remote-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-biometrics-winbio-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-bluetooth-deviceassociation-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-branding-winbrand-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-cluster-clusapi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-cluster-clusapi-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-cluster-resutils-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-cmd-util-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-cng-rng-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-com-clbcatq-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-com-ole32-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-com-ole32-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-com-psmregister-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-core-bi-service-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-core-psm-service-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-domainjoin-netjoin-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-firewallapi-webproxy-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-font-fontgroups-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-fs-clfs-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-fsutilext-ifsutil-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-fsutilext-ulib-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-fveapi-query-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-gdi-dc-create-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-gdi-dc-create-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-gdi-dc-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-gdi-draw-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-gdi-draw-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-gdi-font-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-gdi-font-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-gdi-metafile-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-gdi-metafile-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-gdi-path-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-gdi-private-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-gdi-render-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-gdi-wcs-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-globalization-collation-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-globalization-input-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-gpapi-grouppolicy-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-gpsvc-grouppolicy-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-gui-uxinit-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-imm-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-kernel32-appcompat-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-kernel32-datetime-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-kernel32-elevation-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-kernel32-errorhandling-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-kernel32-file-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-kernel32-localization-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-kernel32-package-current-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-kernel32-package-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-kernel32-package-l1-1-1.dll  6.3.9600.17031              ApiSet Stub DLL
    ext-ms-win-kernel32-quirks-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-kernel32-registry-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-kernel32-sidebyside-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-kernel32-transacted-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-kernel32-windowserrorreporting-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-kernelbase-processthread-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-mm-msacm-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-mm-pehelper-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-mm-wmdrmsdk-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-mpr-multipleproviderrouter-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-mrmcorer-environment-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-mrmcorer-resmanager-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-msa-ui-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-msa-user-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-msiltcfg-msi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-net-isoext-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-networking-wcmapi-l1-1-0.dll  6.3.9600.17031              ApiSet Stub DLL
    ext-ms-win-networking-winipsec-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-networking-wlanapi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-newdev-config-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntdsa-activedirectoryserver-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntdsapi-activedirectoryclient-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntos-kcminitcfg-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntos-ksecurity-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntos-ksecurity-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntos-ksigningpolicy-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntos-ksr-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntos-pico-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntos-tm-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntos-werkernel-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-caret-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-chartranslation-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-dialogbox-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-dialogbox-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-draw-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-draw-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-gui-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-gui-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-keyboard-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-keyboard-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-menu-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-menu-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-message-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-message-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-misc-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-misc-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-mouse-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-powermanagement-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-private-l1-1-0.dll  6.3.9600.17031              ApiSet Stub DLL
    ext-ms-win-ntuser-private-l1-1-1.dll  6.3.9600.17031              ApiSet Stub DLL
    ext-ms-win-ntuser-rectangle-ext-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-rotationmanager-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-string-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-synch-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-touch-hittest-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-windowclass-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-windowclass-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-window-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-window-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-windowstation-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ntuser-windowstation-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ole32-bindctx-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ole32-ie-ext-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ole32-oleautomation-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-oleacc-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-printer-winspool-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-printer-winspool-l1-1-1.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-profile-profsvc-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-profile-userenv-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ras-rasapi32-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ras-rasdlg-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ras-rasman-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-ras-tapi32-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-reinfo-query-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-rometadata-dispenser-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-rtcore-gdi-devcaps-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-rtcore-gdi-object-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-rtcore-gdi-rgn-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-rtcore-ntuser-dc-access-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-rtcore-ntuser-dpi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-rtcore-ntuser-sysparams-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-samsrv-accountstore-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-scesrv-server-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-secur32-translatename-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-security-credui-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-security-cryptui-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-security-kerberos-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-security-vaultcli-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-session-userinit-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-session-usertoken-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-session-wininit-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-session-winlogon-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-session-winsta-l1-1-0.dll  6.3.9600.17031              ApiSet Stub DLL
    ext-ms-win-session-wtsapi32-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-setupapi-cfgmgr32remote-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-setupapi-classinstallers-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-setupapi-inf-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-setupapi-logging-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-shell32-shellcom-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-shell32-shellfolders-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-shell-propsys-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-shell-settingsync-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-shell-shell32-l1-2-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-shell-shlwapi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-smbshare-browser-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-smbshare-sscore-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-spinf-inf-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-storage-iscsidsc-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-sxs-oleautomation-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-uiacore-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-umpoext-umpo-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-usp10-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-uxtheme-themes-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-webio-pal-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-wer-reporting-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-wevtapi-eventlog-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-winbici-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-winhttp-pal-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-wininet-pal-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-winlogon-mincreds-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-winrt-storage-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-wlan-grouppolicy-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-wlan-onexui-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-wlan-scard-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-wsclient-devlicense-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-wwan-wwapi-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-xaml-controls-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    ext-ms-win-xaml-pal-l1-1-0.dll  6.3.9600.16384              ApiSet Stub DLL
    f3ahvoas.dll               6.3.9600.17031              JP Japanese Keyboard Layout for Fujitsu FMV oyayubi-shift keyboard
    faultrep.dll               6.3.9600.17031                     Windows
    fdbth.dll                  6.3.9600.16384              Function Discovery Bluetooth Provider Dll
    fdbthproxy.dll             6.3.9600.16384              Bluetooth Provider Proxy Dll
    fddevquery.dll             6.3.9600.16384              Microsoft Windows Device Query Helper
    fde.dll                    6.3.9600.16384                 
    fdeploy.dll                6.3.9600.16384                  
    fdpnp.dll                  6.3.9600.16384              Pnp Provider Dll
    fdprint.dll                6.3.9600.16397               DLL    
    fdproxy.dll                6.3.9600.16384              Function Discovery Proxy Dll
    fdssdp.dll                 6.3.9600.16384              Function Discovery SSDP Provider Dll
    fdwcn.dll                  6.3.9600.16384              Windows Connect Now - Config Function Discovery Provider DLL
    fdwnet.dll                 6.3.9600.16384              Function Discovery WNet Provider Dll
    fdwsd.dll                  6.3.9600.16384              Function Discovery WS Discovery Provider Dll
    feclient.dll               6.3.9600.16384              Windows NT File Encryption Client Interfaces
    filemgmt.dll               6.3.9600.16384                 
    findnetprinters.dll        6.3.9600.16384              Find Network Printers COM Component
    firewallapi.dll            6.3.9600.16384              API  Windows
    firewallcontrolpanel.dll   6.3.9600.16384                -  Windows
    fltlib.dll                 6.3.9600.16384               
    fm20.dll                   15.0.4567.1000              Microsoft Forms DLL
    fm20enu.dll                15.0.4420.1017              Microsoft Forms International DLL
    fmifs.dll                  6.3.9600.16384              FM IFS Utility DLL
    fms.dll                    6.3.9600.16384                
    fontext.dll                6.3.9600.16384                Windows
    fontsub.dll                6.3.9600.16405              Font Subsetting DLL
    fphc.dll                   6.3.9600.16384               Filtering Platform Helper
    framedyn.dll               6.3.9600.17114              WMI SDK Provider Framework
    framedynos.dll             6.3.9600.17114              WMI SDK Provider Framework
    frprov.dll                 6.3.9600.16384              Folder Redirection WMI Provider
    fsutilext.dll              6.3.9600.16384              FS Utility Extension DLL
    fundisc.dll                6.3.9600.16384              DLL  
    fwcfg.dll                  6.3.9600.16384                  Windows
    fwpuclnt.dll               6.3.9600.17042              API   FWP/IPsec
    fwremotesvr.dll            6.3.9600.16384              Windows Firewall Remote APIs Server
    fxsapi.dll                 6.3.9600.16384              Microsoft  Fax API Support DLL
    fxscom.dll                 6.3.9600.16384              Microsoft Fax Server COM Client Interface
    fxscomex.dll               6.3.9600.16384              Microsoft Fax Server Extended COM Client Interface
    fxsext32.dll               6.3.9600.16384              Microsoft  Fax Exchange Command Extension
    fxsresm.dll                6.3.9600.16384               DLL   (Microsoft)
    fxsxp32.dll                6.3.9600.16384              Microsoft  Fax Transport Provider
    gameux.dll                 6.3.9600.17031               
    gameuxlegacygdfs.dll       1.0.0.1                     Legacy GDF resource DLL
    gcdef.dll                  6.3.9600.16384                   
    gdi32.dll                  6.3.9600.17246              GDI Client DLL
    gdiplus.dll                6.3.9600.17227              Microsoft GDI+
    geofencemonitorservice.dll  6.3.9600.17051                  Windows
    getuname.dll               6.3.9600.16384              Unicode name Dll for UCE
    glcndfilter.dll            6.3.9600.17031              Windows Reader
    glmf32.dll                 6.3.9600.16384              OpenGL Metafiling DLL
    globcollationhost.dll      6.3.9600.17031              GlobCollationHost
    globinputhost.dll          6.3.9600.16384              Windows Globalization Extension API for Input
    glu32.dll                  6.3.9600.16384                OpenGL
    gpapi.dll                  6.3.9600.17085                API  
    gpedit.dll                 6.3.9600.17238              GPEdit
    gpprefcl.dll               6.3.9600.17111                 
    gpprnext.dll               6.3.9600.16384                 
    gpscript.dll               6.3.9600.16384                
    gptext.dll                 6.3.9600.16384              GPTExt
    hbaapi.dll                 6.3.9600.16384              HBA API data interface dll for HBA_API_Rev_2-18_2002MAR1.doc
    hcproviders.dll            6.3.9600.16384                
    helppaneproxy.dll          6.3.9600.16384              Microsoft Help Proxy
    hgcpl.dll                  6.3.9600.16384                 
    hhsetup.dll                6.3.9600.16384              Microsoft HTML Help
    hid.dll                    6.3.9600.16384                HID
    hidserv.dll                6.3.9600.16384               HID
    hlink.dll                  6.3.9600.16384               Microsoft Office 2000
    hnetcfg.dll                6.3.9600.16384                 
    hnetmon.dll                6.3.9600.16384              DLL   
    hpbuio32.dll               2.0.0.434                   HP Unified IO API
    hpbuiodm32.dll             2.0.0.434                   HP Unified IO Data Model API
    hpbuiofax32.dll            2.0.0.434                   HP Unified IO Fax API
    hppccompio.dll             1.3.0.24                    LEDM USB Composite Bulk Helper
    hpunifiediodotnet.dll      2.0.0.434                   HP Unified IO API .NET Wrapper
    httpapi.dll                6.3.9600.16384              HTTP Protocol Stack API
    htui.dll                   6.3.9600.16384                  
    ias.dll                    6.3.9600.16384                 (NPS)
    iasacct.dll                6.3.9600.16384                NPS
    iasads.dll                 6.3.9600.16384                Active Directory NPS
    iasdatastore.dll           6.3.9600.16384              NPS Datastore server
    iashlpr.dll                6.3.9600.16384                NPS
    iasmigplugin.dll           6.3.9600.16384              NPS Migration DLL
    iasnap.dll                 6.3.9600.17238              NPS NAP Provider
    iaspolcy.dll               6.3.9600.16384              NPS Pipeline
    iasrad.dll                 6.3.9600.16384                RADIUS NPS
    iasrecst.dll               6.3.9600.16384              NPS XML Datastore Access
    iassam.dll                 6.3.9600.16384              NPS NT SAM Provider
    iassdo.dll                 6.3.9600.16384               SDO NPS
    iassvcs.dll                6.3.9600.16384                NPS
    iccvid.dll                 1.10.0.12                    Cinepak
    icm32.dll                  6.3.9600.16384              Microsoft Color Management Module (CMM)
    icmp.dll                   6.3.9600.16384              ICMP DLL
    icmui.dll                  6.3.9600.16384                  
    iconcodecservice.dll       6.3.9600.16384              Converts a PNG part of the icon to a legacy bmp icon
    icsigd.dll                 6.3.9600.16384                 
    idctrls.dll                6.3.9600.17031               
    idndl.dll                  6.3.9600.16384              Downlevel DLL
    idstore.dll                6.3.9600.16384              Identity Store
    ieadvpack.dll              11.0.9600.16384             ADVPACK
    ieapfltr.dll               11.0.9600.17239             Microsoft SmartScreen Filter
    iedkcs32.dll               18.0.9600.17239               IEAK
    ieetwproxystub.dll         11.0.9600.16384             IE ETW Collector Proxy Stub Resources
    ieframe.dll                11.0.9600.17239             
    iepeers.dll                11.0.9600.16384             Peer- Internet Explorer
    iernonce.dll               11.0.9600.16384               RunOnce   
    iertutil.dll               11.0.9600.17239                  Internet Explorer
    iesetup.dll                11.0.9600.17031               IOD
    iesysprep.dll              11.0.9600.16384             IE Sysprep Provider
    ieui.dll                   11.0.9600.16384                Internet Explorer
    ifmon.dll                  6.3.9600.16384                IF
    ifsutil.dll                6.3.9600.16384              IFS Utility DLL
    ifsutilx.dll               6.3.9600.16384              IFS Utility Extension DLL
    imagehlp.dll               6.3.9600.16438              Windows NT Image Helper
    imageres.dll               6.3.9600.16384              Windows Image Resource
    imagesp1.dll               6.3.9600.16384              Windows SP1 Image Resource
    imapi.dll                  6.3.9600.16384               Image Mastering API
    imapi2.dll                 6.3.9600.16384              IMAPI  2
    imapi2fs.dll               6.3.9600.16384              Image Mastering File System Imaging API v2
    imgutil.dll                11.0.9600.16384             IE plugin image decoder support DLL
    imm32.dll                  6.3.9600.17031              Multi-User Windows IMM32 API Client DLL
    inetcomm.dll               6.3.9600.16384              Microsoft Internet Messaging API Resources
    inetmib1.dll               6.3.9600.16384              Microsoft MIB-II subagent
    inetres.dll                6.3.9600.16384               API  
    inked.dll                  6.3.9600.16384              Microsoft Tablet PC InkEdit Control
    input.dll                  6.3.9600.16384               DLL  
    inputswitch.dll            6.3.9600.17031                Microsoft Windows
    inseng.dll                 11.0.9600.16384              
    iologmsg.dll               6.3.9600.16384                /
    iphlpapi.dll               6.3.9600.16384              API   IP
    iprop.dll                  6.3.9600.16384              OLE PropertySet Implementation
    iprtprio.dll               6.3.9600.16384              IP Routing Protocol Priority DLL
    iprtrmgr.dll               6.3.9600.16384               IP-
    ipsecsnp.dll               6.3.9600.16384                 IP-
    ipsmsnap.dll               6.3.9600.16384                IP-
    ir32_32.dll                6.3.9600.16384              IR32_32 WRAPPER DLL
    ir32_32original.dll        3.24.15.3                   32-  Intel Indeo(R) Video R3.2
    ir41_32original.dll        4.51.16.3                   Intel Indeo Video 4.5
    ir41_qc.dll                6.3.9600.16384              IR41_QC WRAPPER DLL
    ir41_qcoriginal.dll        4.30.62.2                   Intel Indeo Video Interactive Quick Compressor
    ir41_qcx.dll               6.3.9600.16384              IR41_QCX WRAPPER DLL
    ir41_qcxoriginal.dll       4.30.64.1                   Intel Indeo Video Interactive Quick Compressor
    ir50_32.dll                6.3.9600.16384              IR50_32 WRAPPER DLL
    ir50_32original.dll        5.2562.15.55                Intel Indeo video 5.10
    ir50_qc.dll                6.3.9600.16384              IR50_QC WRAPPER DLL
    ir50_qcoriginal.dll        5.0.63.48                   Intel Indeo video 5.10 Quick Compressor
    ir50_qcx.dll               6.3.9600.16384              IR50_QCX WRAPPER DLL
    ir50_qcxoriginal.dll       5.0.64.48                   Intel Indeo video 5.10 Quick Compressor
    irclass.dll                6.3.9600.16384                 
    iscsicpl.dll               5.2.3790.1830                   iSCSI
    iscsidsc.dll               6.3.9600.16384              API-  iSCSI
    iscsied.dll                6.3.9600.16384              iSCSI Extension DLL
    iscsium.dll                6.3.9600.16384              iSCSI Discovery api
    iscsiwmi.dll               6.3.9600.16384              MS iSCSI Initiator WMI Provider
    iscsiwmiv2.dll             6.3.9600.16384              WMI Provider for iSCSI
    itircl.dll                 6.3.9600.16384              Microsoft InfoTech IR Local DLL
    itss.dll                   6.3.9600.16384              Microsoft InfoTech Storage System Library
    iyuv_32.dll                6.3.9600.16384              Intel Indeo(R) Video YUV 
    javascriptcollectionagent.dll  11.0.9600.17239             JavaScript Performance Collection Agent
    jdns_sd.dll                3.0.0.10                    Bonjour support for Java
    jscript.dll                5.8.9600.16384              Microsoft  JScript
    jscript9.dll               11.0.9600.17239             Microsoft  JScript
    jscript9diag.dll           11.0.9600.17239             Microsoft  JScript Diagnostics
    jsproxy.dll                11.0.9600.16384             JScript Proxy Auto-Configuration
    kbd101.dll                 6.3.9600.16384              JP Japanese Keyboard Layout for 101
    kbd101a.dll                6.3.9600.16384              KO Hangeul Keyboard Layout for 101 (Type A)
    kbd101b.dll                6.3.9600.16384              KO Hangeul Keyboard Layout for 101(Type B)
    kbd101c.dll                6.3.9600.16384              KO Hangeul Keyboard Layout for 101(Type C)
    kbd103.dll                 6.3.9600.16384              KO Hangeul Keyboard Layout for 103
    kbd106.dll                 6.3.9600.16384              JP Japanese Keyboard Layout for 106
    kbd106n.dll                6.3.9600.16384              JP Japanese Keyboard Layout for 106
    kbda1.dll                  6.3.9600.16384              Arabic_English_101 Keyboard Layout
    kbda2.dll                  6.3.9600.16384              Arabic_2 Keyboard Layout
    kbda3.dll                  6.3.9600.16384              Arabic_French_102 Keyboard Layout
    kbdal.dll                  6.3.9600.16384              Albania Keyboard Layout
    kbdarme.dll                6.3.9600.16384              Eastern Armenian Keyboard Layout
    kbdarmph.dll               6.3.9600.16384              Armenian Phonetic Keyboard Layout
    kbdarmty.dll               6.3.9600.16384              Armenian Typewriter Keyboard Layout
    kbdarmw.dll                6.3.9600.16384              Western Armenian Keyboard Layout
    kbdax2.dll                 6.3.9600.16384              JP Japanese Keyboard Layout for AX2
    kbdaze.dll                 6.3.9600.16384              Azerbaijan_Cyrillic Keyboard Layout
    kbdazel.dll                6.3.9600.16384              Azeri-Latin Keyboard Layout
    kbdazst.dll                6.3.9600.16384              Azerbaijani (Standard) Keyboard Layout
    kbdbash.dll                6.3.9600.17238              Bashkir Keyboard Layout
    kbdbe.dll                  6.3.9600.16384              Belgian Keyboard Layout
    kbdbene.dll                6.3.9600.16384              Belgian Dutch Keyboard Layout
    kbdbgph.dll                6.3.9600.16384              Bulgarian Phonetic Keyboard Layout
    kbdbgph1.dll               6.3.9600.16384              Bulgarian (Phonetic Traditional) Keyboard Layout
    kbdbhc.dll                 6.3.9600.16384              Bosnian (Cyrillic) Keyboard Layout
    kbdblr.dll                 6.3.9600.16384              Belarusian Keyboard Layout
    kbdbr.dll                  6.3.9600.16384              Brazilian Keyboard Layout
    kbdbu.dll                  6.3.9600.16384              Bulgarian (Typewriter) Keyboard Layout
    kbdbug.dll                 6.3.9600.16384              Buginese Keyboard Layout
    kbdbulg.dll                6.3.9600.16384              Bulgarian Keyboard Layout
    kbdca.dll                  6.3.9600.16384              Canadian Multilingual Keyboard Layout
    kbdcan.dll                 6.3.9600.16384              Canadian Multilingual Standard Keyboard Layout
    kbdcher.dll                6.3.9600.16384              Cherokee Nation Keyboard Layout
    kbdcherp.dll               6.3.9600.16384              Cherokee Phonetic Keyboard Layout
    kbdcr.dll                  6.3.9600.16384              Croatian/Slovenian Keyboard Layout
    kbdcz.dll                  6.3.9600.16384              Czech Keyboard Layout
    kbdcz1.dll                 6.3.9600.16384              Czech_101 Keyboard Layout
    kbdcz2.dll                 6.3.9600.16384              Czech_Programmer's Keyboard Layout
    kbdda.dll                  6.3.9600.16384              Danish Keyboard Layout
    kbddiv1.dll                6.3.9600.16384              Divehi Phonetic Keyboard Layout
    kbddiv2.dll                6.3.9600.16384              Divehi Typewriter Keyboard Layout
    kbddv.dll                  6.3.9600.16384              Dvorak US English Keyboard Layout
    kbdes.dll                  6.3.9600.16384              Spanish Alernate Keyboard Layout
    kbdest.dll                 6.3.9600.16384              Estonia Keyboard Layout
    kbdfa.dll                  6.3.9600.16384              Persian Keyboard Layout
    kbdfar.dll                 6.3.9600.16384              Persian Standard Keyboard Layout
    kbdfc.dll                  6.3.9600.16384              Canadian French Keyboard Layout
    kbdfi.dll                  6.3.9600.16384              Finnish Keyboard Layout
    kbdfi1.dll                 6.3.9600.16384              Finnish-Swedish with Sami Keyboard Layout
    kbdfo.dll                  6.3.9600.16384              F?roese Keyboard Layout
    kbdfr.dll                  6.3.9600.16384              French Keyboard Layout
    kbdfthrk.dll               6.3.9600.16384              Futhark Keyboard Layout
    kbdgae.dll                 6.3.9600.16384              Scottish Gaelic (United Kingdom) Keyboard Layout
    kbdgeo.dll                 6.3.9600.16384              Georgian Keyboard Layout
    kbdgeoer.dll               6.3.9600.16384              Georgian (Ergonomic) Keyboard Layout
    kbdgeome.dll               6.3.9600.16384              Georgian (MES) Keyboard Layout
    kbdgeooa.dll               6.3.9600.16384              Georgian (Old Alphabets) Keyboard Layout
    kbdgeoqw.dll               6.3.9600.16384              Georgian (QWERTY) Keyboard Layout
    kbdgkl.dll                 6.3.9600.16384              Greek_Latin Keyboard Layout
    kbdgn.dll                  6.3.9600.16384              Guarani Keyboard Layout
    kbdgr.dll                  6.3.9600.16384              German Keyboard Layout
    kbdgr1.dll                 6.3.9600.16384              German_IBM Keyboard Layout
    kbdgrlnd.dll               6.3.9600.16384              Greenlandic Keyboard Layout
    kbdgthc.dll                6.3.9600.16384              Gothic Keyboard Layout
    kbdhau.dll                 6.3.9600.16384              Hausa Keyboard Layout
    kbdhaw.dll                 6.3.9600.16384              Hawaiian Keyboard Layout
    kbdhe.dll                  6.3.9600.16384              Greek Keyboard Layout
    kbdhe220.dll               6.3.9600.16384              Greek IBM 220 Keyboard Layout
    kbdhe319.dll               6.3.9600.16384              Greek IBM 319 Keyboard Layout
    kbdheb.dll                 6.3.9600.16384              KBDHEB Keyboard Layout
    kbdhebl3.dll               6.3.9600.16384              Hebrew Standard Keyboard Layout
    kbdhela2.dll               6.3.9600.16384              Greek IBM 220 Latin Keyboard Layout
    kbdhela3.dll               6.3.9600.16384              Greek IBM 319 Latin Keyboard Layout
    kbdhept.dll                6.3.9600.16384              Greek_Polytonic Keyboard Layout
    kbdhu.dll                  6.3.9600.16384              Hungarian Keyboard Layout
    kbdhu1.dll                 6.3.9600.16384              Hungarian 101-key Keyboard Layout
    kbdibm02.dll               6.3.9600.16384              JP Japanese Keyboard Layout for IBM 5576-002/003
    kbdibo.dll                 6.3.9600.16384              Igbo Keyboard Layout
    kbdic.dll                  6.3.9600.16384              Icelandic Keyboard Layout
    kbdinasa.dll               6.3.9600.16384              Assamese (Inscript) Keyboard Layout
    kbdinbe1.dll               6.3.9600.16384              Bengali - Inscript (Legacy) Keyboard Layout
    kbdinbe2.dll               6.3.9600.16384              Bengali (Inscript) Keyboard Layout
    kbdinben.dll               6.3.9600.16384              Bengali Keyboard Layout
    kbdindev.dll               6.3.9600.16384              Devanagari Keyboard Layout
    kbdinen.dll                6.3.9600.16384              English - India Keyboard Layout
    kbdinguj.dll               6.3.9600.16384              Gujarati Keyboard Layout
    kbdinhin.dll               6.3.9600.16384              Hindi Keyboard Layout
    kbdinkan.dll               6.3.9600.16384              Kannada Keyboard Layout
    kbdinmal.dll               6.3.9600.16384              Malayalam Keyboard Layout Keyboard Layout
    kbdinmar.dll               6.3.9600.16384              Marathi Keyboard Layout
    kbdinori.dll               6.3.9600.16384              Odia Keyboard Layout
    kbdinpun.dll               6.3.9600.16384              Punjabi/Gurmukhi Keyboard Layout
    kbdintam.dll               6.3.9600.16384              Tamil Keyboard Layout
    kbdintel.dll               6.3.9600.16384              Telugu Keyboard Layout
    kbdinuk2.dll               6.3.9600.16384              Inuktitut Naqittaut Keyboard Layout
    kbdir.dll                  6.3.9600.16384              Irish Keyboard Layout
    kbdit.dll                  6.3.9600.16384              Italian Keyboard Layout
    kbdit142.dll               6.3.9600.16384              Italian 142 Keyboard Layout
    kbdiulat.dll               6.3.9600.16384              Inuktitut Latin Keyboard Layout
    kbdjav.dll                 6.3.9600.16384              Javanese Keyboard Layout
    kbdjpn.dll                 6.3.9600.16384              JP Japanese Keyboard Layout Stub driver
    kbdkaz.dll                 6.3.9600.16384              Kazak_Cyrillic Keyboard Layout
    kbdkhmr.dll                6.3.9600.16384              Cambodian Standard Keyboard Layout
    kbdkni.dll                 6.3.9600.16384              Khmer (NIDA) Keyboard Layout
    kbdkor.dll                 6.3.9600.16384              KO Hangeul Keyboard Layout Stub driver
    kbdkurd.dll                6.3.9600.16384              Central Kurdish Keyboard Layout
    kbdkyr.dll                 6.3.9600.16384              Kyrgyz Keyboard Layout
    kbdla.dll                  6.3.9600.16384              Latin-American Spanish Keyboard Layout
    kbdlao.dll                 6.3.9600.16384              Lao Standard Keyboard Layout
    kbdlisub.dll               6.3.9600.16384              Lisu Basic Keyboard Layout
    kbdlisus.dll               6.3.9600.16384              Lisu Standard Keyboard Layout
    kbdlk41a.dll               6.3.9600.16384              DEC LK411-AJ Keyboard Layout
    kbdlt.dll                  6.3.9600.16384              Lithuania Keyboard Layout
    kbdlt1.dll                 6.3.9600.16384              Lithuanian Keyboard Layout
    kbdlt2.dll                 6.3.9600.16384              Lithuanian Standard Keyboard Layout
    kbdlv.dll                  6.3.9600.16384              Latvia Keyboard Layout
    kbdlv1.dll                 6.3.9600.16384              Latvia-QWERTY Keyboard Layout
    kbdlvst.dll                6.3.9600.16384              Latvian (Standard) Keyboard Layout
    kbdmac.dll                 6.3.9600.16384              Macedonian (FYROM) Keyboard Layout
    kbdmacst.dll               6.3.9600.16384              Macedonian (FYROM) - Standard Keyboard Layout
    kbdmaori.dll               6.3.9600.16384              Maori Keyboard Layout
    kbdmlt47.dll               6.3.9600.16384              Maltese 47-key Keyboard Layout
    kbdmlt48.dll               6.3.9600.16384              Maltese 48-key Keyboard Layout
    kbdmon.dll                 6.3.9600.16384              Mongolian Keyboard Layout
    kbdmonmo.dll               6.3.9600.16384              Mongolian (Mongolian Script) Keyboard Layout
    kbdmonst.dll               6.3.9600.16384              Traditional Mongolian (Standard) Keyboard Layout
    kbdmyan.dll                6.3.9600.16384              Myanmar Keyboard Layout
    kbdne.dll                  6.3.9600.16384              Dutch Keyboard Layout
    kbdnec.dll                 6.3.9600.16384              JP Japanese Keyboard Layout for (NEC PC-9800)
    kbdnec95.dll               6.3.9600.16384              JP Japanese Keyboard Layout for (NEC PC-9800 Windows 95)
    kbdnecat.dll               6.3.9600.16384              JP Japanese Keyboard Layout for (NEC PC-9800 on PC98-NX)
    kbdnecnt.dll               6.3.9600.16384              JP Japanese NEC PC-9800 Keyboard Layout
    kbdnepr.dll                6.3.9600.16384              Nepali Keyboard Layout
    kbdnko.dll                 6.3.9600.16384              N'Ko Keyboard Layout
    kbdno.dll                  6.3.9600.16384              Norwegian Keyboard Layout
    kbdno1.dll                 6.3.9600.16384              Norwegian with Sami Keyboard Layout
    kbdnso.dll                 6.3.9600.16384              Sesotho sa Leboa Keyboard Layout
    kbdntl.dll                 6.3.9600.16384              New Tai Leu Keyboard Layout
    kbdogham.dll               6.3.9600.16384              Ogham Keyboard Layout
    kbdolch.dll                6.3.9600.16384              Ol Chiki Keyboard Layout
    kbdoldit.dll               6.3.9600.16384              Old Italic Keyboard Layout
    kbdosm.dll                 6.3.9600.16384              Osmanya Keyboard Layout
    kbdpash.dll                6.3.9600.16384              Pashto (Afghanistan) Keyboard Layout
    kbdphags.dll               6.3.9600.16384              Phags-pa Keyboard Layout
    kbdpl.dll                  6.3.9600.16384              Polish Keyboard Layout
    kbdpl1.dll                 6.3.9600.16384              Polish Programmer's Keyboard Layout
    kbdpo.dll                  6.3.9600.16384              Portuguese Keyboard Layout
    kbdro.dll                  6.3.9600.16384              Romanian (Legacy) Keyboard Layout
    kbdropr.dll                6.3.9600.16384              Romanian (Programmers) Keyboard Layout
    kbdrost.dll                6.3.9600.16384              Romanian (Standard) Keyboard Layout
    kbdru.dll                  6.3.9600.17238              Russian Keyboard Layout
    kbdru1.dll                 6.3.9600.17238              Russia(Typewriter) Keyboard Layout
    kbdrum.dll                 6.3.9600.17238              Russian - Mnemonic Keyboard Layout
    kbdsf.dll                  6.3.9600.16384              Swiss French Keyboard Layout
    kbdsg.dll                  6.3.9600.16384              Swiss German Keyboard Layout
    kbdsl.dll                  6.3.9600.16384              Slovak Keyboard Layout
    kbdsl1.dll                 6.3.9600.16384              Slovak(QWERTY) Keyboard Layout
    kbdsmsfi.dll               6.3.9600.16384              Sami Extended Finland-Sweden Keyboard Layout
    kbdsmsno.dll               6.3.9600.16384              Sami Extended Norway Keyboard Layout
    kbdsn1.dll                 6.3.9600.16384              Sinhala Keyboard Layout
    kbdsora.dll                6.3.9600.16384              Sora Keyboard Layout
    kbdsorex.dll               6.3.9600.16384              Sorbian Extended Keyboard Layout
    kbdsors1.dll               6.3.9600.16384              Sorbian Standard Keyboard Layout
    kbdsorst.dll               6.3.9600.16384              Sorbian Standard (Legacy) Keyboard Layout
    kbdsp.dll                  6.3.9600.16384              Spanish Keyboard Layout
    kbdsw.dll                  6.3.9600.16384              Swedish Keyboard Layout
    kbdsw09.dll                6.3.9600.16384              Sinhala - Wij 9 Keyboard Layout
    kbdsyr1.dll                6.3.9600.16384              Syriac Standard Keyboard Layout
    kbdsyr2.dll                6.3.9600.16384              Syriac Phoenetic Keyboard Layout
    kbdtaile.dll               6.3.9600.16384              Tai Le Keyboard Layout
    kbdtajik.dll               6.3.9600.16384              Tajik Keyboard Layout
    kbdtat.dll                 6.3.9600.17238              Tatar (Legacy) Keyboard Layout
    kbdth0.dll                 6.3.9600.16384              Thai Kedmanee Keyboard Layout
    kbdth1.dll                 6.3.9600.16384              Thai Pattachote Keyboard Layout
    kbdth2.dll                 6.3.9600.16384              Thai Kedmanee (non-ShiftLock) Keyboard Layout
    kbdth3.dll                 6.3.9600.16384              Thai Pattachote (non-ShiftLock) Keyboard Layout
    kbdtifi.dll                6.3.9600.16384              Tifinagh (Basic) Keyboard Layout
    kbdtifi2.dll               6.3.9600.16384              Tifinagh (Extended) Keyboard Layout
    kbdtiprc.dll               6.3.9600.16384              Tibetan (PRC) Keyboard Layout
    kbdtiprd.dll               6.3.9600.16384              Tibetan (PRC) - Updated Keyboard Layout
    kbdtt102.dll               6.3.9600.17238              Tatar Keyboard Layout
    kbdtuf.dll                 6.3.9600.16384              Turkish F Keyboard Layout
    kbdtuq.dll                 6.3.9600.16384              Turkish Q Keyboard Layout
    kbdturme.dll               6.3.9600.16384              Turkmen Keyboard Layout
    kbdtzm.dll                 6.3.9600.16384              Central Atlas Tamazight Keyboard Layout
    kbdughr.dll                6.3.9600.16384              Uyghur (Legacy) Keyboard Layout
    kbdughr1.dll               6.3.9600.16384              Uyghur Keyboard Layout
    kbduk.dll                  6.3.9600.16384              United Kingdom Keyboard Layout
    kbdukx.dll                 6.3.9600.16384              United Kingdom Extended Keyboard Layout
    kbdur.dll                  6.3.9600.16384              Ukrainian Keyboard Layout
    kbdur1.dll                 6.3.9600.16384              Ukrainian (Enhanced) Keyboard Layout
    kbdurdu.dll                6.3.9600.16384              Urdu Keyboard Layout
    kbdus.dll                  6.3.9600.16384              United States Keyboard Layout
    kbdusa.dll                 6.3.9600.16384              US IBM Arabic 238_L Keyboard Layout
    kbdusl.dll                 6.3.9600.16384              Dvorak Left-Hand US English Keyboard Layout
    kbdusr.dll                 6.3.9600.16384              Dvorak Right-Hand US English Keyboard Layout
    kbdusx.dll                 6.3.9600.16384              US Multinational Keyboard Layout
    kbduzb.dll                 6.3.9600.16384              Uzbek_Cyrillic Keyboard Layout
    kbdvntc.dll                6.3.9600.16384              Vietnamese Keyboard Layout
    kbdwol.dll                 6.3.9600.16384              Wolof Keyboard Layout
    kbdyak.dll                 6.3.9600.17238              Sakha - Russia Keyboard Layout
    kbdyba.dll                 6.3.9600.16384              Yoruba Keyboard Layout
    kbdycc.dll                 6.3.9600.16384              Serbian (Cyrillic) Keyboard Layout
    kbdycl.dll                 6.3.9600.16384              Serbian (Latin) Keyboard Layout
    kerberos.dll               6.3.9600.17042                Kerberos
    kernel.appcore.dll         6.3.9600.16384              AppModel API Host
    kernel32.dll               6.3.9600.17056                Windows NT BASE API
    kernelbase.dll             6.3.9600.17055                Windows NT BASE API
    keyboardfiltercore.dll     6.3.9600.16384              Keyboard Filter Hooks
    keyiso.dll                 6.3.9600.16384                 CNG
    keymgr.dll                 6.3.9600.16384                  
    korwbrkr.dll               6.3.9600.17031              Korean Word Breaker
    ksuser.dll                 6.3.9600.16384              User CSA Library
    ktmw32.dll                 6.3.9600.16384              Windows KTM Win32 Client DLL
    l2gpstore.dll              6.3.9600.17041              Policy Storage dll
    l2nacp.dll                 6.3.9600.16384                 Onex Windows
    l2sechc.dll                6.3.9600.16384                    2
    laprxy.dll                 12.0.9600.16384             Windows Media Logagent Proxy
    licmgr10.dll               11.0.9600.16384              (DLL)    Microsoft
    linkinfo.dll               6.3.9600.16384              Windows Volume Tracking
    loadperf.dll               6.3.9600.16384                  
    localsec.dll               6.3.9600.16384               MMC "   "
    locationapi.dll            6.3.9600.16499              Microsoft Windows Location API
    loghours.dll               6.3.9600.16384               
    logoncli.dll               6.3.9600.16384              Net Logon Client DLL
    lpk.dll                    6.3.9600.16384              Language Pack
    lsmproxy.dll               6.3.9600.16384              LSM interfaces proxy Dll
    luainstall.dll             6.3.9600.16384              Lua manifest install
    lz32.dll                   6.3.9600.16384              LZ Expand/Compress API DLL
    magnification.dll          6.3.9600.16384               API  ()
    mapi32.dll                 1.0.2536.0                   MAPI 1.0  Windows NT
    mapistub.dll               1.0.2536.0                   MAPI 1.0  Windows NT
    mbaeapi.dll                6.3.9600.16384              API     
    mbaeapipublic.dll          6.3.9600.17031              Mobile Broadband Account API
    mbsmsapi.dll               6.3.9600.16384              Microsoft Windows Mobile Broadband SMS API
    mbussdapi.dll              6.3.9600.16384              Microsoft Windows Mobile Broadband USSD API
    mcewmdrmndbootstrap.dll    1.3.2310.10                 Windows Media Center WMDRM-ND Receiver Bridge Bootstrap DLL
    mciavi32.dll               6.3.9600.16384               MCI Video  Windows
    mcicda.dll                 6.3.9600.16384               MCI   cdaudio
    mciqtz32.dll               6.6.9600.16384               MCI DirectShow
    mciseq.dll                 6.3.9600.16384               MCI   MIDI
    mciwave.dll                6.3.9600.16384               MCI   
    mdminst.dll                6.3.9600.16384               
    mdmregistration.dll        6.3.9600.17031              MDM Registration DLL
    mf.dll                     12.0.9600.17090              DLL Media Foundation
    mf3216.dll                 6.3.9600.16384              32-bit to 16-bit Metafile Conversion DLL
    mfaacenc.dll               6.3.9600.16384              Media Foundation AAC Encoder
    mfasfsrcsnk.dll            12.0.9600.16405             Media Foundation ASF Source and Sink DLL
    mfc100.dll                 10.0.40219.325              MFCDLL Shared Library - Retail Version
    mfc100chs.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100cht.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100deu.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100enu.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100esn.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100fra.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100ita.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100jpn.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100kor.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100rus.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100u.dll                10.0.40219.325              MFCDLL Shared Library - Retail Version
    mfc110.dll                 11.0.60610.1                MFCDLL Shared Library - Retail Version
    mfc110chs.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110cht.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110deu.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110enu.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110esn.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110fra.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110ita.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110jpn.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110kor.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110rus.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110u.dll                11.0.60610.1                MFCDLL Shared Library - Retail Version
    mfc40.dll                  4.1.0.6140                    MFCDLL -  
    mfc40u.dll                 4.1.0.6140                    MFCDLL -  
    mfc42.dll                  6.6.8063.0                    MFCDLL -  
    mfc42u.dll                 6.6.8063.0                    MFCDLL -  
    mfcaptureengine.dll        12.0.9600.17095              DLL Media Foundation CaptureEngine
    mfcm100.dll                10.0.40219.325              MFC Managed Library - Retail Version
    mfcm100u.dll               10.0.40219.325              MFC Managed Library - Retail Version
    mfcm110.dll                11.0.60610.1                MFC Managed Library - Retail Version
    mfcm110u.dll               11.0.60610.1                MFC Managed Library - Retail Version
    mfcore.dll                 12.0.9600.17238             Media Foundation Core DLL
    mfcsubs.dll                2001.12.10530.16384         COM+
    mfds.dll                   12.0.9600.16469             Media Foundation Direct Show wrapper DLL
    mfdvdec.dll                6.3.9600.16384              Media Foundation DV Decoder
    mferror.dll                12.0.9600.16384              DLL  Media Foundation
    mfh264enc.dll              6.3.9600.16384              Media Foundation H264 Encoder
    mfmediaengine.dll          6.3.9600.17090              Media Foundation Media Engine DLL
    mfmjpegdec.dll             6.3.9600.16384              Media Foundation MJPEG Decoder
    mfmp4srcsnk.dll            12.0.9600.17238              DLL    MPEG4 Media Foundation
    mfmpeg2srcsnk.dll          12.0.9600.17090             Media Foundation MPEG2 Source and Sink DLL
    mfnetcore.dll              12.0.9600.17031             Media Foundation Net Core DLL
    mfnetsrc.dll               12.0.9600.17031             Media Foundation Net Source DLL
    mfplat.dll                 12.0.9600.17238             Media Foundation Platform DLL
    mfplay.dll                 12.0.9600.16384             Media Foundation Playback API DLL
    mfps.dll                   12.0.9600.16384             Media Foundation Proxy DLL
    mfreadwrite.dll            12.0.9600.17238             Media Foundation ReadWrite DLL
    mfsrcsnk.dll               12.0.9600.16408             Media Foundation Source and Sink DLL
    mfsvr.dll                  6.3.9600.17090              Media Foundation Simple Video Renderer DLL
    mftranscode.dll            12.0.9600.17238             Media Foundation Transcode DLL
    mfvdsp.dll                 6.3.9600.16384              Windows Media Foundation Video DSP Components
    mfwmaaec.dll               6.3.9600.16384              Windows Media Audio AEC for Media Foundation
    mgmtapi.dll                6.3.9600.16384              Microsoft SNMP Manager API (uses WinSNMP)
    mi.dll                     6.3.9600.16384              Management Infrastructure
    mibincodec.dll             6.3.9600.16384              Management Infrastructure binary codec component
    microsoft.management.infrastructure.native.unmanaged.dll  6.3.9600.16384              Microsoft.Management.Infrastructure.Native.Unmanaged.dll
    microsoftaccounttokenprovider.dll  6.3.9600.17031              Microsoft Account Token Provider
    midimap.dll                6.3.9600.16384              Microsoft MIDI Mapper
    migisol.dll                6.3.9600.17031              Migration System Isolation Layer
    miguiresource.dll          6.3.9600.16384               MIG wini32
    mimefilt.dll               2008.0.9600.16384            MIME
    mimofcodec.dll             6.3.9600.16384               MOF-  
    mirrordrvcompat.dll        6.3.9600.16384              Mirror Driver Compatibility Helper
    mispace.dll                6.3.9600.17221              Storage Management Provider for Spaces
    miutils.dll                6.3.9600.16421               
    mlang.dll                  6.3.9600.16384               DLL  
    mmcbase.dll                6.3.9600.16384                DLL MMC
    mmci.dll                   6.3.9600.16384                
    mmcico.dll                 6.3.9600.16384              Media class co-installer
    mmcndmgr.dll               6.3.9600.16384                 MMC
    mmcshext.dll               6.3.9600.16384              MMC Shell Extension DLL
    mmdevapi.dll               6.3.9600.17031              MMDevice API
    mmres.dll                  6.3.9600.16384               
    modemui.dll                6.3.9600.16384                Windows
    moricons.dll               6.3.9600.16384              Windows NT Setup Icon Resources Library
    mp3dmod.dll                6.3.9600.16384              Microsoft MP3 Decoder DMO
    mp43decd.dll               6.3.9600.16384              Windows Media MPEG-4 Video Decoder
    mp4sdecd.dll               6.3.9600.16384              Windows Media MPEG-4 S Video Decoder
    mpg4decd.dll               6.3.9600.16384              Windows Media MPEG-4 Video Decoder
    mpr.dll                    6.3.9600.16384                   
    mprapi.dll                 6.3.9600.16384              Windows NT MP Router Administration DLL
    mprddm.dll                 6.3.9600.16384                  
    mprdim.dll                 6.3.9600.16384                
    mprext.dll                 6.3.9600.16384               DLL     
    mprmsg.dll                 6.3.9600.16384               (DLL)    
    mrmcorer.dll               6.3.9600.17044              Microsoft Windows MRM
    mrmindexer.dll             6.3.9600.17031              Microsoft Windows MRM
    mrt_map.dll                1.0.51112.34112             Microsoft SLR Error Reporting Helper
    mrt100.dll                 1.0.30319.34112             System Language Runtime
    msaatext.dll               2.0.10413.0                 Active Accessibility text support
    msac3enc.dll               6.3.9600.16384              Microsoft AC-3 Encoder
    msacm32.dll                6.3.9600.16384                 Microsoft
    msadce.dll                 6.3.9600.16384              OLE DB Cursor Engine
    msadcer.dll                6.3.9600.16384              OLE DB Cursor Engine Resources
    msadco.dll                 6.3.9600.16384              Remote Data Services Data Control
    msadcor.dll                6.3.9600.16384              Remote Data Services Data Control Resources
    msadds.dll                 6.3.9600.16384              OLE DB Data Shape Provider
    msaddsr.dll                6.3.9600.16384               OLE DB Data Shape Provider Resources
    msader15.dll               6.3.9600.16384              ActiveX Data Objects Resources
    msado15.dll                6.3.9600.16384              ActiveX Data Objects
    msadomd.dll                6.3.9600.16384              ActiveX Data Objects (Multi-Dimensional)
    msador15.dll               6.3.9600.16384              Microsoft ActiveX Data Objects Recordset
    msadox.dll                 6.3.9600.16384              ActiveX Data Objects Extensions
    msadrh15.dll               6.3.9600.16384              ActiveX Data Objects Rowset Helper
    msafd.dll                  6.3.9600.16384              Microsoft Windows Sockets 2.0 Service Provider
    msasn1.dll                 6.3.9600.16384              ASN.1 Runtime APIs
    msauddecmft.dll            6.3.9600.16384              Media Foundation Audio Decoders
    msaudite.dll               6.3.9600.16384                 
    mscandui.dll               6.3.9600.16384                MSCANDUI
    mscat32.dll                6.3.9600.16384              MSCAT32 Forwarder DLL
    msclmd.dll                 6.3.9600.16384              Microsoft Class Mini-driver
    mscms.dll                  6.3.9600.16384              DLL-    
    mscoree.dll                6.3.9600.16384              Microsoft .NET Runtime Execution Engine
    mscorier.dll               6.3.9600.16384              Microsoft .NET Runtime IE resources
    mscories.dll               2.0.50727.7905              Microsoft .NET IE SECURITY REGISTRATION
    mscpx32r.dll               6.3.9600.16384              ODBC Code Page Translator Resources
    mscpxl32.dll               6.3.9600.16384                 ODBC
    msctf.dll                  6.3.9600.17031                MSCTF
    msctfmonitor.dll           6.3.9600.16384              MsCtfMonitor DLL
    msctfp.dll                 6.3.9600.16384              MSCTFP Server DLL
    msctfui.dll                6.3.9600.16384                MSCTFUI
    msctfuimanager.dll         6.3.9600.17031              Microsoft UIManager DLL
    msdadc.dll                 6.3.9600.16384              OLE DB Data Conversion Stub
    msdadiag.dll               6.3.9600.16384              Built-In Diagnostics
    msdaenum.dll               6.3.9600.16384              OLE DB Root Enumerator Stub
    msdaer.dll                 6.3.9600.16384              OLE DB Error Collection Stub
    msdaora.dll                6.3.9600.16384              OLE DB Provider for Oracle
    msdaorar.dll               6.3.9600.16384              OLE DB Provider for Oracle Resources
    msdaosp.dll                6.3.9600.16384              OLE DB Simple Provider
    msdaprsr.dll               6.3.9600.16384                OLE DB Persistence Services
    msdaprst.dll               6.3.9600.16384              OLE DB Persistence Services
    msdaps.dll                 6.3.9600.16384              OLE DB Interface Proxies/Stubs
    msdarem.dll                6.3.9600.16384              OLE DB Remote Provider
    msdaremr.dll               6.3.9600.16384              OLE DB Remote Provider Resources
    msdart.dll                 6.3.9600.16384              OLE DB Runtime Routines
    msdasc.dll                 6.3.9600.16384              OLE DB Service Components Stub
    msdasql.dll                6.3.9600.16384              OLE DB Provider for ODBC Drivers
    msdasqlr.dll               6.3.9600.16384              OLE DB Provider for ODBC Drivers Resources
    msdatl3.dll                6.3.9600.16384              OLE DB Implementation Support Routines
    msdatt.dll                 6.3.9600.16384              OLE DB Temporary Table Services
    msdaurl.dll                6.3.9600.16384              OLE DB RootBinder Stub
    msdelta.dll                6.3.9600.16384              Microsoft Patch Engine
    msdfmap.dll                6.3.9600.16384              Data Factory Handler
    msdmo.dll                  6.6.9600.16384              DMO Runtime
    msdrm.dll                  6.3.9600.16483                 Windows
    msdtcprx.dll               2001.12.10530.16384         Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL
    msdtcuiu.dll               2001.12.10530.16384         Microsoft Distributed Transaction Coordinator Administrative DLL
    msdtcvsp1res.dll           2001.12.10530.16384             ()  Vista SP1
    msexch40.dll               4.0.9756.0                  Microsoft Jet Exchange Isam
    msexcl40.dll               4.0.9756.0                  Microsoft Jet Excel Isam
    msfeeds.dll                11.0.9600.17239             Microsoft Feeds Manager
    msfeedsbs.dll              11.0.9600.16384               - ()
    msftedit.dll               6.3.9600.17041                 ,  7.5
    mshtml.dll                 11.0.9600.17239               HTML Microsoft
    mshtmldac.dll              11.0.9600.17239             DAC for Trident DOM
    mshtmled.dll               11.0.9600.17239             Microsoft HTML Editing Component
    mshtmler.dll               11.0.9600.16384                 HTML (Microsoft)
    msi.dll                    5.0.9600.17198              Windows Installer
    msidcrl40.dll              6.3.9600.16384              Microsoft Account Dynamic Link Library
    msident.dll                6.3.9600.16384                (Microsoft)
    msidle.dll                 6.3.9600.16384              User Idle Monitor
    msidntld.dll               6.3.9600.16384                (Microsoft)
    msieftp.dll                6.3.9600.16477                Microsoft Internet Explorer  FTP
    msihnd.dll                 5.0.9600.17198              Windows installer
    msiltcfg.dll               5.0.9600.16384              Windows Installer Configuration API Stub
    msimg32.dll                6.3.9600.16384              GDIEXT Client DLL
    msimsg.dll                 5.0.9600.16384                 Windows
    msimtf.dll                 6.3.9600.16384              Active IMM Server DLL
    msisip.dll                 5.0.9600.16384              MSI Signature SIP Provider
    msiwer.dll                 5.0.9600.16384              MSI Windows Error Reporting
    msjet40.dll                4.0.9765.0                  Microsoft Jet Engine Library
    msjetoledb40.dll           4.0.9756.0                  
    msjint40.dll               4.0.9765.0                       Microsoft Jet
    msjro.dll                  6.3.9600.16384              Jet and Replication Objects
    msjter40.dll               4.0.9756.0                  Microsoft Jet Database Engine Error DLL
    msjtes40.dll               4.0.9756.0                  Microsoft Jet Expression Service
    mskeyprotcli.dll           6.3.9600.16384                  Windows
    mskeyprotect.dll           6.3.9600.16384                 ()
    msls31.dll                 3.10.349.0                  Microsoft Line Services library file
    msltus40.dll               4.0.9756.0                  Microsoft Jet Lotus 1-2-3 Isam
    msmpeg2adec.dll            12.0.9477.0                 Microsoft DTV-DVD Audio Decoder
    msmpeg2enc.dll             12.0.9600.16384              Microsoft MPEG-2
    msmpeg2vdec.dll            12.0.9600.16476             Microsoft DTV-DVD Video Decoder
    msnetobj.dll               11.0.9600.16384             DRM ActiveX Network Object
    msobjs.dll                 6.3.9600.16384                 
    msoeacct.dll               6.3.9600.16384              Microsoft Internet Account Manager
    msoert2.dll                6.3.9600.16384              Microsoft Windows Mail RT Lib
    msorc32r.dll               6.3.9600.16384                ODBC  Oracle
    msorcl32.dll               6.3.9600.16384              ODBC Driver for Oracle
    mspatcha.dll               6.3.9600.16384              Microsoft File Patch Application API
    mspatchc.dll               6.3.9600.16384              Microsoft Patch Creation Engine
    mspbde40.dll               4.0.9756.0                  Microsoft Jet Paradox Isam
    msports.dll                6.3.9600.16384                 
    msrating.dll               11.0.9600.16384                  
    msrd2x40.dll               4.0.9756.0                  Microsoft (R) Red ISAM
    msrd3x40.dll               4.0.9756.0                  Microsoft (R) Red ISAM
    msrdc.dll                  6.3.9600.16384              Remote Differential Compression COM server
    msrdpwebaccess.dll         6.3.9600.16384              Microsoft Remote Desktop Services Web Access Control
    msrepl40.dll               4.0.9756.0                  Microsoft Replication Library
    msrle32.dll                6.3.9600.16384              Microsoft RLE Compressor
    msscntrs.dll               7.0.9600.16384              PKM Perfmon Counter DLL
    msscp.dll                  11.0.9600.16384             Windows Media Secure Content Provider
    mssha.dll                  6.3.9600.16384                  Windows
    msshavmsg.dll              6.3.9600.16384                     Windows
    msshooks.dll               7.0.9600.17031              Microsoft Search Hooks
    mssign32.dll               6.3.9600.16384               API  
    mssip32.dll                6.3.9600.16384              MSSIP32 Forwarder DLL
    mssitlb.dll                7.0.9600.16384              mssitlb
    msspellcheckingfacility.dll  6.3.9600.16500                 ()
    mssph.dll                  7.0.9600.17031                 Microsoft
    mssphtb.dll                7.0.9600.17031              Outlook MSSearch Connector
    mssprxy.dll                7.0.9600.17031              Microsoft Search Proxy
    mssrch.dll                 7.0.9600.17031                ()
    msstkprp.dll               6.0.81.69                   msprop32.ocx
    mssvp.dll                  7.0.9600.17031               Vista MSSearch
    mstask.dll                 6.3.9600.16384                 
    mstext40.dll               4.0.9756.0                  Microsoft Jet Text Isam
    mstscax.dll                6.3.9600.17238              ActiveX-    
    msutb.dll                  6.3.9600.16384               (DLL)  MSUTB
    msv1_0.dll                 6.3.9600.16384              Microsoft Authentication Package v1.0
    msvbvm60.dll               6.0.98.15                   Visual Basic Virtual Machine
    msvcirt.dll                7.0.9600.16384              Windows NT IOStreams DLL
    msvcm90.dll                9.0.21022.8                 Microsoft C Runtime Library
    msvcp100.dll               10.0.40219.325              Microsoft C Runtime Library
    msvcp110.dll               11.0.51106.1                Microsoft C Runtime Library
    msvcp120.dll               12.0.21005.1                Microsoft C Runtime Library
    msvcp120_clr0400.dll       12.0.20806.33440            Microsoft C Runtime Library
    msvcp60.dll                7.0.9600.16384              Windows NT C++ Runtime Library DLL
    msvcp90.dll                9.0.21022.8                 Microsoft C++ Runtime Library
    msvcr100.dll               10.0.40219.325              Microsoft C Runtime Library
    msvcr100_clr0400.dll       12.0.20806.33440            Microsoft .NET Framework
    msvcr110.dll               11.0.51106.1                Microsoft C Runtime Library
    msvcr120.dll               12.0.21005.1                Microsoft C Runtime Library
    msvcr120_clr0400.dll       12.0.20806.33440            Microsoft C Runtime Library
    msvcr71.dll                7.10.3052.4                 Microsoft C Runtime Library
    msvcr90.dll                9.0.21022.8                 Microsoft C Runtime Library
    msvcrt.dll                 7.0.9600.16384              Windows NT CRT DLL
    msvcrt20.dll               2.12.0.0                    Microsoft C Runtime Library
    msvcrt40.dll               6.3.9600.16384              VC 4.x CRT DLL (Forwarded to msvcrt.dll)
    msvfw32.dll                6.3.9600.16384               Microsoft Video  Windows
    msvidc32.dll               6.3.9600.16384                Microsoft Video 1
    msvidctl.dll               6.5.9600.16384               ActiveX  
    msvideodsp.dll             6.3.9600.17090              Video Stabilization MFT
    msvproc.dll                12.0.9600.17031             Media Foundation Video Processor
    mswb7.dll                  6.3.9600.16384              MSWB7 DLL
    mswb70011.dll              6.3.9600.16384              MSWB7EA DLL
    mswb7001e.dll              6.3.9600.16384              MSWB7EA DLL
    mswb70404.dll              6.3.9600.16384              MSWB7EA DLL
    mswb70804.dll              6.3.9600.16384              MSWB7EA DLL
    mswdat10.dll               4.0.9756.0                  Microsoft Jet Sort Tables
    mswmdm.dll                 12.0.9600.16384               Windows Media Device Manager
    mswsock.dll                6.3.9600.16384                 API Microsoft Windows Sockets 2.0
    mswstr10.dll               4.0.9765.0                    Microsoft Jet
    msxactps.dll               6.3.9600.16384              OLE DB Transaction Proxies/Stubs
    msxbde40.dll               4.0.9756.0                  Microsoft Jet xBASE Isam
    msxml3.dll                 8.110.9600.17120            MSXML 3.0
    msxml3r.dll                8.110.9600.16384            XML Resources
    msxml4.dll                 4.20.9818.0                 MSXML 4.0 SP 2
    msxml4a.dll                4.10.9404.0                 MSXML 4.0 SP1 Resources
    msxml4r.dll                4.10.9404.0                 MSXML 4.0 SP1 Resources
    msxml6.dll                 6.30.9600.17041             MSXML 6.0
    msxml6r.dll                6.30.9600.16384             XML Resources
    msyuv.dll                  6.3.9600.16384              Microsoft UYVY Video Decompressor
    mtxclu.dll                 2001.12.10530.16384         Microsoft Distributed Transaction Coordinator Failover Clustering Support DLL
    mtxdm.dll                  2001.12.10530.16384         COM+
    mtxex.dll                  2001.12.10530.16384         COM+
    mtxlegih.dll               2001.12.10530.16384         COM+
    mtxoci.dll                 2001.12.10530.16384         Microsoft Distributed Transaction Coordinator Database Support DLL for Oracle
    muifontsetup.dll           6.3.9600.16384              MUI Callback for font registry settings
    mycomput.dll               6.3.9600.16384               
    mydocs.dll                 6.3.9600.16384                 " "
    napcrypt.dll               6.3.9600.16384              NAP Cryptographic API helper
    napdsnap.dll               6.3.9600.16384               GPEdit    
    naphlpr.dll                6.3.9600.16384              NAP client config API helper
    napinsp.dll                6.3.9600.16384                    
    napipsec.dll               6.3.9600.16384                      IPSec
    napmontr.dll               6.3.9600.16384                NAP  Netsh
    naturallanguage6.dll       6.3.9600.16384              Natural Language Development Platform 6
    ncaapi.dll                 6.3.9600.16384              Microsoft Network Connectivity Assistant API
    ncdprop.dll                6.3.9600.16384                 
    nci.dll                    6.3.9600.16384              CoInstaller: NET
    ncobjapi.dll               6.3.9600.17114              Microsoft Windows Operating System
    ncrypt.dll                 6.3.9600.16384               Windows NCrypt
    ncryptprov.dll             6.3.9600.16384              Microsoft KSP
    ncryptsslp.dll             6.3.9600.17031              Microsoft SChannel Provider
    nddeapi.dll                6.3.9600.16384              Network DDE Share Management APIs
    ndfapi.dll                 6.3.9600.16384              API    
    ndfetw.dll                 6.3.9600.16384              Network Diagnostic Engine Event Interface
    ndfhcdiscovery.dll         6.3.9600.16384              Network Diagnostic Framework HC Discovery API
    ndiscapcfg.dll             6.3.9600.16384              NdisCap Notify Object
    ndishc.dll                 6.3.9600.16384                NDIS
    ndproxystub.dll            6.3.9600.16384              Network Diagnostic Engine Proxy/Stub
    negoexts.dll               6.3.9600.16384              NegoExtender Security Package
    netapi32.dll               6.3.9600.16384              Net Win32 API DLL
    netbios.dll                6.3.9600.16384              NetBIOS Interface Library
    netcenter.dll              6.3.9600.16384                 -  
    netcfgx.dll                6.3.9600.17114                
    netcorehc.dll              6.3.9600.16384                   
    netdiagfx.dll              6.3.9600.16384                
    netevent.dll               6.3.9600.16384                
    netfxperf.dll              6.3.9600.16384              Extensible Performance Counter Shim
    neth.dll                   6.3.9600.16384                 
    netid.dll                  6.3.9600.17031                  
    netiohlp.dll               6.3.9600.16477               DLL   Netio
    netjoin.dll                6.3.9600.16384               DLL   
    netlogon.dll               6.3.9600.17041                 Net Logon
    netmsg.dll                 6.3.9600.16384                
    netplwiz.dll               6.3.9600.17031                   
    netprofm.dll               6.3.9600.16384              Network List Manager
    netprovisionsp.dll         6.3.9600.16384              Provisioning Service Provider DLL
    netshell.dll               6.3.9600.16384                
    netutils.dll               6.3.9600.16384              Net Win32 API Helpers DLL
    networkexplorer.dll        6.3.9600.16384               
    networkitemfactory.dll     6.3.9600.16384                
    newdev.dll                 6.0.5054.0                    
    ninput.dll                 6.3.9600.16517              Microsoft Pen and Touch Input Component
    nl7data0011.dll            6.3.9600.16384              Microsoft Japanese Natural Language Data and Code
    nl7data001e.dll            6.3.9600.16384              Microsoft Thai Natural Language Data and Code
    nl7data0404.dll            6.3.9600.16384              Microsoft Chinese Traditional Natural Language Data and Code
    nl7data0804.dll            6.3.9600.16384              Microsoft Chinese Simplified Natural Language Data and Code
    nlaapi.dll                 6.3.9600.16384              Network Location Awareness 2
    nlhtml.dll                 2008.0.9600.16384            HTML
    nlmgp.dll                  6.3.9600.16384                 
    nlmproxy.dll               6.3.9600.16384              Network List Manager Public Proxy
    nlmsprep.dll               6.3.9600.16384              Network List Manager Sysprep Module
    nlsbres.dll                6.3.9600.16384              NLSBuild resource DLL
    nlsdata0000.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0002.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0003.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0007.dll            6.3.9600.16384              Microsoft German Natural Language Server Data and Code
    nlsdata0009.dll            6.3.9600.16384              Microsoft English Natural Language Server Data and Code
    nlsdata000a.dll            6.3.9600.16384              Microsoft Spanish Natural Language Server Data and Code
    nlsdata000c.dll            6.3.9600.16384              Microsoft French Natural Language Server Data and Code
    nlsdata000d.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata000f.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0010.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0018.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001a.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001b.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001d.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0020.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0021.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0022.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0024.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0026.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0027.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata002a.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0039.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata003e.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0045.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0046.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0047.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0049.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004a.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004b.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004c.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004e.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0414.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0416.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0816.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata081a.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0c1a.dll            6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlsdl.dll                  6.3.9600.16384              Nls Downlevel DLL
    nlslexicons0002.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0003.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0007.dll        6.3.9600.16384              Microsoft German Natural Language Server Data and Code
    nlslexicons0009.dll        6.3.9600.16384              Microsoft English Natural Language Server Data and Code
    nlslexicons000a.dll        6.3.9600.16384              Microsoft Spanish Natural Language Server Data and Code
    nlslexicons000c.dll        6.3.9600.16384              Microsoft French Natural Language Server Data and Code
    nlslexicons000d.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons000f.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0010.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0018.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001a.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001b.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001d.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0020.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0021.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0022.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0024.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0026.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0027.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons002a.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0039.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons003e.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0045.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0046.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0047.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0049.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004a.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004b.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004c.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004e.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0414.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0416.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0816.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons081a.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0c1a.dll        6.3.9600.16384              Microsoft Neutral Natural Language Server Data and Code
    normaliz.dll               6.3.9600.16384              Unicode Normalization DLL
    npmproxy.dll               6.3.9600.16384              Network List Manager Proxy
    nshhttp.dll                6.3.9600.16384               DLL netsh  HTTP
    nshipsec.dll               6.3.9600.16384               DLL  IPSec  Net
    nshwfp.dll                 6.3.9600.17042                  Windows  Netsh
    nsi.dll                    6.3.9600.16384              NSI User-mode interface DLL
    ntasn1.dll                 6.3.9600.16384              Microsoft ASN.1 API
    ntdll.dll                  6.3.9600.17114                NT
    ntdsapi.dll                6.3.9600.16384              Active Directory Domain Services API
    ntlanman.dll               6.3.9600.16384              Microsoft LAN Manager
    ntlanui2.dll               6.3.9600.16384                  
    ntmarta.dll                6.3.9600.16384               Windows NT MARTA
    ntprint.dll                6.3.9600.16384                  
    ntshrui.dll                6.3.9600.17031               ,   
    ntvdm64.dll                6.3.9600.16384              16-   NT64
    objsel.dll                 6.3.9600.16384                
    occache.dll                11.0.9600.17031                 
    ocsetapi.dll               6.3.9600.17031              Windows Optional Component Setup API
    odbc32.dll                 6.3.9600.16384              ODBC Driver Manager
    odbcbcp.dll                6.3.9600.16384              BCP for ODBC
    odbcconf.dll               6.3.9600.16384              ODBC Driver Configuration Program
    odbccp32.dll               6.3.9600.16384              ODBC Installer
    odbccr32.dll               6.3.9600.16384              ODBC Cursor Library
    odbccu32.dll               6.3.9600.16384              ODBC Cursor Library
    odbcint.dll                6.3.9600.16384              ODBC Resources
    odbcji32.dll               6.3.9600.16384              Microsoft ODBC Desktop Driver Pack 3.5
    odbcjt32.dll               6.3.9600.16384              Microsoft ODBC Desktop Driver Pack 3.5
    odbctrac.dll               6.3.9600.16384              ODBC Driver Manager Trace
    oddbse32.dll               6.3.9600.16384              ODBC (3.0) driver for DBase
    odexl32.dll                6.3.9600.16384              ODBC (3.0) driver for Excel
    odfox32.dll                6.3.9600.16384              ODBC (3.0) driver for FoxPro
    odpdx32.dll                6.3.9600.16384              ODBC (3.0) driver for Paradox
    odtext32.dll               6.3.9600.16384              ODBC (3.0) driver for text files
    oemlicense.dll                                         
    offfilt.dll                2008.0.9600.16384            OFFICE
    offreg.dll                 6.3.9600.17031              Offline registry DLL
    ogldrv.dll                 6.3.9600.16384              MSOGL
    ole2.dll                   3.10.0.103                  Windows Win16 Application Launcher
    ole2disp.dll               3.10.0.103                  Windows Win16 Application Launcher
    ole2nls.dll                3.10.0.103                  Windows Win16 Application Launcher
    ole32.dll                  6.3.9600.17042              Microsoft OLE  Windows
    oleacc.dll                 7.2.9600.16384              Active Accessibility Core Component
    oleacchooks.dll            7.2.9600.16384              Active Accessibility Event Hooks Library
    oleaccrc.dll               7.2.9600.16384              Active Accessibility Resource DLL
    oleaut32.dll               6.3.9600.16506              
    olecli32.dll               6.3.9600.16384                OLE
    oledb32.dll                6.3.9600.16384              OLE DB Core Services
    oledb32r.dll               6.3.9600.16384                 OLE DB
    oledlg.dll                 6.3.9600.16384                 OLE
    oleprn.dll                 6.3.9600.16384              Oleprn DLL
    olepro32.dll               6.3.9600.16384              
    olesvr32.dll               6.3.9600.16384              Object Linking and Embedding Server Library
    olethk32.dll               6.3.9600.16384              Microsoft OLE for Windows
    ondemandconnroutehelper.dll  6.3.9600.16384              On Demand Connctiond Route Helper
    onex.dll                   6.3.9600.16384                IEEE 802.1X
    onexui.dll                 6.3.9600.16384                 IEEE 802.1X
    oobefldr.dll               6.3.9600.17031                
    opcservices.dll            6.3.9600.16384              Native Code OPC Services Library
    opencl.dll                 1.2.11.0                    OpenCL Client DLL
    opengl32.dll               6.3.9600.16384              OpenGL Client DLL
    openvideo.dll              10.0.1348.5                 AMD Accelerated Parallel Processing OpenVideo 1.1 Runtime
    osbaseln.dll               6.3.9600.16384              Service Reporting API
    osksupport.dll             6.3.9600.16384              Microsoft On-Screen Keyboard Support Utilities
    osuninst.dll               6.3.9600.16384              Uninstall Interface
    ovdecode.dll               10.0.1348.5                 AMD Accelerated Parallel Processing OVDecode 1.1 Runtime
    p2p.dll                    6.3.9600.16384                
    p2pgraph.dll               6.3.9600.16384              Peer-to-Peer Graphing
    p2pnetsh.dll               6.3.9600.16384                 NetSh
    packager.dll               6.3.9600.16384               2
    packagestateroaming.dll    6.3.9600.16384              Package State Roaming
    panmap.dll                 6.3.9600.16384              PANOSE(tm) Font Mapper
    pautoenr.dll               6.3.9600.16384                
    pcacli.dll                 6.3.9600.16384              Program Compatibility Assistant Client Module
    pcaui.dll                  6.3.9600.16407                  
    pcpksp.dll                 6.3.9600.16384                  ()    
    pcptpm12.dll               6.3.9600.16384              Microsoft Platform Crypto Provider for Trusted Platform Module 1.2
    pcwum.dll                  6.3.9600.16384                   DLL Windows
    pdh.dll                    6.3.9600.17039                  Windows
    pdhui.dll                  6.3.9600.16384                
    peerdist.dll               6.3.9600.16384                BranchCache
    peerdistsh.dll             6.3.9600.16384                BranchCache Netshell
    perfctrs.dll               6.3.9600.16384               
    perfdisk.dll               6.3.9600.16384                  Windows
    perfnet.dll                6.3.9600.16384                   Windows
    perfos.dll                 6.3.9600.16384                  Windows
    perfproc.dll               6.3.9600.16384                   Windows
    perfts.dll                 6.3.9600.16384              Windows Remote Desktop Services Performance Objects
    photometadatahandler.dll   6.3.9600.16384              Photo Metadata Handler
    photowiz.dll               6.3.9600.16384                
    pid.dll                    6.3.9600.16384              Microsoft PID
    pidgenx.dll                6.3.9600.16384              Pid Generation
    pifmgr.dll                 6.3.9600.16384              Windows NT PIF Manager Icon Resources Library
    pku2u.dll                  6.3.9600.16384              Pku2u Security Package
    pla.dll                    6.3.9600.16384                 
    playlistfolder.dll         6.3.9600.16384              Playlist Folder
    playsndsrv.dll             6.3.9600.16384               PlaySound
    playtodevice.dll           12.0.9600.17031             DLL-   
    playtomanager.dll          6.3.9600.17031              Microsoft Windows PlayTo Manager
    playtostatusprovider.dll   6.3.9600.16384               DLL   
    pncrt.dll                  6.0.0.0                     Real Networks C/C++ Runtime Library
    pngfilt.dll                11.0.9600.16384             IE PNG plugin image decoder
    pnrpnsp.dll                6.3.9600.16384                 PNRP
    polstore.dll               6.3.9600.16384              Policy Storage dll
    portabledeviceapi.dll      6.3.9600.16384               API    Windows
    portabledeviceclassextension.dll  6.3.9600.16384              Windows Portable Device Class Extension Component
    portabledeviceconnectapi.dll  6.3.9600.16384              Portable Device Connection API Components
    portabledevicestatus.dll   6.3.9600.16384                  Microsoft Windows
    portabledevicesyncprovider.dll  6.3.9600.16384                 Microsoft Windows
    portabledevicetypes.dll    6.3.9600.16384              Windows Portable Device (Parameter) Types Component
    portabledevicewiacompat.dll  6.3.9600.16384              PortableDevice WIA Compatibility Driver
    portabledevicewmdrm.dll    6.3.9600.16384              Windows Portable Device WMDRM Component
    pots.dll                   6.3.9600.16384               
    powercpl.dll               6.3.9600.16384                
    powrprof.dll               6.3.9600.17031              DLL     
    presentationcffrasterizernative_v0300.dll  3.0.6920.7903               WinFX OpenType/CFF Rasterizer
    presentationhostproxy.dll  6.3.9600.16384              Windows Presentation Foundation Host Proxy
    presentationnative_v0300.dll  3.0.6920.7903               PresentationNative_v0300.dll
    prflbmsg.dll               6.3.9600.16384                  
    printconfig.dll            0.3.9600.17238                PrintConfig
    printdialogs.dll           6.3.9600.17238                Microsoft Windows
    printui.dll                6.3.9600.17238                 
    prncache.dll               6.3.9600.16384              Print UI Cache
    prnfldr.dll                6.3.9600.16384              prnfldr dll
    prnntfy.dll                6.3.9600.17238              prnntfy DLL
    prntvpt.dll                6.3.9600.16384              Print Ticket Services Module
    profapi.dll                6.3.9600.16384              User Profile Basic API
    profext.dll                6.3.9600.16384              profext
    propsys.dll                7.0.9600.17098                 ()
    provcore.dll               6.3.9600.16384                   ()
    provsvc.dll                6.3.9600.17031                Windows
    provthrd.dll               6.3.9600.16384              WMI Provider Thread & Log Library
    proximitycommon.dll        6.3.9600.16384                 
    proximitycommonpal.dll     6.3.9600.16384              Proximity Common PAL
    proximityrtapipal.dll      6.3.9600.16384              Proximity WinRT API PAL
    prvdmofcomp.dll            6.3.9600.16384              WMI
    psapi.dll                  6.3.9600.16384              Process Status Helper
    pshed.dll                  6.3.9600.16384                ,   
    psisdecd.dll               6.6.9600.16384              Microsoft SI/PSI parser for MPEG2 based networks.
    psmodulediscoveryprovider.dll  6.3.9600.16384              WMI
    pstorec.dll                6.3.9600.16384              Deprecated Protected Storage COM interfaces
    puiapi.dll                 6.3.9600.17238               DLL puiapi
    puiobj.dll                 6.3.9600.17238               DLL  PrintUI
    pwrshplugin.dll            6.3.9600.16384              pwrshplugin.dll
    qagent.dll                 6.3.9600.16384                
    qasf.dll                   12.0.9600.16384             DirectShow ASF Support
    qcap.dll                   6.6.9600.16384                DirecxX DirectShow.
    qcliprov.dll               6.3.9600.16384               WMI   
    qdv.dll                    6.6.9600.16384                DirecxX DirectShow.
    qdvd.dll                   6.6.9600.16384              DirectShow DVD PlayBack Runtime.
    qedit.dll                  6.6.9600.17200               DirectShow
    qedwipes.dll               6.6.9600.16384              DirectShow Editing SMPTE Wipes
    qmgrprxy.dll               7.7.9600.16384              Background Intelligent Transfer Service Proxy
    qshvhost.dll               6.3.9600.16384                SHV
    qsvrmgmt.dll               6.3.9600.16384                
    quartz.dll                 6.6.9600.16384                DirecxX DirectShow.
    query.dll                  6.3.9600.16384                  
    qutil.dll                  6.3.9600.16384                
    qwave.dll                  6.3.9600.16384              Windows NT
    racengn.dll                6.3.9600.17031                  
    racpldlg.dll               6.3.9600.16384                 
    radardt.dll                6.3.9600.16384                   Windows
    radarrs.dll                6.3.9600.16384                   Microsoft Windows
    radcui.dll                 6.3.9600.16384                      RemoteApp
    rasadhlp.dll               6.3.9600.16384              Remote Access AutoDial Helper
    rasapi32.dll               6.3.9600.17039              API  
    rascfg.dll                 6.3.9600.16384                RAS
    raschap.dll                6.3.9600.16384                 PPP CHAP
    raschapext.dll             6.3.9600.16384              Windows Extension library for raschap
    rasctrs.dll                6.3.9600.16384                     Windows NT
    rasdiag.dll                6.3.9600.16384                  RAS
    rasdlg.dll                 6.3.9600.16384              API     
    rasgcw.dll                 6.3.9600.17031                RAS
    rasman.dll                 6.3.9600.16384              Remote Access Connection Manager
    rasmontr.dll               6.3.9600.16384                RAS
    rasmxs.dll                 6.3.9600.16384              Remote Access Device DLL for modems, PADs and switches
    rasplap.dll                6.3.9600.16384                 RAS PLAP
    rasppp.dll                 6.3.9600.16384              Remote Access PPP
    rasser.dll                 6.3.9600.16384              Remote Access Media DLL for COM ports
    rastapi.dll                6.3.9600.16384              Remote Access TAPI Compliance Layer
    rastls.dll                 6.3.9600.16475                 PPP EAP-TLS
    rastlsext.dll              6.3.9600.16384              Windows Extension library for rastls
    rdpcore.dll                6.3.9600.16523              RDP Core DLL
    rdpencom.dll               6.3.9600.17093              RDPSRAPI COM Objects
    rdpendp.dll                6.3.9600.16384                 RDP
    rdpsaps.dll                6.3.9600.16384              RDP Session Agent Proxy Stub
    rdvidcrl.dll               6.3.9600.17238              Remote Desktop Services Client for Microsoft Online Services
    rdvvmtransport.dll         6.3.9600.16384              RdvVmTransport EndPoints
    reagent.dll                6.3.9600.17056               DLL   Microsoft Windows
    regapi.dll                 6.3.9600.16384              Registry Configuration APIs
    regctrl.dll                6.3.9600.16384              RegCtrl
    reinfo.dll                 6.3.9600.17056              Microsoft Windows Recovery Info DLL
    remotepg.dll               6.3.9600.16384              CPL-  
    removedevicecontexthandler.dll  6.3.9600.16384                    
    removedeviceelevated.dll   6.3.9600.16384              RemoveDeviceElevated Proxy Dll
    resampledmo.dll            6.3.9600.16384              Windows Media Resampler
    resutils.dll               6.3.9600.17083               DLL     ()
    rgb9rast.dll               6.3.9600.16384              Microsoft Windows Operating System
    riched20.dll               5.31.23.1231                Rich Text Edit Control, v3.1
    riched32.dll               6.3.9600.16384              Wrapper Dll for Richedit 1.0
    rmoc3260.dll               6.0.9.2533                  Real Player(tm) ActiveX Control
    rnr20.dll                  6.3.9600.16384              Windows Socket2 NameSpace DLL
    rometadata.dll             4.0.20806.33440             Microsoft MetaData Library
    rpchttp.dll                6.3.9600.17092              RPC HTTP DLL
    rpcns4.dll                 6.3.9600.16384                    (RPC)
    rpcnsh.dll                 6.3.9600.16384                RPC Netshell
    rpcrt4.dll                 6.3.9600.17216                 
    rpcrtremote.dll            6.3.9600.16384              Remote RPC Extension
    rsaenh.dll                 6.3.9600.17200              Microsoft Enhanced Cryptographic Provider
    rscricon.dll               1.10.0.0                    Realtek Card Reader Icon Dll
    rshx32.dll                 6.3.9600.16384                
    rstrtmgr.dll               6.3.9600.16384               
    rtffilt.dll                2008.0.9600.16384            RTF
    rtm.dll                    6.3.9600.16384                
    rtutils.dll                6.3.9600.16384              Routing Utilities
    rtworkq.dll                12.0.9600.16384              DLL  WorkQueue  
    samcli.dll                 6.3.9600.16384              Security Accounts Manager Client DLL
    samlib.dll                 6.3.9600.17031              SAM Library DLL
    sas.dll                    6.3.9600.16384              WinLogon Software SAS Library
    sbe.dll                    6.6.9600.16384              DirectShow Stream Buffer Filter.
    sbeio.dll                  12.0.9600.16384             Stream Buffer IO DLL
    sberes.dll                 6.6.9600.16384                  DirectShow.
    scansetting.dll            6.3.9600.16384                    Microsoft Windows(TM)
    scarddlg.dll               6.3.9600.16384              SCardDlg -   -
    scecli.dll                 6.3.9600.16384                 
    scesrv.dll                 6.3.9600.16384                
    schannel.dll               6.3.9600.17193                TLS/SSL
    schedcli.dll               6.3.9600.16384              Scheduler Service Client DLL
    scksp.dll                  6.3.9600.16384              Microsoft Smart Card Key Storage Provider
    scripto.dll                6.6.9600.16384              Microsoft ScriptO
    scrobj.dll                 5.8.9600.17031              Windows  Script Component Runtime
    scrptadm.dll               6.3.9600.16384                
    scrrun.dll                 5.8.9600.17031              Microsoft  Script Runtime
    sdiageng.dll               6.3.9600.16384                 
    sdiagprv.dll               6.3.9600.16384              API    Windows
    sdohlp.dll                 6.3.9600.16384                 SDO NPS
    searchfolder.dll           6.3.9600.17098              SearchFolder
    sechost.dll                6.3.9600.16384              Host for SCM/SDDL/LSA Lookup APIs
    secproc.dll                6.3.9600.16384              Windows Rights Management Desktop Security Processor
    secproc_isv.dll            6.3.9600.16384              Windows Rights Management Desktop Security Processor
    secproc_ssp.dll            6.3.9600.16384              Windows Rights Management Services Server Security Processor
    secproc_ssp_isv.dll        6.3.9600.16384              Windows Rights Management Services Server Security Processor (Pre-production)
    secur32.dll                6.3.9600.16384              Security Support Provider Interface
    security.dll               6.3.9600.16384              Security Support Provider Interface
    sendmail.dll               6.3.9600.16384               
    sensapi.dll                6.3.9600.16384              SENS Connectivity API DLL
    sensorsapi.dll             6.3.9600.17041              API 
    sensorscpl.dll             6.3.9600.16384                "    "
    serialui.dll               6.3.9600.16384                
    serwvdrv.dll               6.3.9600.16384                Unimodem
    sessenv.dll                6.3.9600.17041                   
    settingmonitor.dll         6.3.9600.17031              Setting Synchronization Change Monitor
    settingsync.dll            6.3.9600.17238              Setting Synchronization
    settingsynccore.dll        6.3.9600.17031                
    settingsyncpolicy.dll      6.3.9600.17031              SettingSync Policy
    setupapi.dll               6.3.9600.17031              Windows Setup API
    setupcln.dll               6.3.9600.16384                
    sfc.dll                    6.3.9600.16384              Windows File Protection
    sfc_os.dll                 6.3.9600.16384              Windows File Protection
    shacct.dll                 6.3.9600.16384              Shell Accounts Classes
    shcore.dll                 6.3.9600.17238              SHCORE
    shdocvw.dll                6.3.9600.16384                    
    shell32.dll                6.3.9600.17238                 Windows
    shellstyle.dll             6.3.9600.16384              Windows Shell Style Resource Dll
    shfolder.dll               6.3.9600.16384              Shell Folder Service
    shgina.dll                 6.3.9600.16384              Windows Shell User Logon
    shimeng.dll                6.3.9600.16384              Shim Engine DLL
    shimgvw.dll                6.3.9600.16384               
    shlwapi.dll                6.3.9600.16384                 
    shpafact.dll               6.3.9600.16384              Windows Shell LUA/PA Elevation Factory Dll
    shsetup.dll                6.3.9600.16423              Shell setup helper
    shsvcs.dll                 6.3.9600.16384               DLL   Windows
    shunimpl.dll               6.3.9600.16384              Windows Shell Obsolete APIs
    shwebsvc.dll               6.3.9600.16384              -  Windows
    signdrv.dll                6.3.9600.16384              WMI provider for Signed Drivers
    simauth.dll                6.3.9600.16384              DLL   EAP-SIM
    simcfg.dll                 6.3.9600.16384              DLL  EAP-SIM
    sisbkup.dll                6.3.9600.16384              Single-Instance Store Backup Support Functions
    skydriveshell.dll          6.3.9600.17122                Microsoft OneDrive
    slc.dll                    6.3.9600.17031              Software Licensing Client DLL
    slcext.dll                 6.3.9600.16384              Software Licensing Client Extension Dll
    slpts.dll                  6.3.9600.17031              Sleep Study Troubleshooter
    slwga.dll                  6.3.9600.16384              Software Licensing WGA API
    smartcardcredentialprovider.dll  6.3.9600.16384                 - Windows
    smbhelperclass.dll         1.0.0.1                        SMB (   )    
    smphost.dll                6.3.9600.16384              Storage Management Provider (SMP) host service
    sndvolsso.dll              6.3.9600.17031               SCA 
    snmpapi.dll                6.3.9600.16384              SNMP Utility Library
    softkbd.dll                6.3.9600.16384                  
    softpub.dll                6.3.9600.16384              Softpub Forwarder DLL
    sortserver2003compat.dll   6.3.9600.16384              Sort Version Server 2003
    sortwindows61.dll          6.3.9600.16384              SortWindows61 Dll
    sortwindows6compat.dll     6.3.9600.16384              Sort Version Windows 6.0
    spbcd.dll                  6.3.9600.17031              BCD Sysprep Plugin
    spfileq.dll                6.3.9600.16384              Windows SPFILEQ
    spinf.dll                  6.3.9600.16384              Windows SPINF
    spnet.dll                  6.3.9600.16384              Net Sysprep Plugin
    spopk.dll                  6.3.9600.16384              OPK Sysprep Plugin
    spp.dll                    6.3.9600.17042                  Microsoft Windows
    sppc.dll                   6.3.9600.17031              Software Licensing Client DLL
    sppcext.dll                6.3.9600.16384              Software Protection Platform Client Extension Dll
    sppinst.dll                6.3.9600.16384              SPP CMI Installer Plug-in DLL
    sppwmi.dll                 6.3.9600.16384              Software Protection Platform WMI provider
    spwinsat.dll               6.3.9600.16384              WinSAT Sysprep Plugin
    spwizeng.dll               6.3.9600.17031              Setup Wizard Framework
    spwizimg.dll               6.3.9600.16384              Setup Wizard Framework Resources
    spwizres.dll               6.3.9600.16384                 
    spwmp.dll                  6.3.9600.16384              Windows Media Player System Preparation DLL
    sqlcecompact40.dll         4.0.8275.1                  Database Repair Tool (32-bit)
    sqlceoledb40.dll           4.0.9600.1                  OLEDB Provider (32-bit)
    sqlceqp40.dll              4.0.9600.1                  Query Processor (32-bit)
    sqlcese40.dll              4.0.9600.1                  Storage Engine (32-bit)
    sqloledb.dll               6.3.9600.16384              OLE DB Provider for SQL Server
    sqlsrv32.dll               6.3.9600.16384              SQL Server ODBC Driver
    sqlunirl.dll               2000.80.2039.0              String Function .DLL for SQL Enterprise Components
    sqlwid.dll                 2000.80.2039.0              Unicode Function .DLL for SQL Enterprise Components
    sqlwoa.dll                 2000.80.2040.0              Unicode/ANSI Function .DLL for SQL Enterprise Components
    sqlxmlx.dll                6.3.9600.16384              XML extensions for SQL Server
    sqmapi.dll                 6.3.9600.17031              SQM Client
    srchadmin.dll              7.0.9600.17031               
    srclient.dll               6.3.9600.17090              Microsoft Windows System Restore Client Library
    srh.dll                    6.3.9600.17238               DLL      
    srm.dll                    6.3.9600.16384                    Microsoft
    srm_ps.dll                 6.3.9600.16384              Microsoft FSRM internal proxy/stub
    srmclient.dll              6.3.9600.16384              Microsoft File Server Resource Management Client Extensions
    srmlib.dll                 6.3.9600.16384              Microsoft (R) File Server Resource Management Interop Assembly
    srmscan.dll                6.3.9600.16384              Microsoft File Server Storage Reports Scan Engine
    srmshell.dll               6.3.9600.16384                    ()
    srmstormod.dll             6.3.9600.16384              Microsoft File Server Resource Management Office Parser
    srmtrace.dll               6.3.9600.16384              Microsoft File Server Resource Management Tracing Library
    srpuxnativesnapin.dll      6.3.9600.16384                     
    srumapi.dll                6.3.9600.16384              System Resource Usage Monitor API
    srumsvc.dll                6.3.9600.16384              System Resource Usage Monitor Service
    srvcli.dll                 6.3.9600.16384              Server Service Client DLL
    sscore.dll                 6.3.9600.16384               DLL-  
    ssdpapi.dll                6.3.9600.16384              SSDP Client API DLL
    sspicli.dll                6.3.9600.16408              Security Support Provider Interface
    ssshim.dll                 6.3.9600.17031              Windows Componentization Platform Servicing API
    startupscan.dll            6.3.9600.16384               DLL    
    stclient.dll               2001.12.10530.16384         COM+ Configuration Catalog Client
    sti.dll                    6.3.9600.16501                   
    stobject.dll               6.3.9600.17238                 Systray
    storage.dll                3.10.0.103                  Windows Win16 Application Launcher
    storagecontexthandler.dll  6.3.9600.17031                   
    storagewmi.dll             6.3.9600.17238              WMI Provider for Storage Management
    storagewmi_passthru.dll    6.3.9600.16384              WMI PassThru Provider for Storage Management
    storprop.dll               6.3.9600.16384                  
    storsvc.dll                6.3.9600.16384               
    structuredquery.dll        7.0.9600.17031              Structured Query
    sud.dll                    6.3.9600.17031                SUD
    sxproxy.dll                6.3.9600.17042                  Microsoft Windows
    sxs.dll                    6.3.9600.16384              Fusion 2.5
    sxshared.dll               6.3.9600.17031              Microsoft Windows SX Shared Library
    sxsstore.dll               6.3.9600.16384              Sxs Store DLL
    synccenter.dll             6.3.9600.17031                
    synceng.dll                6.3.9600.16384              Windows Briefcase Engine
    synchostps.dll             6.3.9600.16384              Proxystub for sync host
    syncinfrastructure.dll     6.3.9600.16384                Microsoft Windows.
    syncinfrastructureps.dll   6.3.9600.16384              Microsoft Windows sync infrastructure proxy stub.
    syncom.dll                 18.0.7.0                    SynCOM
    syncreg.dll                2007.94.9600.16384          Microsoft Synchronization Framework Registration
    syncui.dll                 6.3.9600.16384               Windows
    syssetup.dll               6.3.9600.16384              Windows NT System Setup
    systemcpl.dll              6.3.9600.16384              CPL 
    systemeventsbrokerclient.dll  6.3.9600.16384              system Events Broker Client Library
    t2embed.dll                6.3.9600.16384              Microsoft T2Embed Font Embedding
    tapi3.dll                  6.3.9600.16384              Microsoft TAPI3
    tapi32.dll                 6.3.9600.16384               API  Microsoft Windows
    tapimigplugin.dll          6.3.9600.16384              Microsoft Windows(TM) TAPI Migration Plugin Dll
    tapiperf.dll               6.3.9600.16384              Microsoft Windows(TM) Telephony Performance Monitor
    tapisrv.dll                6.3.9600.16384                 Microsoft Windows
    tapisysprep.dll            6.3.9600.16384              Microsoft Windows(TM) Telephony Sysprep Work
    tapiui.dll                 6.3.9600.16384               DLL   Microsoft Windows
    taskcomp.dll               6.3.9600.16384                  
    taskschd.dll               6.3.9600.16384              Task Scheduler COM API
    taskschdps.dll             6.3.9600.16384              Task Scheduler Interfaces Proxy
    tbs.dll                    6.3.9600.16384              TBS
    tcpipcfg.dll               6.3.9600.16384                
    tcpmib.dll                 6.3.9600.16384              Standard TCP/IP Port Monitor Helper DLL
    tcpmonui.dll               6.3.9600.16384                  TCP/IP
    tdh.dll                    6.3.9600.17031                 
    termmgr.dll                6.3.9600.16384              Microsoft TAPI3 Terminal Manager
    themecpl.dll               6.3.9600.17031              CPL 
    themeui.dll                6.3.9600.17031              API   Windows
    threadpoolwinrt.dll        6.3.9600.16384              Windows WinRT Threadpool
    thumbcache.dll             6.3.9600.17031                
    timebrokerclient.dll       6.3.9600.16384              Time Broker Client Library
    timedatemuicallback.dll    6.3.9600.16384              Time Date Control UI Language Change plugin
    tlscsp.dll                 6.3.9600.17088              Microsoft Remote Desktop Services Cryptographic Utility
    tpmcompc.dll               6.3.9600.16384                
    tquery.dll                 7.0.9600.17031               Microsoft Tripoli
    traffic.dll                6.3.9600.16384              Microsoft Traffic Control 1.0 DLL
    tsbyuv.dll                 6.3.9600.16384              Toshiba Video Codec
    tschannel.dll              6.3.9600.16384              Task Scheduler Proxy
    tsgqec.dll                 6.3.9600.16520                      
    tsmf.dll                   6.3.9600.16404                MF    
    tspkg.dll                  6.3.9600.16384              Web Service Security Package
    tsworkspace.dll            6.3.9600.16421                      RemoteApp
    ttlsauth.dll               6.3.9600.16384              DLL   EAP-TTLS
    ttlscfg.dll                6.3.9600.16384              DLL  EAP-TTLS
    ttlsext.dll                6.3.9600.16384              Windows Extension library for EAP TTLS
    tvratings.dll              6.6.9600.16384              Module for managing TV ratings
    twext.dll                  6.3.9600.16384              :  
    twinapi.appcore.dll        6.3.9600.17093              twinapi.appcore
    twinapi.dll                6.3.9600.17031              twinapi
    twinui.appcore.dll         6.3.9600.17195              TWINUI.APPCORE
    twinui.dll                 6.3.9600.17238              TWINUI
    txflog.dll                 2001.12.10530.16384         COM+
    txfw32.dll                 6.3.9600.16384              TxF Win32 DLL
    typelib.dll                3.10.0.103                  Windows Win16 Application Launcher
    tzres.dll                  6.3.9600.16384               DLL   
    ucmhc.dll                  6.3.9600.16384                 UCM
    udhisapi.dll               6.3.9600.16384              UPnP Device Host ISAPI Extension
    uexfat.dll                 6.3.9600.16384              eXfat Utility DLL
    ufat.dll                   6.3.9600.16384              FAT Utility DLL
    uianimation.dll            6.3.9600.16384              Windows Animation Manager
    uiautomationcore.dll       7.2.9600.16421                 Microsoft UI
    uiautomationcoreres.dll    7.2.9600.16384              Microsoft UI Automation Core Resource
    uicom.dll                  6.3.9600.16384              Add/Remove Modems
    uireng.dll                 6.3.9600.16384                  
    uiribbon.dll               6.3.9600.16384                Windows
    uiribbonres.dll            6.3.9600.16384              Windows Ribbon Framework Resources
    ulib.dll                   6.3.9600.16384              DLL   
    umdmxfrm.dll               6.3.9600.16384              Unimodem Tranform Module
    unimdmat.dll               6.3.9600.16384              - AT   Unimodem
    uniplat.dll                6.3.9600.16384              Unimodem AT Mini Driver Platform Driver for Windows NT
    unrar.dll                  5.10.100.1259               
    untfs.dll                  6.3.9600.17031              NTFS Utility DLL
    upnp.dll                   6.3.9600.16384              API   UPnP
    upnphost.dll               6.3.9600.16384                PNP-
    urefs.dll                  6.3.9600.16384              NTFS Utility DLL
    ureg.dll                   6.3.9600.16384              Registry Utility DLL
    url.dll                    11.0.9600.16384             Internet Shortcut Shell Extension DLL
    urlmon.dll                 11.0.9600.17239              OLE32  Win32
    usbceip.dll                6.3.9600.16384               USBCEIP
    usbperf.dll                6.3.9600.16384               DLL   USB
    usbui.dll                  6.3.9600.16384              USB UI Dll
    user32.dll                 6.3.9600.17238                 USER API Windows
    useraccountcontrolsettings.dll  6.3.9600.16384                  
    usercpl.dll                6.3.9600.17031                
    userenv.dll                6.3.9600.17041              Userenv
    userinitext.dll            6.3.9600.16384               DLL    UserInit
    userlanguageprofilecallback.dll  6.3.9600.16384              MUI Callback for User Language profile changed
    userlanguagescpl.dll       6.3.9600.17031               " "  
    usp10.dll                  6.3.9600.16384              Uniscribe Unicode script processor
    ustprov.dll                6.3.9600.16384              User State WMI Provider
    utildll.dll                6.3.9600.16384                WinStation
    uudf.dll                   6.3.9600.16384              UDF Utility DLL
    uxinit.dll                 6.3.9600.17031              Windows User Experience Session Initialization Dll
    uxlib.dll                  6.3.9600.16384              Setup Wizard Framework
    uxlibres.dll               6.3.9600.16384              UXLib Resources
    uxtheme.dll                6.3.9600.17031                UxTheme (Microsoft)
    van.dll                    6.3.9600.17238                
    vault.dll                  6.3.9600.16384                -  Windows
    vaultcli.dll               6.3.9600.16384                  
    vbajet32.dll               6.0.1.9431                  Visual Basic for Applications Development Environment - Expression Service Loader
    vbscript.dll               5.8.9600.17239              Microsoft  VBScript
    vcamp110.dll               11.0.51106.1                Microsoft C++ AMP Runtime
    vccorlib110.dll            11.0.51106.1                Microsoft  VC WinRT core library
    vccorlib120.dll            12.0.21005.1                Microsoft  VC WinRT core library
    vcomp100.dll               10.0.40219.325              Microsoft C/C++ OpenMP Runtime
    vcomp110.dll               11.0.51106.1                Microsoft C/C++ OpenMP Runtime
    vdmdbg.dll                 6.3.9600.16384              VDMDBG.DLL
    vds_ps.dll                 6.3.9600.16384              Microsoft Virtual Disk Service proxy/stub
    verifier.dll               6.3.9600.16384              Standard application verifier provider dll
    version.dll                6.3.9600.16384              Version Checking and File Installation Libraries
    vfwwdm32.dll               6.3.9600.16384               VfW MM Driver    WDM-
    vidreszr.dll               6.3.9600.16384              Windows Media Resizer
    virtdisk.dll               6.3.9600.16384              Virtual Disk API DLL
    vpnikeapi.dll              6.3.9600.16384              VPN IKE API's
    vscmgrps.dll               6.3.9600.16384              Microsoft Virtual Smart Card Manager Proxy/Stub
    vss_ps.dll                 6.3.9600.16384              Microsoft Volume Shadow Copy Service proxy/stub
    vssapi.dll                 6.3.9600.16384              Microsoft Volume Shadow Copy Requestor/Writer Services API DLL
    vsstrace.dll               6.3.9600.16384                    Microsoft
    w32topl.dll                6.3.9600.16384              Windows NT Topology Maintenance Tool
    wab32.dll                  6.3.9600.16384              Microsoft (R) Contacts DLL
    wab32res.dll               6.3.9600.16384               Microsoft (R) DLL
    wabsyncprovider.dll        6.3.9600.16384                 Microsoft Windows
    wavemsp.dll                6.3.9600.16384              Microsoft Wave MSP
    wbemcomn.dll               6.3.9600.16384              WMI
    wcmapi.dll                 6.3.9600.16384              Windows Connection Manager Client API
    wcnapi.dll                 6.3.9600.16384              Windows Connect Now - API Helper DLL
    wcnwiz.dll                 6.3.9600.16384                Windows Connect Now
    wcspluginservice.dll       6.3.9600.16384               DLL WcsPlugInService
    wdc.dll                    6.3.9600.16384               
    wdi.dll                    6.3.9600.16384                Windows
    wdigest.dll                6.3.9600.16384              Microsoft Digest Access
    wdscore.dll                6.3.9600.16384              Panther Engine Module
    webcamui.dll               6.3.9600.16388                Microsoft Windows
    webcheck.dll               11.0.9600.16384              -
    webclnt.dll                6.3.9600.17238               DLL - DAV
    webio.dll                  6.3.9600.16384              API    
    webservices.dll            6.3.9600.17031                - Windows
    websocket.dll              6.3.9600.16384              Web Socket API
    wecapi.dll                 6.3.9600.16384              Event Collector Configuration API
    wer.dll                    6.3.9600.17031                  Windows
    werdiagcontroller.dll      6.3.9600.16384              WER Diagnostic Controller
    werui.dll                  6.3.9600.17031               DLL      Windows
    wevtapi.dll                6.3.9600.16384              API    
    wevtfwd.dll                6.3.9600.16384                  WS-Management
    wfapigp.dll                6.3.9600.16384              Windows Firewall GPO Helper dll
    wfdprov.dll                6.3.9600.16384              Private WPS provisioning API DLL for Wi-Fi Direct
    wfhc.dll                   6.3.9600.16384               Windows.   
    whhelper.dll               6.3.9600.16384              DLL     winHttp
    wiaaut.dll                 6.3.9600.16384               WIA-
    wiadefui.dll               6.3.9600.16384                  WIA
    wiadss.dll                 6.3.9600.16384               WIA -  TWAIN
    wiascanprofiles.dll        6.3.9600.16384              Microsoft Windows ScanProfiles
    wiashext.dll               6.3.9600.16384                     
    wiatrace.dll               6.3.9600.16384              WIA Tracing
    wimgapi.dll                6.3.9600.17031               Windows Imaging
    winbio.dll                 6.3.9600.16384              API   Windows
    winbrand.dll               6.3.9600.17031              Windows Branding Resources
    wincorlib.dll              6.3.9600.17031              Microsoft Windows  WinRT core library
    wincredprovider.dll        6.3.9600.16384               DLL wincredprovider
    windows.applicationmodel.background.systemeventsbroker.dll  6.3.9600.16384              Windows Background System Events Broker API Server
    windows.applicationmodel.background.timebroker.dll  6.3.9600.16384              Windows Background Time Broker API Server
    windows.applicationmodel.dll  6.3.9600.16384              Windows ApplicationModel API Server
    windows.applicationmodel.store.dll  6.3.9600.17031               Windows   DLL  
    windows.applicationmodel.store.testingframework.dll  6.3.9600.17238               Windows   DLL    
    windows.data.pdf.dll       6.3.9600.17054              PDF WinRT APIs
    windows.devices.background.dll  6.3.9600.16384              Windows.Devices.Background
    windows.devices.background.ps.dll  6.3.9600.16384              Windows.Devices.Background Interface Proxy
    windows.devices.bluetooth.dll  6.3.9600.17238              DLL- Windows.Devices.Bluetooth
    windows.devices.custom.dll  6.3.9600.16384              Windows.Devices.Custom
    windows.devices.custom.ps.dll  6.3.9600.16384              Windows.Devices.Custom Interface Proxy
    windows.devices.enumeration.dll  6.3.9600.16384              Windows.Devices.Enumeration
    windows.devices.enumeration.ps.dll  6.3.9600.16384              Windows.Devices.Enumeration Interface Proxy
    windows.devices.geolocation.dll  6.3.9600.16384              Geolocation Runtime DLL
    windows.devices.humaninterfacedevice.dll  6.3.9600.17031              Windows.Devices.HumanInterfaceDevice DLL
    windows.devices.pointofservice.dll  6.3.9600.16384              Windows Runtime PointOfService DLL
    windows.devices.portable.dll  6.3.9600.16384              Windows Runtime Portable Devices DLL
    windows.devices.printers.extensions.dll  6.3.9600.16384              Windows.Devices.Printers.Extensions
    windows.devices.scanners.dll  6.3.9600.17041               DLL    Windows
    windows.devices.sensors.dll  6.3.9600.17041               DLL    Windows
    windows.devices.smartcards.dll  6.3.9600.16384               DLL API -   Windows
    windows.devices.usb.dll    6.3.9600.16403              Windows Runtime Usb DLL
    windows.devices.wifidirect.dll  6.3.9600.16384              Windows.Devices.WiFiDirect DLL
    windows.globalization.dll  6.3.9600.17031              Windows Globalization
    windows.globalization.fontgroups.dll  6.3.9600.16384              Fonts Mapping API
    windows.graphics.dll       6.3.9600.16477              WinRT Windows Graphics DLL
    windows.graphics.printing.dll  6.3.9600.17039                Microsoft Windows
    windows.management.workplace.workplacesettings.dll  6.3.9600.16384              Windows Runtime WorkplaceSettings DLL
    windows.media.devices.dll  6.3.9600.16384              Windows Runtime media device server DLL
    windows.media.dll          6.3.9600.17238              Windows Media Runtime DLL
    windows.media.mediacontrol.dll  6.3.9600.16384               DLL  MediaControl   Windows
    windows.media.speechsynthesis.dll  6.3.9600.16384              Windows Speech Runtime DLL
    windows.media.streaming.dll  12.0.9600.17090             DLNA DLL
    windows.media.streaming.ps.dll  12.0.9600.16384             DLNA Proxy-Stub DLL
    windows.networking.backgroundtransfer.dll  6.3.9600.16421              Windows.Networking.BackgroundTransfer DLL
    windows.networking.connectivity.dll  6.3.9600.16523              Windows Networking Connectivity Runtime DLL
    windows.networking.dll     6.3.9600.17238              Windows.Networking DLL
    windows.networking.hostname.dll  6.3.9600.16384              Windows.Networking.HostName DLL
    windows.networking.networkoperators.hotspotauthentication.dll  6.3.9600.16384              Microsoft Windows Hotspot Authentication API
    windows.networking.proximity.dll  6.3.9600.16384              Windows Runtime Proximity API DLL
    windows.networking.sockets.pushenabledapplication.dll  6.3.9600.17031              Windows.Networking.Sockets.PushEnabledApplication DLL
    windows.security.authentication.onlineid.dll  6.3.9600.17031              Windows Runtime OnlineId Authentication DLL
    windows.security.credentials.ui.credentialpicker.dll  6.3.9600.16384              WinRT Credential Picker Server
    windows.security.credentials.ui.userconsentverifier.dll  6.3.9600.16384              API     Windows
    windows.shell.search.urihandler.dll  6.3.9600.17041              Windows Search URI Handler
    windows.storage.applicationdata.dll  6.3.9600.16384              Windows Application Data API Server
    windows.storage.compression.dll  6.3.9600.16384              WinRT Compression
    windows.system.display.dll  6.3.9600.16384               DLL     Windows
    windows.system.profile.hardwareid.dll  6.3.9600.16384              DLL-      Windows
    windows.system.profile.systemmanufacturers.dll  6.3.9600.16384              Windows.System.Profile.SystemManufacturers
    windows.system.remotedesktop.dll  6.3.9600.16384              Windows System RemoteDesktop Runtime DLL
    windows.ui.dll             6.3.9600.16384              Windows Runtime UI Foundation DLL
    windows.ui.immersive.dll   6.3.9600.17031              WINDOWS.UI.IMMERSIVE
    windows.ui.input.inking.dll  6.3.9600.16384              WinRT Windows Inking DLL
    windows.ui.search.dll      6.3.9600.17238              Windows.UI.Search
    windows.ui.xaml.dll        6.3.9600.17238              Windows.UI.Xaml dll
    windows.web.dll            6.3.9600.16384               DLL -
    windows.web.http.dll       6.3.9600.16423               DLL Windows.Web.Http
    windowsaccessbridge-32.dll  2.0.4.0                     Java Access Bridge for Windows
    windowscodecs.dll          6.3.9600.16521              Microsoft Windows Codecs Library
    windowscodecsext.dll       6.3.9600.16384              Microsoft Windows Codecs Extended Library
    windowslivelogin.dll       6.3.9600.16384              Microsoft Account Login Helper
    winfax.dll                 6.3.9600.16384              Microsoft  Fax API Support DLL
    winhttp.dll                6.3.9600.16384               HTTP Windows
    wininet.dll                11.0.9600.17239                Win32
    wininitext.dll             6.3.9600.16384              WinInit Utility Extension DLL
    winipsec.dll               6.3.9600.16384              Windows IPsec SPD Client DLL
    winlangdb.dll              6.3.9600.16384                 Windows Bcp47
    winmde.dll                 12.0.9600.17090             WinMDE DLL
    winmm.dll                  6.3.9600.17078              MCI API DLL
    winmmbase.dll              6.3.9600.17080              Base Multimedia Extension API DLL
    winmsoirmprotector.dll     6.3.9600.16384              Windows Office file format IRM Protector
    winnsi.dll                 6.3.9600.16384              Network Store Information RPC interface
    winopcirmprotector.dll     6.3.9600.16384              Windows Office file format IRM Protector
    winrnr.dll                 6.3.9600.16384              LDAP RnR Provider DLL
    winrscmd.dll               6.3.9600.16384              remtsvc
    winrsmgr.dll               6.3.9600.16384              WSMan Shell API
    winrssrv.dll               6.3.9600.16384              winrssrv
    winrttracing.dll           6.3.9600.16384              Windows Diagnostics Tracing
    winsatapi.dll              6.3.9600.16384              Windows System Assessment Tool API
    winscard.dll               6.3.9600.16408              API - (Microsoft)
    winshfhc.dll               6.3.9600.16384              File Risk Estimation
    winsku.dll                 6.3.9600.17031              Windows SKU Library
    winsockhc.dll              6.3.9600.16384                   Winsock
    winsrpc.dll                6.3.9600.16384              WINS RPC LIBRARY
    winsta.dll                 6.3.9600.16384              Winstation Library
    winsync.dll                2007.94.9600.16384          Synchronization Framework
    winsyncmetastore.dll       2007.94.9600.16384          Windows Synchronization Metadata Store
    winsyncproviders.dll       2007.94.9600.16384          Windows Synchronization Provider Framework
    wintrust.dll               6.3.9600.17085              Microsoft Trust Verification APIs
    wintypes.dll               6.3.9600.17031               DLL   Windows
    winusb.dll                 6.3.9600.16384              Windows USB Driver User Library
    wisp.dll                   6.3.9600.17231              Microsoft Pen and Touch Input Component
    wkscli.dll                 6.3.9600.16384              Workstation Service Client DLL
    wkspbrokerax.dll           6.3.9600.16384              Microsoft Workspace Broker ActiveX Control
    wksprtps.dll               6.3.9600.16384              WorkspaceRuntime ProxyStub DLL
    wlanapi.dll                6.3.9600.17238              Windows WLAN AutoConfig Client Side API DLL
    wlancfg.dll                6.3.9600.16384               DLL    Netsh  WLAN
    wlanconn.dll               6.3.9600.17031                Dot11
    wlandlg.dll                6.3.9600.16384                   
    wlangpui.dll               6.3.9600.17041               "   "
    wlanhlp.dll                6.3.9600.17055              Windows Wireless LAN 802.11 Client Side Helper API
    wlaninst.dll               6.3.9600.16384              Windows NET Device Class Co-Installer for Wireless LAN
    wlanmm.dll                 6.3.9600.17031                Dot11   
    wlanmsm.dll                6.3.9600.17238              Windows Wireless LAN 802.11 MSM DLL
    wlanpref.dll               6.3.9600.16384                
    wlansec.dll                6.3.9600.16384              Windows Wireless LAN 802.11 MSM Security Module DLL
    wlanui.dll                 6.3.9600.16384                 
    wlanutil.dll               6.3.9600.16384               DLL     Windows   802.11
    wldap32.dll                6.3.9600.16384              Win32 LDAP API DLL
    wlgpclnt.dll               6.3.9600.16384                 802.11
    wlidcli.dll                6.3.9600.17031                 (DLL)   
    wlidcredprov.dll           6.3.9600.17031              Microsoft Account Credential Provider
    wlidfdp.dll                6.3.9600.16384              Microsoft Account Function Discovery Provider
    wlidnsp.dll                6.3.9600.16384              Microsoft Account Namespace Provider
    wlidprov.dll               6.3.9600.17039              Microsoft Account Provider
    wlidres.dll                6.3.9600.16384               Microsoft Windows Live ID
    wls0wndh.dll               6.3.9600.16384              Session0 Viewer Window Hook DLL
    wmadmod.dll                6.3.9600.16384              Windows Media Audio Decoder
    wmadmoe.dll                6.3.9600.16384              Windows Media Audio 10 Encoder/Transcoder
    wmasf.dll                  12.0.9600.16384             Windows Media ASF DLL
    wmcodecdspps.dll           6.3.9600.16384              Windows Media CodecDSP Proxy Stub Dll
    wmdmlog.dll                12.0.9600.16384             Windows Media Device Manager Logger
    wmdmps.dll                 12.0.9600.16384             Windows Media Device Manager Proxy Stub
    wmdrmdev.dll               12.0.9600.16384             Windows Media DRM for Network Devices Registration DLL
    wmdrmnet.dll               12.0.9600.16384             Windows Media DRM for Network Devices DLL
    wmdrmsdk.dll               11.0.9600.16384             Windows Media DRM SDK DLL
    wmerror.dll                12.0.9600.16384               Windows Media ()
    wmi.dll                    6.3.9600.16384              WMI DC and DP functionality
    wmiclnt.dll                6.3.9600.16384              WMI Client API
    wmidcom.dll                6.3.9600.16384              WMI
    wmidx.dll                  12.0.9600.16384             Windows Media Indexer DLL
    wmiprop.dll                6.3.9600.16384                  WDM
    wmitomi.dll                6.3.9600.16384                CIM
    wmnetmgr.dll               12.0.9600.16384             Windows Media Network Plugin Manager DLL
    wmp.dll                    12.0.9600.17031             Windows Media Player
    wmpdui.dll                 12.0.9600.16384             Windows Media Player UI Engine
    wmpdxm.dll                 12.0.9600.16384             Windows Media Player Extension
    wmpeffects.dll             12.0.9600.16384             Windows Media Player Effects
    wmphoto.dll                6.3.9600.16474               Windows Media
    wmploc.dll                 12.0.9600.16384               Windows Media
    wmpps.dll                  12.0.9600.16384             Windows Media Player Proxy Stub Dll
    wmpshell.dll               12.0.9600.16384                Windows Media
    wmsgapi.dll                6.3.9600.16384              WinLogon IPC Client
    wmspdmod.dll               6.3.9600.16384              Windows Media Audio Voice Decoder
    wmspdmoe.dll               6.3.9600.16384              Windows Media Audio Voice Encoder
    wmvcore.dll                12.0.9600.16384             Windows Media Playback/Authoring DLL
    wmvdecod.dll               6.3.9600.17238                  Windows Media
    wmvdspa.dll                6.3.9600.16384              Windows Media Video DSP Components - Advanced
    wmvencod.dll               6.3.9600.16384                  Windows Media 9
    wmvsdecd.dll               6.3.9600.16384              Windows Media Screen Decoder
    wmvsencd.dll               6.3.9600.16384              Windows Media Screen Encoder
    wmvxencd.dll               6.3.9600.16384              Windows Media Video Encoder
    workfoldersres.dll         6.2.9200.16384                
    wow32.dll                  6.3.9600.16384              Wow32
    wpc.dll                    6.3.9600.17236                 
    wpcsvc.dll                 6.3.9600.16384                  Windows
    wpdshext.dll               6.3.9600.16384                  
    wpdshserviceobj.dll        6.3.9600.16384              Windows Portable Device Shell Service Object
    wpdsp.dll                  6.3.9600.16384              WMDM Service Provider for Windows Portable Devices
    wpnapps.dll                6.3.9600.16384                push- Windows
    ws2_32.dll                 6.3.9600.16384              32-  Windows Socket 2.0
    ws2help.dll                6.3.9600.16384              Windows Socket 2.0 Helper for Windows NT
    wscapi.dll                 6.3.9600.17031              API    Windows
    wscinterop.dll             6.3.9600.17031              Windows Health Center WSC Interop
    wscisvif.dll               6.3.9600.16384              Windows Security Center ISV API
    wsclient.dll               6.3.9600.17031               Windows   
    wscproxystub.dll           6.3.9600.16384              Windows Security Center ISV Proxy Stub
    wsdapi.dll                 6.3.9600.16523              -   DLL API- 
    wsdchngr.dll               6.3.9600.16384              WSD Challenge Component
    wsecedit.dll               6.3.9600.17195                 
    wshbth.dll                 6.3.9600.17238              Windows Sockets Helper DLL
    wshcon.dll                 5.8.9600.16384              Microsoft  Windows Script Controller
    wshelper.dll               6.3.9600.16384               DLL    Winsock Net
    wshext.dll                 5.8.9600.16384              Microsoft  Shell Extension for Windows Script Host
    wship6.dll                 6.3.9600.16384               DLL  Winsock2 (TL/IPv6)
    wshirda.dll                6.3.9600.16384              Windows Sockets Helper DLL
    wshqos.dll                 6.3.9600.16384               DLL   QoS Winsock2
    wshrm.dll                  6.3.9600.16384                DLL   Windows  PGM
    wshtcpip.dll               6.3.9600.16384               DLL   Winsock2 (TL/IPv4)
    wsmagent.dll               6.3.9600.16384              WinRM Agent
    wsmanmigrationplugin.dll   6.3.9600.16384              WinRM Migration Plugin
    wsmauto.dll                6.3.9600.16384              WSMAN Automation
    wsmplpxy.dll               6.3.9600.16384              wsmplpxy
    wsmres.dll                 6.3.9600.16384               DLL  WSMan
    wsmsvc.dll                 6.3.9600.17041               WSMan
    wsmwmipl.dll               6.3.9600.16384              WSMAN WMI Provider
    wsnmp32.dll                6.3.9600.16384              Microsoft WinSNMP v2.0 Manager API
    wsock32.dll                6.3.9600.16384              Windows Socket 32-Bit DLL
    wsshared.dll               6.3.9600.17238               DLL WSShared
    wssync.dll                 6.3.9600.16384              Windows Store Licensing Sync Client
    wtsapi32.dll               6.3.9600.16384              Windows Remote Desktop Session Host Server SDK APIs
    wuapi.dll                  7.9.9600.17238              API    Windows
    wudriver.dll               7.9.9600.17238              Windows Update WUDriver Stub
    wups.dll                   7.9.9600.17238              Windows Update client proxy stub
    wuwebv.dll                 7.9.9600.17093              Windows Update Vista Web Control
    wvc.dll                    6.3.9600.16384              Windows Visual Components
    wwaapi.dll                 6.3.9600.16384              Microsoft Web Application Host API library
    wwanapi.dll                6.3.9600.16384              Mbnapi
    wwapi.dll                  8.1.9600.16384              WWAN API
    x3daudio1_0.dll            9.11.519.0                  X3DAudio
    x3daudio1_1.dll            9.15.779.0                  X3DAudio
    x3daudio1_2.dll            9.21.1148.0                 X3DAudio
    x3daudio1_3.dll            9.22.1284.0                 X3DAudio
    x3daudio1_4.dll            9.23.1350.0                 X3DAudio
    x3daudio1_5.dll            9.25.1476.0                 X3DAudio
    x3daudio1_6.dll            9.26.1590.0                 3D Audio Library
    x3daudio1_7.dll            9.28.1886.0                 3D Audio Library
    xactengine2_0.dll          9.11.519.0                  XACT Engine API
    xactengine2_1.dll          9.12.589.0                  XACT Engine API
    xactengine2_10.dll         9.21.1148.0                 XACT Engine API
    xactengine2_2.dll          9.13.644.0                  XACT Engine API
    xactengine2_3.dll          9.14.701.0                  XACT Engine API
    xactengine2_4.dll          9.15.779.0                  XACT Engine API
    xactengine2_5.dll          9.16.857.0                  XACT Engine API
    xactengine2_6.dll          9.17.892.0                  XACT Engine API
    xactengine2_7.dll          9.18.944.0                  XACT Engine API
    xactengine2_8.dll          9.19.1007.0                 XACT Engine API
    xactengine2_9.dll          9.20.1057.0                 XACT Engine API
    xactengine3_0.dll          9.22.1284.0                 XACT Engine API
    xactengine3_1.dll          9.23.1350.0                 XACT Engine API
    xactengine3_2.dll          9.24.1400.0                 XACT Engine API
    xactengine3_3.dll          9.25.1476.0                 XACT Engine API
    xactengine3_4.dll          9.26.1590.0                 XACT Engine API
    xactengine3_5.dll          9.27.1734.0                 XACT Engine API
    xactengine3_6.dll          9.28.1886.0                 XACT Engine API
    xactengine3_7.dll          9.29.1962.0                 XACT Engine API
    xapofx1_0.dll              9.23.1350.0                 XAPOFX
    xapofx1_1.dll              9.24.1400.0                 XAPOFX
    xapofx1_2.dll              9.25.1476.0                 XAPOFX
    xapofx1_3.dll              9.26.1590.0                 Audio Effect Library
    xapofx1_4.dll              9.28.1886.0                 Audio Effect Library
    xapofx1_5.dll              9.29.1962.0                 Audio Effect Library
    xaudio2_0.dll              9.22.1284.0                 XAudio2 Game Audio API
    xaudio2_1.dll              9.23.1350.0                 XAudio2 Game Audio API
    xaudio2_2.dll              9.24.1400.0                 XAudio2 Game Audio API
    xaudio2_3.dll              9.25.1476.0                 XAudio2 Game Audio API
    xaudio2_4.dll              9.26.1590.0                 XAudio2 Game Audio API
    xaudio2_5.dll              9.27.1734.0                 XAudio2 Game Audio API
    xaudio2_6.dll              9.28.1886.0                 XAudio2 Game Audio API
    xaudio2_7.dll              9.29.1962.0                 XAudio2 Game Audio API
    xaudio2_8.dll              6.3.9600.16384              XAudio2 Game Audio API
    xinput1_1.dll              9.12.589.0                  Microsoft Common Controller API
    xinput1_2.dll              9.14.701.0                  Microsoft Common Controller API
    xinput1_3.dll              9.18.944.0                  Microsoft Common Controller API
    xinput1_4.dll              6.3.9600.16384              API   ()
    xinput9_1_0.dll            6.3.9600.16384                XNA
    xlive.dll                  3.5.92.0                    Games for Windows - LIVE DLL
    xlivefnt.dll               2.0.673.0                   XLive Fonts DLL
    xmlfilter.dll              2008.0.9600.16384            XML
    xmllite.dll                6.3.9600.16384              Microsoft XmlLite Library
    xmlprovi.dll               6.3.9600.16384              Network Provisioning Service Client API
    xmlrw.dll                  2011.110.2809.27            Microsoft XML Slim Library
    xmlrwbin.dll               2011.110.2809.27            Microsoft XML Slim Library
    xolehlp.dll                2001.12.10530.16384         Microsoft Distributed Transaction Coordinator Helper APIs DLL
    xpsfilt.dll                6.3.9600.16384              XML Paper Specification Document IFilter
    xpsgdiconverter.dll        6.3.9600.17053              XPS to GDI Converter
    xpsprint.dll               6.3.9600.17238              XPS Printing DLL
    xpsrasterservice.dll       6.3.9600.16384              XPS Rasterization Service Component
    xpsservices.dll            6.3.9600.16384              Xps Object Model in memory creation and deserialization
    xpsshhdr.dll               6.3.9600.16384              OPC Shell Metadata Handler
    xpssvcs.dll                6.3.9600.16384              Native Code Xps Services Library
    xwizards.dll               6.3.9600.16384                 
    xwreg.dll                  6.3.9600.16384              Extensible Wizard Registration Manager Module
    xwtpdui.dll                6.3.9600.16384                   DUI
    xwtpw32.dll                6.3.9600.16384                   Win32
    zipfldr.dll                6.3.9600.17031               ZIP-


--------[   ]------------------------------------------------------------------------------------------------

     :
                         17.08.2014 22:58:52
                           17.08.2014 22:59:39
                                            17.08.2014 23:24:11
                                             1523  (0 ., 0 , 25 , 23 )

      :
                                     26.07.2014 16:13:30
                            26.07.2014 16:12:50
                                        1925264  (22 ., 6 , 47 , 44 )
                                       1468  (0 ., 0 , 24 , 28 )
                                  242111  (2 ., 19 , 15 , 11 )
                                 111  (0 ., 0 , 1 , 51 )
                                       65
                                99.92%

      (" "):
                                        16.08.2014 20:47:47
                                     16.08.2014 20:47:47
                                              1

    :
                                                    


--------[   ]-----------------------------------------------------------------------------------------------

    E                                                                                  E:\
    Users                                                                              C:\Users
                                                                              E:\ \
                                                                               E:\ \
                                                                                 E:\
                                                                             E:\ \
    IPC$                            IPC            IPC                             


--------[  ]------------------------------------------------------------------------------------------------

       :
                                          
                                             Black_SOKOL
                              
                      
      ./.                      0 / 42 .
                                  0 
                                     
                                       
                                30 
                                30 


--------[    ]----------------------------------------------------------------------------------------------

    nicksab1491@mail.ru                                                      MicrosoftAccount
    nicksab1491@mail.ru                                                      MicrosoftAccount


--------[  ]------------------------------------------------------------------------------------------------

  [ Black_SOKOL ]

     :
                                         Black_SOKOL
                                               Black_SOKOL 123
                                               HomeUsers; ; 
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [ HomeGroupUser$ ]

     :
                                         HomeGroupUser$
                                               HomeGroupUser$
                                                       
                                               HomeUsers; 
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                                 /
                                               ; 
                                     3
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                                      
                                               ; 
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            


--------[   ]--------------------------------------------------------------------------------------------

  [ AMD FUEL ]

      :
                                             Members of this group can change AMD platform power controls within Catalyst Control Center to balance system performance with power usage.

  [ HomeUsers ]

      :
                                             HomeUsers Security Group

     :
      Black_SOKOL                                       Black_SOKOL 123
      HomeGroupUser$                                    HomeGroupUser$
      nicksab1491@mail.ru                               
      WMPNetworkSvc                                     

  [ IIS_IUSRS ]

      :
                                              ,    IIS.

     :
      IUSR                                              

  [ WinRMRemoteWMIUsers__ ]

      :
                                             Members of this group can access WMI resources over management protocols (such as WS-Management via the Windows Remote Management service). This applies only to WMI namespaces that grant access to the user.

  [  Hyper-V ]

      :
                                                        Hyper-V.

  [  ]

      :
                                               ,         

     :
      Black_SOKOL                                       Black_SOKOL 123
                                           

  [  ]

      :
                                                   ,   ,     "",     .

     :
                                                   

  [   ]

      :
                                                 .

  [   ]

      :
                                                         

  [    ]

      :
                                                         

  [       ]

      :
                                                           .

  [   ]

      :
                                                        

  [  DCOM ]

      :
                                                 ,     DCOM   .

  [    ]

      :
                                                     ,         ,        .

  [    ]

      :
                                                  ,       

  [     ]

      :
                                                     

  [    ]

      :
                                                      WMI    (  WS-Management     Windows).      WMI,   .

  [  ]

      :
                                                         

     :
                                           
                                       

  [  ]

      :
                                                 

  [    ]

      :
                                                      


--------[   ]-------------------------------------------------------------------------------------------

  [  ]

      :
                                              

     :
      Black_SOKOL                                       Black_SOKOL 123
      HomeGroupUser$                                    HomeGroupUser$
                                           
                                                   


--------[  Windows ]-----------------------------------------------------------------------------------------------

  [ AMD Radeon HD 6520G ]

     :
                                      AMD Radeon HD 6520G
                                          AMD Radeon HD 6520G
       BIOS                                       BR40913.bin
                                      AMD Radeon HD 6520G (0x9647)
       DAC                                           Internal DAC(400MHz)
                                            04.07.2014
                                          13.251.9001.1001
                                       Advanced Micro Devices, Inc.
                                           512 

     :
      aticfx64                                          8.17.10.1247
      aticfx64                                          8.17.10.1247
      aticfx64                                          8.17.10.1247
      aticfx32                                          8.17.10.1247
      aticfx32                                          8.17.10.1247
      aticfx32                                          8.17.10.1247
      atiumd64                                          9.14.10.01001
      atidxx64                                          8.17.10.0525
      atidxx64                                          8.17.10.0525
      atiumdag                                          9.14.10.01001
      atidxx32                                          8.17.10.0525
      atidxx32                                          8.17.10.0525
      atiumdva                                          8.14.10.0429
      atiumd6a                                          8.14.10.0429
      atitmm64                                          6.14.11.25

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates

  [ AMD Radeon HD 6520G ]

     :
                                      AMD Radeon HD 6520G
                                          AMD Radeon HD 6520G
       BIOS                                       BR40913.bin
                                      AMD Radeon HD 6520G (0x9647)
       DAC                                           Internal DAC(400MHz)
                                            04.07.2014
                                          13.251.9001.1001
                                       Advanced Micro Devices, Inc.
                                           512 

     :
      aticfx64                                          8.17.10.1247
      aticfx64                                          8.17.10.1247
      aticfx64                                          8.17.10.1247
      aticfx32                                          8.17.10.1247
      aticfx32                                          8.17.10.1247
      aticfx32                                          8.17.10.1247
      atiumd64                                          9.14.10.01001
      atidxx64                                          8.17.10.0525
      atidxx64                                          8.17.10.0525
      atiumdag                                          9.14.10.01001
      atidxx32                                          8.17.10.0525
      atidxx32                                          8.17.10.0525
      atiumdva                                          8.14.10.0429
      atiumd6a                                          8.14.10.0429
      atitmm64                                          6.14.11.25

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates


--------[  PCI / AGP ]---------------------------------------------------------------------------------------------

    AMD Radeon HD 6450M/6470M/6490M (Seymour)                                         
    AMD Radeon HD 6520G (Sumo)                                                        
    AMD Radeon HD 6450M/6470M/6490M (Seymour)                                         3D-
    AMD Radeon HD 6520G (Sumo)                                                        3D-


--------[   ]---------------------------------------------------------------------------------------

  [ : AMD Radeon HD 6520G (Sumo) ]

      :
                                            AMD Radeon HD 6520G (Sumo)
       BIOS                                       012.043.000.014.040913
       BIOS                                         10.05.2011
                                       Sumo (BeaverCreek)
                                          BR40913.bin
      PCI-                                    1002-9647 / 1179-FC51  (Rev 00)
                                  32 nm
                                                 
                                           512 
                                               275   (original: 400 MHz)
       RAMDAC                                    400 
                                     8
                                 16
                                     320  (v5.0)
        DirectX                      DirectX v11
      PowerControl                                      0%
       WDDM                                       WDDM 1.2

    :
                                             ATI Terascale 2 (VLIW5)
        (CU)                       4
      SIMD                         1
       SIMD                                       16
        SIMD                            5
       L1                                            8  per CU
      Local Data Share                                  32 
      Global Data Share                                 64 

      :
                            2200 / @ 275 
                            4400 / @ 275 
      FLOPS                          176.0 GFLOPS @ 275 
      24-  IOPS                         35.2 GIOPS @ 275 
      32-  IOPS                         35.2 GIOPS @ 275 

    :
                                    12%
                                        0 
                                      164 

    ATI PowerPlay (BIOS):
      State #1                                           : 400 
      State #2                                           : 275 
      State #3                                           : 400   (UVD)
      State #4                                           : 275 
      State #5                                           : 400 
      State #6                                           : 200   (Boot)
      State #7                                           : 200   (Thermal)

      :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates

    ATI GPU Registers:
      ati-$04D0                                         00113C70
      ati-$061C                                         00000001
      ati-$0620                                         68683A32
      ati-$063C                                         0000FA02
      ati-$0668                                         00010000
      ati-$066C                                         00000000
      ati-$0678                                         00000077
      ati-$0684                                         0F0FA8BA
      ati-$0688                                         0F0F0F0F
      ati-$06D0                                         00000000
      ati-$070C                                         0986A048
      ati-$0750                                         00003FAC
      ati-$0754                                         00003FAC
      ati-$0770                                         00006403
      ati-$0774                                         00000001
      ati-$078C                                         00000000
      ati-$2004                                         00000210
      ati-$2760                                         008FF800
      ati-$5428                                         20000000
      ati-$8950                                         FFF0F001
      ati-$8954                                         00000000
      ati-$98F0                                         00000000
      ati-$98F4                                         00FC0001
      ati-$98F8                                         02110001
      ati-$9B7C                                         00000000

  [ PCI Express 2.0 x16: AMD Radeon HD 6450M/6470M/6490M (Seymour) ]

      :
                                            AMD Radeon HD 6450M/6470M/6490M (Seymour)
       BIOS                                       012.043.000.014.040913
       BIOS                                         10.05.2011
                                       Seymour XT/Pro
                                          BR40913.bin
      PCI-                                    1002-6760 / 1179-FC51  (Rev 00)
                                       370 .
                                  40 nm
                                         67 mm2
                                                 PCI Express 2.0 x16 @ 1.1 x1
                                           1 
       RAMDAC                                    400 
                                     4
                                 8
                                     160  (v5.0)
        DirectX                      DirectX v11
      PowerControl                                      0%

      :
                                                 GDDR3
                                              32 
                                         100  (DDR)  (original: 667 MHz)
                                      200 
                                   800 /

    :
                                             ATI Terascale 2 (VLIW5)
        (CU)                       2
      SIMD                         1
       SIMD                                       16
        SIMD                            5
       L1                                            8  per CU
      Local Data Share                                  32 
      Global Data Share                                 64 

    ATI PowerPlay (BIOS):
      State #1                                           : 400 
      State #2                                           : 275 
      State #3                                           : 400   (UVD)
      State #4                                           : 275 
      State #5                                           : 400 
      State #6                                           : 200   (Boot)
      State #7                                           : 200   (Thermal)

      :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates

    ATI GPU Registers:
      ati-$0600                                         00000000
      ati-$0604                                         00000000
      ati-$0608                                         00000000
      ati-$061C                                         00000000
      ati-$0624                                         00000000
      ati-$0628                                         00000000
      ati-$062C                                         00000000
      ati-$063C                                         00000000
      ati-$0660                                         00000000
      ati-$0668                                         00000000
      ati-$066C                                         00000000
      ati-$06D0                                         00000000
      ati-$0710                                         00000000
      ati-$0730                                         00000000
      ati-$073C                                         00000000
      ati-$0740                                         00000000
      ati-$0760                                         00000000
      ati-$0764                                         00000000
      ati-$0768                                         00000000
      ati-$0770                                         00000000
      ati-$078C                                         00000000
      ati-$1600                                         00000000
      ati-$2004                                         00000000
      ati-$2760                                         00000000
      ati-$2774                                         00000000
      ati-$2778                                         00000000
      ati-$28A0                                         00000000
      ati-$28A4                                         00000000
      ati-$28A8                                         00000000
      ati-$28AC                                         00000000
      ati-$28B0                                         00000000
      ati-$5428                                         00000400
      ati-$8950                                         00000000
      ati-$8954                                         00000000
      ati-$98F0                                         00000000
      ati-$98F4                                         00000000
      ati-$98F8                                         00000000
      ati-$98FC                                         00000000
      ati-$9B7C                                         00000000


--------[  ]-----------------------------------------------------------------------------------------------------

  [ LG Philips LP156WH4-TLA1 ]

     :
                                             LG Philips LP156WH4-TLA1
      ID                                        LGD02DC
                                           LG Display
                                                  LP156WH4-TLA1
                                             15.6" LCD (WXGA)
                                             2010
                                           
      .                         344 mm x 194 mm (15.5")
                                       16:9
                                  1366 x 768
                                                   2.20
        DPMS                        

     :
      1366 x 768                                         : 70.00 

     :
                                                   LG Electronics
                                     http://www.lg.com/us/monitors
                                       http://www.lg.com/us/support
                                     http://www.aida64.com/driver-updates


--------[   ]------------------------------------------------------------------------------------------------

      :
                                     
                                              1366 x 768
                                            32 
                                       1
                                        96 dpi
        /                         36 / 36
                                     51
                                      60 
                                    C:\Windows\web\wallpaper\Windows\img0.jpg

      :
       -                             
                                              
                                      
                              
      ClearType                                         
             
                                
                                  
                                      
                                  
                                 
                                            
                                   
       /           
                                           
                              
                               
                            
                              
      Windows Aero                                      
       Windows Plus!                               


--------[  ]-----------------------------------------------------------------------------------------------

    \\.\DISPLAY1           (0,0)          (1366,768)


--------[  ]-------------------------------------------------------------------------------------------------

    640 x 480           8   60 Hz
    640 x 480           8   60 Hz
    640 x 480           8   60 Hz
    640 x 480          16   60 Hz
    640 x 480          16   60 Hz
    640 x 480          16   60 Hz
    640 x 480          32   60 Hz
    640 x 480          32   60 Hz
    640 x 480          32   60 Hz
    800 x 480           8   60 Hz
    800 x 480           8   60 Hz
    800 x 480           8   60 Hz
    800 x 480          16   60 Hz
    800 x 480          16   60 Hz
    800 x 480          16   60 Hz
    800 x 480          32   60 Hz
    800 x 480          32   60 Hz
    800 x 480          32   60 Hz
    800 x 600           8   60 Hz
    800 x 600           8   60 Hz
    800 x 600           8   60 Hz
    800 x 600          16   60 Hz
    800 x 600          16   60 Hz
    800 x 600          16   60 Hz
    800 x 600          32   60 Hz
    800 x 600          32   60 Hz
    800 x 600          32   60 Hz
    1024 x 600          8   60 Hz
    1024 x 600          8   60 Hz
    1024 x 600          8   60 Hz
    1024 x 600         16   60 Hz
    1024 x 600         16   60 Hz
    1024 x 600         16   60 Hz
    1024 x 600         32   60 Hz
    1024 x 600         32   60 Hz
    1024 x 600         32   60 Hz
    1024 x 768          8   60 Hz
    1024 x 768          8   60 Hz
    1024 x 768          8   60 Hz
    1024 x 768         16   60 Hz
    1024 x 768         16   60 Hz
    1024 x 768         16   60 Hz
    1024 x 768         32   60 Hz
    1024 x 768         32   60 Hz
    1024 x 768         32   60 Hz
    1280 x 720          8   60 Hz
    1280 x 720          8   60 Hz
    1280 x 720          8   60 Hz
    1280 x 720         16   60 Hz
    1280 x 720         16   60 Hz
    1280 x 720         16   60 Hz
    1280 x 720         32   60 Hz
    1280 x 720         32   60 Hz
    1280 x 720         32   60 Hz
    1280 x 768          8   60 Hz
    1280 x 768          8   60 Hz
    1280 x 768          8   60 Hz
    1280 x 768         16   60 Hz
    1280 x 768         16   60 Hz
    1280 x 768         16   60 Hz
    1280 x 768         32   60 Hz
    1280 x 768         32   60 Hz
    1280 x 768         32   60 Hz
    1360 x 768          8   60 Hz
    1360 x 768          8   60 Hz
    1360 x 768          8   60 Hz
    1360 x 768         16   60 Hz
    1360 x 768         16   60 Hz
    1360 x 768         16   60 Hz
    1360 x 768         32   60 Hz
    1360 x 768         32   60 Hz
    1360 x 768         32   60 Hz
    1366 x 768          8   60 Hz
    1366 x 768         16   60 Hz
    1366 x 768         32   60 Hz


--------[ OpenGL ]------------------------------------------------------------------------------------------------------

     OpenGL:
                                           ATI Technologies Inc.
      Renderer                                          AMD Radeon HD 7400M Series
                                                  4.3.12618 Compatibility Profile Context 13.251.9001.1001
                                    4.30
      OpenGL DLL                                        6.3.9600.16384(winblue_rtm.130821-1623)
      Multitexture Texture Units                        8
      Occlusion Query Counter Bits                      32
      Sub-Pixel Precision                               8 
      Max Viewport Size                                 16384 x 16384
      Max Cube Map Texture Size                         16384 x 16384
      Max Rectangle Texture Size                        16384 x 16384
      Max 3D Texture Size                               2048 x 2048 x 2048
      Max Anisotropy                                    16
      Max Clipping Planes                               8
      Max Display-List Nesting Level                    64
      Max Draw Buffers                                  8
      Max Evaluator Order                               40
      Max Light Sources                                 8
      Max Pixel Map Table Size                          256
      Min / Max Program Texel Offset                    -8 / 7
      Max Texture Array Layers                          2048
      Max Texture LOD Bias                              16

     OpenGL:
      OpenGL 1.1                                          (100%)
      OpenGL 1.2                                          (100%)
      OpenGL 1.3                                          (100%)
      OpenGL 1.4                                          (100%)
      OpenGL 1.5                                          (100%)
      OpenGL 2.0                                          (100%)
      OpenGL 2.1                                          (100%)
      OpenGL 3.0                                          (100%)
      OpenGL 3.1                                          (100%)
      OpenGL 3.2                                          (100%)
      OpenGL 3.3                                          (100%)
      OpenGL 4.0                                          (100%)
      OpenGL 4.1                                          (100%)
      OpenGL 4.2                                          (100%)
      OpenGL 4.3                                          (100%)
      OpenGL 4.4                                          (33%)

    Max Stack Depth:
      Attribute Stack                                   16
      Client Attribute Stack                            16
      Modelview Matrix Stack                            32
      Name Stack                                        64
      Projection Matrix Stack                           10
      Texture Matrix Stack                              10

    Draw Range Elements:
      Max Index Count                                   16777215
      Max Vertex Count                                  2147483647

    Transform Feedback:
      Max Interleaved Components                        64
      Max Separate Attributes                           4
      Max Separate Components                           4

    Framebuffer Object:
      Max Color Attachments                             8
      Max Render Buffer Size                            16384 x 16384

    Imaging:
      Max Color Matrix Stack Depth                      10
      Max Convolution Width / Height                    11 / 11

    Vertex Shader:
      Max Uniform Vertex Components                     16384
      Max Varying Floats                                128
      Max Vertex Texture Image Units                    16
      Max Combined Texture Image Units                  32

    Geometry Shader:
      Max Geometry Texture Units                        16
      Max Varying Components                            128
      Max Geometry Varying Components                   128
      Max Vertex Varying Components                     128
      Max Geometry Uniform Components                   16384
      Max Geometry Output Vertices                      1024
      Max Geometry Total Output Components              16384

    Fragment Shader:
      Max Uniform Fragment Components                   16384
      Max Fragment Registers                            6
      Max Fragment Constants                            8
      Max Passes                                        2
      Max Instructions Per Pass                         8
      Max Total Instructions                            16
      Max Input Interpolator Components                 3
      Max Loopback Components                           3

    Vertex Program:
      Max Local Parameters                              256
      Max Environment Parameters                        256
      Max Program Matrices                              32
      Max Program Matrix Stack Depth                    32
      Max Vertex Attributes                             29
      Max Instructions                                  2147483647
      Max Native Instructions                           2147483647
      Max Temporaries                                   320
      Max Native Temporaries                            256
      Max Parameters                                    256
      Max Native Parameters                             256
      Max Attributes                                    29
      Max Native Attributes                             32
      Max Address Registers                             1
      Max Native Address Registers                      1

    Fragment Program:
      Max Local Parameters                              256
      Max Environment Parameters                        256
      Max Texture Coordinates                           16
      Max Texture Image Units                           16
      Max Instructions                                  2147483647
      Max Native Instructions                           2147483647
      Max Temporaries                                   320
      Max Native Temporaries                            256
      Max Parameters                                    256
      Max Native Parameters                             256
      Max Attributes                                    29
      Max Native Attributes                             16
      Max Address Registers                             0
      Max Native Address Registers                      0
      Max ALU Instructions                              2147483647
      Max Native ALU Instructions                       2147483647
      Max Texture Instructions                          2147483647
      Max Native Texture Instructions                   2147483647
      Max Texture Indirections                          2147483647
      Max Native Texture Indirections                   2147483647

     OpenGL:
       /                   968 / 264
      GL_3DFX_multisample                                
      GL_3DFX_tbuffer                                    
      GL_3DFX_texture_compression_FXT1                   
      GL_3DL_direct_texture_access2                      
      GL_3Dlabs_multisample_transparency_id              
      GL_3Dlabs_multisample_transparency_range           
      GL_AMD_blend_minmax_factor                         
      GL_AMD_compressed_3DC_texture                      
      GL_AMD_compressed_ATC_texture                      
      GL_AMD_conservative_depth                         
      GL_AMD_debug_output                               
      GL_AMD_depth_clamp_separate                       
      GL_AMD_draw_buffers_blend                         
      GL_AMD_framebuffer_sample_positions                
      GL_AMD_gcn_shader                                  
      GL_AMD_gpu_shader_int64                            
      GL_AMD_interleaved_elements                        
      GL_AMD_multi_draw_indirect                        
      GL_AMD_name_gen_delete                            
      GL_AMD_occlusion_query_event                       
      GL_AMD_performance_monitor                        
      GL_AMD_pinned_memory                              
      GL_AMD_program_binary_Z400                         
      GL_AMD_query_buffer_object                        
      GL_AMD_sample_positions                           
      GL_AMD_seamless_cubemap_per_texture               
      GL_AMD_shader_atomic_counter_ops                   
      GL_AMD_shader_stencil_export                      
      GL_AMD_shader_stencil_value_export                 
      GL_AMD_shader_trace                               
      GL_AMD_shader_trinary_minmax                       
      GL_AMD_sparse_texture                              
      GL_AMD_sparse_texture_pool                         
      GL_AMD_stencil_operation_extended                  
      GL_AMD_texture_compression_dxt6                    
      GL_AMD_texture_compression_dxt7                    
      GL_AMD_texture_cube_map_array                     
      GL_AMD_texture_texture4                           
      GL_AMD_texture_tile_pool                           
      GL_AMD_transform_feedback3_lines_triangles        
      GL_AMD_transform_feedback4                         
      GL_AMD_vertex_shader_layer                        
      GL_AMD_vertex_shader_tessellator                  
      GL_AMD_vertex_shader_viewport_index               
      GL_AMDX_debug_output                              
      GL_AMDX_name_gen_delete                            
      GL_AMDX_random_access_target                       
      GL_AMDX_vertex_shader_tessellator                 
      GL_ANDROID_extension_pack_es31a                    
      GL_ANGLE_depth_texture                             
      GL_ANGLE_framebuffer_blit                          
      GL_ANGLE_framebuffer_multisample                   
      GL_ANGLE_instanced_arrays                          
      GL_ANGLE_pack_reverse_row_order                    
      GL_ANGLE_program_binary                            
      GL_ANGLE_texture_compression_dxt1                  
      GL_ANGLE_texture_compression_dxt3                  
      GL_ANGLE_texture_compression_dxt5                  
      GL_ANGLE_texture_usage                             
      GL_ANGLE_translated_shader_source                  
      GL_APPLE_aux_depth_stencil                         
      GL_APPLE_client_storage                            
      GL_APPLE_copy_texture_levels                       
      GL_APPLE_element_array                             
      GL_APPLE_fence                                     
      GL_APPLE_float_pixels                              
      GL_APPLE_flush_buffer_range                        
      GL_APPLE_flush_render                              
      GL_APPLE_framebuffer_multisample                   
      GL_APPLE_object_purgeable                          
      GL_APPLE_packed_pixel                              
      GL_APPLE_packed_pixels                             
      GL_APPLE_pixel_buffer                              
      GL_APPLE_rgb_422                                   
      GL_APPLE_row_bytes                                 
      GL_APPLE_specular_vector                           
      GL_APPLE_sync                                      
      GL_APPLE_texture_2D_limited_npot                   
      GL_APPLE_texture_format_BGRA8888                   
      GL_APPLE_texture_max_level                         
      GL_APPLE_texture_range                             
      GL_APPLE_transform_hint                            
      GL_APPLE_vertex_array_object                       
      GL_APPLE_vertex_array_range                        
      GL_APPLE_vertex_point_size                         
      GL_APPLE_vertex_program_evaluators                 
      GL_APPLE_ycbcr_422                                 
      GL_ARB_arrays_of_arrays                           
      GL_ARB_base_instance                              
      GL_ARB_bindless_texture                            
      GL_ARB_blend_func_extended                        
      GL_ARB_buffer_storage                              
      GL_ARB_cl_event                                    
      GL_ARB_clear_buffer_object                        
      GL_ARB_clear_texture                               
      GL_ARB_color_buffer_float                         
      GL_ARB_compatibility                              
      GL_ARB_compressed_texture_pixel_storage           
      GL_ARB_compute_shader                             
      GL_ARB_compute_variable_group_size                 
      GL_ARB_conservative_depth                         
      GL_ARB_copy_buffer                                
      GL_ARB_copy_image                                 
      GL_ARB_debug_group                                 
      GL_ARB_debug_label                                 
      GL_ARB_debug_output                               
      GL_ARB_debug_output2                               
      GL_ARB_depth_buffer_float                         
      GL_ARB_depth_clamp                                
      GL_ARB_depth_texture                              
      GL_ARB_draw_buffers                               
      GL_ARB_draw_buffers_blend                         
      GL_ARB_draw_elements_base_vertex                  
      GL_ARB_draw_indirect                              
      GL_ARB_draw_instanced                             
      GL_ARB_enhanced_layouts                            
      GL_ARB_ES2_compatibility                          
      GL_ARB_ES3_compatibility                          
      GL_ARB_explicit_attrib_location                   
      GL_ARB_explicit_uniform_location                  
      GL_ARB_fragment_coord_conventions                 
      GL_ARB_fragment_layer_viewport                    
      GL_ARB_fragment_program                           
      GL_ARB_fragment_program_shadow                    
      GL_ARB_fragment_shader                            
      GL_ARB_framebuffer_no_attachments                 
      GL_ARB_framebuffer_object                         
      GL_ARB_framebuffer_sRGB                           
      GL_ARB_geometry_shader4                           
      GL_ARB_get_program_binary                         
      GL_ARB_gpu_shader_fp64                            
      GL_ARB_gpu_shader5                                
      GL_ARB_half_float_pixel                           
      GL_ARB_half_float_vertex                          
      GL_ARB_imaging                                    
      GL_ARB_indirect_parameters                         
      GL_ARB_instanced_arrays                           
      GL_ARB_internalformat_query                       
      GL_ARB_internalformat_query2                      
      GL_ARB_invalidate_subdata                         
      GL_ARB_make_current_read                           
      GL_ARB_map_buffer_alignment                       
      GL_ARB_map_buffer_range                           
      GL_ARB_matrix_palette                              
      GL_ARB_multi_bind                                  
      GL_ARB_multi_draw_indirect                        
      GL_ARB_multisample                                
      GL_ARB_multitexture                               
      GL_ARB_occlusion_query                            
      GL_ARB_occlusion_query2                           
      GL_ARB_pixel_buffer_object                        
      GL_ARB_point_parameters                           
      GL_ARB_point_sprite                               
      GL_ARB_program_interface_query                    
      GL_ARB_provoking_vertex                           
      GL_ARB_query_buffer_object                        
      GL_ARB_robust_buffer_access_behavior               
      GL_ARB_robustness                                  
      GL_ARB_robustness_isolation                        
      GL_ARB_sample_shading                             
      GL_ARB_sampler_objects                            
      GL_ARB_seamless_cube_map                          
      GL_ARB_seamless_cubemap_per_texture               
      GL_ARB_separate_shader_objects                    
      GL_ARB_shader_atomic_counters                     
      GL_ARB_shader_bit_encoding                        
      GL_ARB_shader_draw_parameters                      
      GL_ARB_shader_group_vote                           
      GL_ARB_shader_image_load_store                    
      GL_ARB_shader_image_size                          
      GL_ARB_shader_objects                             
      GL_ARB_shader_precision                           
      GL_ARB_shader_stencil_export                      
      GL_ARB_shader_storage_buffer_object               
      GL_ARB_shader_subroutine                          
      GL_ARB_shader_texture_lod                         
      GL_ARB_shading_language_100                       
      GL_ARB_shading_language_120                        
      GL_ARB_shading_language_420pack                   
      GL_ARB_shading_language_include                    
      GL_ARB_shading_language_packing                   
      GL_ARB_shadow                                     
      GL_ARB_shadow_ambient                             
      GL_ARB_sparse_texture                              
      GL_ARB_stencil_texturing                          
      GL_ARB_swap_buffers                                
      GL_ARB_sync                                       
      GL_ARB_tessellation_shader                        
      GL_ARB_texture_border_clamp                       
      GL_ARB_texture_buffer_object                      
      GL_ARB_texture_buffer_object_rgb32                
      GL_ARB_texture_buffer_range                       
      GL_ARB_texture_compression                        
      GL_ARB_texture_compression_bptc                   
      GL_ARB_texture_compression_rgtc                   
      GL_ARB_texture_compression_rtgc                    
      GL_ARB_texture_cube_map                           
      GL_ARB_texture_cube_map_array                     
      GL_ARB_texture_env_add                            
      GL_ARB_texture_env_combine                        
      GL_ARB_texture_env_crossbar                       
      GL_ARB_texture_env_dot3                           
      GL_ARB_texture_float                              
      GL_ARB_texture_gather                             
      GL_ARB_texture_mirror_clamp_to_edge               
      GL_ARB_texture_mirrored_repeat                    
      GL_ARB_texture_multisample                        
      GL_ARB_texture_non_power_of_two                   
      GL_ARB_texture_query_levels                       
      GL_ARB_texture_query_lod                          
      GL_ARB_texture_rectangle                          
      GL_ARB_texture_rg                                 
      GL_ARB_texture_rgb10_a2ui                         
      GL_ARB_texture_snorm                              
      GL_ARB_texture_stencil8                            
      GL_ARB_texture_storage                            
      GL_ARB_texture_storage_multisample                
      GL_ARB_texture_swizzle                             
      GL_ARB_texture_view                               
      GL_ARB_timer_query                                
      GL_ARB_transform_feedback_instanced               
      GL_ARB_transform_feedback2                        
      GL_ARB_transform_feedback3                        
      GL_ARB_transpose_matrix                           
      GL_ARB_uber_buffers                                
      GL_ARB_uber_mem_image                              
      GL_ARB_uber_vertex_array                           
      GL_ARB_uniform_buffer_object                      
      GL_ARB_vertex_array_bgra                          
      GL_ARB_vertex_array_object                        
      GL_ARB_vertex_attrib_64bit                        
      GL_ARB_vertex_attrib_binding                      
      GL_ARB_vertex_blend                                
      GL_ARB_vertex_buffer_object                       
      GL_ARB_vertex_program                             
      GL_ARB_vertex_shader                              
      GL_ARB_vertex_type_10f_11f_11f_rev                
      GL_ARB_vertex_type_2_10_10_10_rev                 
      GL_ARB_viewport_array                             
      GL_ARB_window_pos                                 
      GL_ARM_mali_program_binary                         
      GL_ARM_mali_shader_binary                          
      GL_ARM_rgba8                                       
      GL_ARM_shader_framebuffer_fetch                    
      GL_ARM_shader_framebuffer_fetch_depth_stencil      
      GL_ATI_array_rev_comps_in_4_bytes                  
      GL_ATI_blend_equation_separate                     
      GL_ATI_blend_weighted_minmax                       
      GL_ATI_draw_buffers                               
      GL_ATI_element_array                               
      GL_ATI_envmap_bumpmap                             
      GL_ATI_fragment_shader                            
      GL_ATI_lock_texture                                
      GL_ATI_map_object_buffer                           
      GL_ATI_meminfo                                     
      GL_ATI_pixel_format_float                          
      GL_ATI_pn_triangles                                
      GL_ATI_point_cull_mode                             
      GL_ATI_separate_stencil                           
      GL_ATI_shader_texture_lod                          
      GL_ATI_text_fragment_shader                        
      GL_ATI_texture_compression_3dc                    
      GL_ATI_texture_env_combine3                       
      GL_ATI_texture_float                              
      GL_ATI_texture_mirror_once                        
      GL_ATI_vertex_array_object                         
      GL_ATI_vertex_attrib_array_object                  
      GL_ATI_vertex_blend                                
      GL_ATI_vertex_shader                               
      GL_ATI_vertex_streams                              
      GL_ATIX_pn_triangles                               
      GL_ATIX_texture_env_combine3                       
      GL_ATIX_texture_env_route                          
      GL_ATIX_vertex_shader_output_point_size            
      GL_Autodesk_facet_normal                           
      GL_Autodesk_valid_back_buffer_hint                 
      GL_CR_bounding_box                                 
      GL_CR_cursor_position                              
      GL_CR_head_spu_name                                
      GL_CR_performance_info                             
      GL_CR_print_string                                 
      GL_CR_readback_barrier_size                        
      GL_CR_saveframe                                    
      GL_CR_server_id_sharing                            
      GL_CR_server_matrix                                
      GL_CR_state_parameter                              
      GL_CR_synchronization                              
      GL_CR_tile_info                                    
      GL_CR_tilesort_info                                
      GL_CR_window_size                                  
      GL_DIMD_YUV                                        
      GL_DMP_shader_binary                               
      GL_EXT_422_pixels                                  
      GL_EXT_abgr                                       
      GL_EXT_bgra                                       
      GL_EXT_bindable_uniform                           
      GL_EXT_blend_color                                
      GL_EXT_blend_equation_separate                    
      GL_EXT_blend_func_separate                        
      GL_EXT_blend_logic_op                              
      GL_EXT_blend_minmax                               
      GL_EXT_blend_subtract                             
      GL_EXT_Cg_shader                                   
      GL_EXT_clip_control                                
      GL_EXT_clip_volume_hint                            
      GL_EXT_cmyka                                       
      GL_EXT_color_buffer_float                          
      GL_EXT_color_buffer_half_float                     
      GL_EXT_color_matrix                                
      GL_EXT_color_subtable                              
      GL_EXT_color_table                                 
      GL_EXT_compiled_vertex_array                      
      GL_EXT_convolution                                 
      GL_EXT_convolution_border_modes                    
      GL_EXT_coordinate_frame                            
      GL_EXT_copy_buffer                                
      GL_EXT_copy_image                                  
      GL_EXT_copy_texture                               
      GL_EXT_cull_vertex                                 
      GL_EXT_debug_label                                 
      GL_EXT_debug_marker                                
      GL_EXT_depth_bounds_test                           
      GL_EXT_depth_buffer_float                          
      GL_EXT_direct_state_access                        
      GL_EXT_discard_framebuffer                         
      GL_EXT_disjoint_timer_query                        
      GL_EXT_draw_buffers                                
      GL_EXT_draw_buffers_indexed                        
      GL_EXT_draw_buffers2                              
      GL_EXT_draw_indirect                               
      GL_EXT_draw_instanced                             
      GL_EXT_draw_range_elements                        
      GL_EXT_fog_coord                                  
      GL_EXT_fog_function                                
      GL_EXT_fog_offset                                  
      GL_EXT_frag_depth                                  
      GL_EXT_fragment_lighting                           
      GL_EXT_framebuffer_blit                           
      GL_EXT_framebuffer_multisample                    
      GL_EXT_framebuffer_multisample_blit_scaled         
      GL_EXT_framebuffer_object                         
      GL_EXT_framebuffer_sRGB                           
      GL_EXT_generate_mipmap                             
      GL_EXT_geometry_point_size                         
      GL_EXT_geometry_shader                             
      GL_EXT_geometry_shader4                           
      GL_EXT_glx_stereo_tree                             
      GL_EXT_gpu_program_parameters                     
      GL_EXT_gpu_shader_fp64                             
      GL_EXT_gpu_shader4                                
      GL_EXT_gpu_shader5                                 
      GL_EXT_histogram                                  
      GL_EXT_import_sync_object                          
      GL_EXT_index_array_formats                         
      GL_EXT_index_func                                  
      GL_EXT_index_material                              
      GL_EXT_index_texture                               
      GL_EXT_instanced_arrays                            
      GL_EXT_interlace                                   
      GL_EXT_light_texture                               
      GL_EXT_map_buffer_range                            
      GL_EXT_misc_attribute                              
      GL_EXT_multi_draw_arrays                          
      GL_EXT_multisample                                 
      GL_EXT_multisampled_render_to_texture              
      GL_EXT_multiview_draw_buffers                      
      GL_EXT_occlusion_query_boolean                     
      GL_EXT_packed_depth_stencil                       
      GL_EXT_packed_float                               
      GL_EXT_packed_pixels                              
      GL_EXT_packed_pixels_12                            
      GL_EXT_paletted_texture                            
      GL_EXT_pixel_buffer_object                        
      GL_EXT_pixel_format                                
      GL_EXT_pixel_texture                               
      GL_EXT_pixel_transform                             
      GL_EXT_pixel_transform_color_table                 
      GL_EXT_point_parameters                           
      GL_EXT_polygon_offset                              
      GL_EXT_primitive_bounding_box                      
      GL_EXT_provoking_vertex                           
      GL_EXT_pvrtc_sRGB                                  
      GL_EXT_read_format_bgra                            
      GL_EXT_rescale_normal                             
      GL_EXT_robustness                                  
      GL_EXT_scene_marker                                
      GL_EXT_secondary_color                            
      GL_EXT_separate_shader_objects                     
      GL_EXT_separate_specular_color                    
      GL_EXT_shader_atomic_counters                      
      GL_EXT_shader_framebuffer_fetch                    
      GL_EXT_shader_image_load_formatted                 
      GL_EXT_shader_image_load_store                    
      GL_EXT_shader_implicit_conversions                 
      GL_EXT_shader_integer_mix                          
      GL_EXT_shader_io_blocks                            
      GL_EXT_shader_pixel_local_storage                  
      GL_EXT_shader_subroutine                           
      GL_EXT_shader_texture_lod                          
      GL_EXT_shadow_funcs                               
      GL_EXT_shadow_samplers                             
      GL_EXT_shared_texture_palette                      
      GL_EXT_sRGB                                        
      GL_EXT_sRGB_write_control                          
      GL_EXT_static_vertex_array                         
      GL_EXT_stencil_clear_tag                           
      GL_EXT_stencil_two_side                            
      GL_EXT_stencil_wrap                               
      GL_EXT_subtexture                                 
      GL_EXT_swap_control                                
      GL_EXT_tessellation_point_size                     
      GL_EXT_tessellation_shader                         
      GL_EXT_texgen_reflection                          
      GL_EXT_texture                                     
      GL_EXT_texture_array                              
      GL_EXT_texture_border_clamp                        
      GL_EXT_texture_buffer                              
      GL_EXT_texture_buffer_object                      
      GL_EXT_texture_buffer_object_rgb32                 
      GL_EXT_texture_color_table                         
      GL_EXT_texture_compression_bptc                   
      GL_EXT_texture_compression_dxt1                    
      GL_EXT_texture_compression_latc                   
      GL_EXT_texture_compression_rgtc                   
      GL_EXT_texture_compression_s3tc                   
      GL_EXT_texture_cube_map                           
      GL_EXT_texture_cube_map_array                      
      GL_EXT_texture_edge_clamp                         
      GL_EXT_texture_env                                 
      GL_EXT_texture_env_add                            
      GL_EXT_texture_env_combine                        
      GL_EXT_texture_env_dot3                           
      GL_EXT_texture_filter_anisotropic                 
      GL_EXT_texture_format_BGRA8888                     
      GL_EXT_texture_integer                            
      GL_EXT_texture_lod                                
      GL_EXT_texture_lod_bias                           
      GL_EXT_texture_mirror_clamp                       
      GL_EXT_texture_object                             
      GL_EXT_texture_perturb_normal                      
      GL_EXT_texture_rectangle                          
      GL_EXT_texture_rg                                  
      GL_EXT_texture_shared_exponent                    
      GL_EXT_texture_snorm                              
      GL_EXT_texture_sRGB                               
      GL_EXT_texture_sRGB_decode                        
      GL_EXT_texture_storage                            
      GL_EXT_texture_swizzle                            
      GL_EXT_texture_type_2_10_10_10_REV                 
      GL_EXT_texture_view                                
      GL_EXT_texture3D                                  
      GL_EXT_texture4D                                   
      GL_EXT_timer_query                                
      GL_EXT_transform_feedback                         
      GL_EXT_transform_feedback2                         
      GL_EXT_transform_feedback3                         
      GL_EXT_unpack_subimage                             
      GL_EXT_vertex_array                               
      GL_EXT_vertex_array_bgra                          
      GL_EXT_vertex_array_set                            
      GL_EXT_vertex_array_setXXX                         
      GL_EXT_vertex_attrib_64bit                        
      GL_EXT_vertex_shader                               
      GL_EXT_vertex_weighting                            
      GL_EXT_x11_sync_object                             
      GL_EXTX_framebuffer_mixed_formats                  
      GL_EXTX_packed_depth_stencil                       
      GL_FGL_lock_texture                                
      GL_FJ_shader_binary_GCCSO                          
      GL_GL2_geometry_shader                             
      GL_GREMEDY_frame_terminator                        
      GL_GREMEDY_string_marker                           
      GL_HP_convolution_border_modes                     
      GL_HP_image_transform                              
      GL_HP_occlusion_test                               
      GL_HP_texture_lighting                             
      GL_I3D_argb                                        
      GL_I3D_color_clamp                                 
      GL_I3D_interlace_read                              
      GL_IBM_clip_check                                  
      GL_IBM_cull_vertex                                 
      GL_IBM_load_named_matrix                           
      GL_IBM_multi_draw_arrays                           
      GL_IBM_multimode_draw_arrays                       
      GL_IBM_occlusion_cull                              
      GL_IBM_pixel_filter_hint                           
      GL_IBM_rasterpos_clip                              
      GL_IBM_rescale_normal                              
      GL_IBM_static_data                                 
      GL_IBM_texture_clamp_nodraw                        
      GL_IBM_texture_mirrored_repeat                    
      GL_IBM_vertex_array_lists                          
      GL_IBM_YCbCr                                       
      GL_IMG_multisampled_render_to_texture              
      GL_IMG_program_binary                              
      GL_IMG_read_format                                 
      GL_IMG_sgx_binary                                  
      GL_IMG_shader_binary                               
      GL_IMG_texture_compression_pvrtc                   
      GL_IMG_texture_compression_pvrtc2                  
      GL_IMG_texture_env_enhanced_fixed_function         
      GL_IMG_texture_format_BGRA8888                     
      GL_IMG_user_clip_plane                             
      GL_IMG_vertex_program                              
      GL_INGR_blend_func_separate                        
      GL_INGR_color_clamp                                
      GL_INGR_interlace_read                             
      GL_INGR_multiple_palette                           
      GL_INTEL_compute_shader_lane_shift                 
      GL_INTEL_conservative_rasterization                
      GL_INTEL_fragment_shader_ordering                  
      GL_INTEL_fragment_shader_span_sharing              
      GL_INTEL_image_serialize                           
      GL_INTEL_map_texture                               
      GL_INTEL_parallel_arrays                           
      GL_INTEL_performance_queries                       
      GL_INTEL_performance_query                         
      GL_INTEL_texture_scissor                           
      GL_KHR_blend_equation_advanced                     
      GL_KHR_blend_equation_advanced_coherent            
      GL_KHR_debug                                      
      GL_KHR_texture_compression_astc_hdr                
      GL_KHR_texture_compression_astc_ldr                
      GL_KTX_buffer_region                              
      GL_MESA_pack_invert                                
      GL_MESA_program_debug                              
      GL_MESA_resize_buffers                             
      GL_MESA_texture_array                              
      GL_MESA_texture_signed_rgba                        
      GL_MESA_window_pos                                 
      GL_MESA_ycbcr_texture                              
      GL_MESAX_texture_float                             
      GL_MESAX_texture_stack                             
      GL_MTX_fragment_shader                             
      GL_MTX_precision_dpi                               
      GL_NV_3dvision_settings                            
      GL_NV_alpha_test                                   
      GL_NV_bgr                                          
      GL_NV_bindless_multi_draw_indirect                 
      GL_NV_bindless_multi_draw_indirect_count           
      GL_NV_bindless_texture                             
      GL_NV_blend_equation_advanced                      
      GL_NV_blend_equation_advanced_coherent             
      GL_NV_blend_minmax                                 
      GL_NV_blend_square                                
      GL_NV_centroid_sample                              
      GL_NV_complex_primitives                           
      GL_NV_compute_program5                             
      GL_NV_conditional_render                          
      GL_NV_copy_buffer                                  
      GL_NV_copy_depth_to_color                         
      GL_NV_copy_image                                  
      GL_NV_coverage_sample                              
      GL_NV_deep_texture3D                               
      GL_NV_depth_buffer_float                           
      GL_NV_depth_clamp                                  
      GL_NV_depth_nonlinear                              
      GL_NV_depth_range_unclamped                        
      GL_NV_draw_buffers                                 
      GL_NV_draw_instanced                               
      GL_NV_draw_texture                                 
      GL_NV_EGL_stream_consumer_external                 
      GL_NV_ES1_1_compatibility                          
      GL_NV_ES3_1_compatibility                          
      GL_NV_evaluators                                   
      GL_NV_explicit_attrib_location                     
      GL_NV_explicit_multisample                        
      GL_NV_fbo_color_attachments                        
      GL_NV_fence                                        
      GL_NV_float_buffer                                
      GL_NV_fog_distance                                 
      GL_NV_fragdepth                                    
      GL_NV_fragment_program                             
      GL_NV_fragment_program_option                      
      GL_NV_fragment_program2                            
      GL_NV_fragment_program4                            
      GL_NV_framebuffer_blit                             
      GL_NV_framebuffer_multisample                      
      GL_NV_framebuffer_multisample_coverage             
      GL_NV_framebuffer_multisample_ex                   
      GL_NV_generate_mipmap_sRGB                         
      GL_NV_geometry_program4                            
      GL_NV_geometry_shader4                             
      GL_NV_gpu_program_fp64                             
      GL_NV_gpu_program4                                 
      GL_NV_gpu_program4_1                               
      GL_NV_gpu_program5                                 
      GL_NV_gpu_program5_mem_extended                    
      GL_NV_gpu_shader5                                  
      GL_NV_half_float                                  
      GL_NV_instanced_arrays                             
      GL_NV_light_max_exponent                           
      GL_NV_multisample_coverage                         
      GL_NV_multisample_filter_hint                      
      GL_NV_non_square_matrices                          
      GL_NV_occlusion_query                              
      GL_NV_pack_subimage                                
      GL_NV_packed_depth_stencil                         
      GL_NV_packed_float                                 
      GL_NV_packed_float_linear                          
      GL_NV_parameter_buffer_object                      
      GL_NV_parameter_buffer_object2                     
      GL_NV_path_rendering                               
      GL_NV_pixel_buffer_object                          
      GL_NV_pixel_data_range                             
      GL_NV_platform_binary                              
      GL_NV_point_sprite                                 
      GL_NV_present_video                                
      GL_NV_primitive_restart                           
      GL_NV_read_buffer                                  
      GL_NV_read_buffer_front                            
      GL_NV_read_depth                                   
      GL_NV_read_depth_stencil                           
      GL_NV_read_stencil                                 
      GL_NV_register_combiners                           
      GL_NV_register_combiners2                          
      GL_NV_shader_atomic_counters                       
      GL_NV_shader_atomic_float                          
      GL_NV_shader_atomic_int64                          
      GL_NV_shader_buffer_load                           
      GL_NV_shader_buffer_store                          
      GL_NV_shader_storage_buffer_object                 
      GL_NV_shader_thread_group                          
      GL_NV_shader_thread_shuffle                        
      GL_NV_shadow_samplers_array                        
      GL_NV_shadow_samplers_cube                         
      GL_NV_sRGB_formats                                 
      GL_NV_tessellation_program5                        
      GL_NV_texgen_emboss                                
      GL_NV_texgen_reflection                           
      GL_NV_texture_array                                
      GL_NV_texture_barrier                             
      GL_NV_texture_border_clamp                         
      GL_NV_texture_compression_latc                     
      GL_NV_texture_compression_s3tc                     
      GL_NV_texture_compression_s3tc_update              
      GL_NV_texture_compression_vtc                      
      GL_NV_texture_env_combine4                         
      GL_NV_texture_expand_normal                        
      GL_NV_texture_lod_clamp                            
      GL_NV_texture_multisample                          
      GL_NV_texture_npot_2D_mipmap                       
      GL_NV_texture_rectangle                            
      GL_NV_texture_shader                               
      GL_NV_texture_shader2                              
      GL_NV_texture_shader3                              
      GL_NV_timer_query                                  
      GL_NV_transform_feedback                           
      GL_NV_transform_feedback2                          
      GL_NV_vdpau_interop                                
      GL_NV_vertex_array_range                           
      GL_NV_vertex_array_range2                          
      GL_NV_vertex_attrib_64bit                          
      GL_NV_vertex_attrib_integer_64bit                  
      GL_NV_vertex_buffer_unified_memory                 
      GL_NV_vertex_program                               
      GL_NV_vertex_program1_1                            
      GL_NV_vertex_program2                              
      GL_NV_vertex_program2_option                       
      GL_NV_vertex_program3                              
      GL_NV_vertex_program4                              
      GL_NV_video_capture                                
      GL_NVX_conditional_render                          
      GL_NVX_flush_hold                                  
      GL_NVX_gpu_memory_info                             
      GL_NVX_instanced_arrays                            
      GL_NVX_nvenc_interop                               
      GL_NVX_shader_thread_group                         
      GL_NVX_shader_thread_shuffle                       
      GL_NVX_shared_sync_object                          
      GL_NVX_sysmem_buffer                               
      GL_NVX_ycrcb                                       
      GL_OES_blend_equation_separate                     
      GL_OES_blend_func_separate                         
      GL_OES_blend_subtract                              
      GL_OES_byte_coordinates                            
      GL_OES_compressed_EAC_R11_signed_texture           
      GL_OES_compressed_EAC_R11_unsigned_texture         
      GL_OES_compressed_EAC_RG11_signed_texture          
      GL_OES_compressed_EAC_RG11_unsigned_texture        
      GL_OES_compressed_ETC1_RGB8_texture                
      GL_OES_compressed_ETC2_punchthroughA_RGBA8_texture 
      GL_OES_compressed_ETC2_punchthroughA_sRGB8_alpha_texture 
      GL_OES_compressed_ETC2_RGB8_texture                
      GL_OES_compressed_ETC2_RGBA8_texture               
      GL_OES_compressed_ETC2_sRGB8_alpha8_texture        
      GL_OES_compressed_ETC2_sRGB8_texture               
      GL_OES_compressed_paletted_texture                 
      GL_OES_conditional_query                           
      GL_OES_depth_texture                               
      GL_OES_depth_texture_cube_map                      
      GL_OES_depth24                                     
      GL_OES_depth32                                     
      GL_OES_draw_texture                                
      GL_OES_EGL_image                                   
      GL_OES_EGL_image_external                          
      GL_OES_EGL_sync                                    
      GL_OES_element_index_uint                          
      GL_OES_extended_matrix_palette                     
      GL_OES_fbo_render_mipmap                           
      GL_OES_fixed_point                                 
      GL_OES_fragment_precision_high                     
      GL_OES_framebuffer_object                          
      GL_OES_get_program_binary                          
      GL_OES_mapbuffer                                   
      GL_OES_matrix_get                                  
      GL_OES_matrix_palette                              
      GL_OES_packed_depth_stencil                        
      GL_OES_point_size_array                            
      GL_OES_point_sprite                                
      GL_OES_query_matrix                                
      GL_OES_read_format                                 
      GL_OES_required_internalformat                     
      GL_OES_rgb8_rgba8                                  
      GL_OES_sample_shading                              
      GL_OES_sample_variables                            
      GL_OES_shader_image_atomic                         
      GL_OES_shader_multisample_interpolation            
      GL_OES_single_precision                            
      GL_OES_standard_derivatives                        
      GL_OES_stencil_wrap                                
      GL_OES_stencil1                                    
      GL_OES_stencil4                                    
      GL_OES_stencil8                                    
      GL_OES_surfaceless_context                         
      GL_OES_texture_3D                                  
      GL_OES_texture_compression_astc                    
      GL_OES_texture_cube_map                            
      GL_OES_texture_env_crossbar                        
      GL_OES_texture_float                               
      GL_OES_texture_float_linear                        
      GL_OES_texture_half_float                          
      GL_OES_texture_half_float_linear                   
      GL_OES_texture_mirrored_repeat                     
      GL_OES_texture_npot                                
      GL_OES_texture_stencil8                            
      GL_OES_texture_storage_multisample_2d_array        
      GL_OES_vertex_array_object                         
      GL_OES_vertex_half_float                           
      GL_OES_vertex_type_10_10_10_2                      
      GL_OML_interlace                                   
      GL_OML_resample                                    
      GL_OML_subsample                                   
      GL_PGI_misc_hints                                  
      GL_PGI_vertex_hints                                
      GL_QCOM_alpha_test                                 
      GL_QCOM_binning_control                            
      GL_QCOM_driver_control                             
      GL_QCOM_extended_get                               
      GL_QCOM_extended_get2                              
      GL_QCOM_perfmon_global_mode                        
      GL_QCOM_tiled_rendering                            
      GL_QCOM_writeonly_rendering                        
      GL_REND_screen_coordinates                         
      GL_S3_performance_analyzer                         
      GL_S3_s3tc                                         
      GL_SGI_color_matrix                                
      GL_SGI_color_table                                 
      GL_SGI_compiled_vertex_array                       
      GL_SGI_cull_vertex                                 
      GL_SGI_index_array_formats                         
      GL_SGI_index_func                                  
      GL_SGI_index_material                              
      GL_SGI_index_texture                               
      GL_SGI_make_current_read                           
      GL_SGI_texture_add_env                             
      GL_SGI_texture_color_table                         
      GL_SGI_texture_edge_clamp                          
      GL_SGI_texture_lod                                 
      GL_SGIS_color_range                                
      GL_SGIS_detail_texture                             
      GL_SGIS_fog_function                               
      GL_SGIS_generate_mipmap                           
      GL_SGIS_multisample                                
      GL_SGIS_multitexture                               
      GL_SGIS_pixel_texture                              
      GL_SGIS_point_line_texgen                          
      GL_SGIS_sharpen_texture                            
      GL_SGIS_texture_border_clamp                       
      GL_SGIS_texture_color_mask                         
      GL_SGIS_texture_edge_clamp                        
      GL_SGIS_texture_filter4                            
      GL_SGIS_texture_lod                               
      GL_SGIS_texture_select                             
      GL_SGIS_texture4D                                  
      GL_SGIX_async                                      
      GL_SGIX_async_histogram                            
      GL_SGIX_async_pixel                                
      GL_SGIX_blend_alpha_minmax                         
      GL_SGIX_clipmap                                    
      GL_SGIX_convolution_accuracy                       
      GL_SGIX_depth_pass_instrument                      
      GL_SGIX_depth_texture                              
      GL_SGIX_flush_raster                               
      GL_SGIX_fog_offset                                 
      GL_SGIX_fog_texture                                
      GL_SGIX_fragment_specular_lighting                 
      GL_SGIX_framezoom                                  
      GL_SGIX_instruments                                
      GL_SGIX_interlace                                  
      GL_SGIX_ir_instrument1                             
      GL_SGIX_list_priority                              
      GL_SGIX_pbuffer                                    
      GL_SGIX_pixel_texture                              
      GL_SGIX_pixel_texture_bits                         
      GL_SGIX_reference_plane                            
      GL_SGIX_resample                                   
      GL_SGIX_shadow                                     
      GL_SGIX_shadow_ambient                             
      GL_SGIX_sprite                                     
      GL_SGIX_subsample                                  
      GL_SGIX_tag_sample_buffer                          
      GL_SGIX_texture_add_env                            
      GL_SGIX_texture_coordinate_clamp                   
      GL_SGIX_texture_lod_bias                           
      GL_SGIX_texture_multi_buffer                       
      GL_SGIX_texture_range                              
      GL_SGIX_texture_scale_bias                         
      GL_SGIX_vertex_preclip                             
      GL_SGIX_vertex_preclip_hint                        
      GL_SGIX_ycrcb                                      
      GL_SGIX_ycrcb_subsample                            
      GL_SUN_convolution_border_modes                    
      GL_SUN_global_alpha                                
      GL_SUN_mesh_array                                  
      GL_SUN_multi_draw_arrays                          
      GL_SUN_read_video_pixels                           
      GL_SUN_slice_accum                                 
      GL_SUN_triangle_list                               
      GL_SUN_vertex                                      
      GL_SUNX_constant_data                              
      GL_VIV_shader_binary                               
      GL_WGL_ARB_extensions_string                       
      GL_WGL_EXT_extensions_string                       
      GL_WGL_EXT_swap_control                            
      GL_WIN_phong_shading                               
      GL_WIN_specular_fog                                
      GL_WIN_swap_hint                                  
      GLU_EXT_nurbs_tessellator                          
      GLU_EXT_object_space_tess                          
      GLU_SGI_filter4_parameters                         
      GLX_AMD_gpu_association                            
      GLX_ARB_create_context                             
      GLX_ARB_create_context_profile                     
      GLX_ARB_create_context_robustness                  
      GLX_ARB_fbconfig_float                             
      GLX_ARB_framebuffer_sRGB                           
      GLX_ARB_get_proc_address                           
      GLX_ARB_multisample                                
      GLX_ARB_robustness_application_isolation           
      GLX_ARB_robustness_share_group_isolation           
      GLX_ARB_vertex_buffer_object                       
      GLX_EXT_buffer_age                                 
      GLX_EXT_create_context_es_profile                  
      GLX_EXT_create_context_es2_profile                 
      GLX_EXT_fbconfig_packed_float                      
      GLX_EXT_framebuffer_sRGB                           
      GLX_EXT_import_context                             
      GLX_EXT_scene_marker                               
      GLX_EXT_swap_control                               
      GLX_EXT_swap_control_tear                          
      GLX_EXT_texture_from_pixmap                        
      GLX_EXT_visual_info                                
      GLX_EXT_visual_rating                              
      GLX_INTEL_swap_event                               
      GLX_MESA_agp_offset                                
      GLX_MESA_copy_sub_buffer                           
      GLX_MESA_multithread_makecurrent                   
      GLX_MESA_pixmap_colormap                           
      GLX_MESA_query_renderer                            
      GLX_MESA_release_buffers                           
      GLX_MESA_set_3dfx_mode                             
      GLX_MESA_swap_control                              
      GLX_NV_copy_image                                  
      GLX_NV_delay_before_swap                           
      GLX_NV_float_buffer                                
      GLX_NV_multisample_coverage                        
      GLX_NV_present_video                               
      GLX_NV_swap_group                                  
      GLX_NV_video_capture                               
      GLX_NV_video_out                                   
      GLX_NV_video_output                                
      GLX_OML_interlace                                  
      GLX_OML_swap_method                                
      GLX_OML_sync_control                               
      GLX_SGI_cushion                                    
      GLX_SGI_make_current_read                          
      GLX_SGI_swap_control                               
      GLX_SGI_video_sync                                 
      GLX_SGIS_blended_overlay                           
      GLX_SGIS_color_range                               
      GLX_SGIS_multisample                               
      GLX_SGIX_dm_buffer                                 
      GLX_SGIX_fbconfig                                  
      GLX_SGIX_hyperpipe                                 
      GLX_SGIX_pbuffer                                   
      GLX_SGIX_swap_barrier                              
      GLX_SGIX_swap_group                                
      GLX_SGIX_video_resize                              
      GLX_SGIX_video_source                              
      GLX_SGIX_visual_select_group                       
      GLX_SUN_get_transparent_index                      
      GLX_SUN_video_resize                               
      WGL_3DFX_gamma_control                             
      WGL_3DFX_multisample                               
      WGL_3DL_stereo_control                             
      WGL_AMD_gpu_association                           
      WGL_AMDX_gpu_association                          
      WGL_ARB_buffer_region                             
      WGL_ARB_create_context                            
      WGL_ARB_create_context_profile                    
      WGL_ARB_create_context_robustness                  
      WGL_ARB_extensions_string                         
      WGL_ARB_framebuffer_sRGB                           
      WGL_ARB_make_current_read                         
      WGL_ARB_multisample                               
      WGL_ARB_pbuffer                                   
      WGL_ARB_pixel_format                              
      WGL_ARB_pixel_format_float                        
      WGL_ARB_render_texture                            
      WGL_ARB_robustness_application_isolation           
      WGL_ARB_robustness_share_group_isolation           
      WGL_ATI_pbuffer_memory_hint                        
      WGL_ATI_pixel_format_float                        
      WGL_ATI_render_texture_rectangle                  
      WGL_EXT_buffer_region                              
      WGL_EXT_create_context_es_profile                  
      WGL_EXT_create_context_es2_profile                 
      WGL_EXT_depth_float                                
      WGL_EXT_display_color_table                        
      WGL_EXT_extensions_string                         
      WGL_EXT_framebuffer_sRGB                          
      WGL_EXT_framebuffer_sRGBWGL_ARB_create_context     
      WGL_EXT_gamma_control                              
      WGL_EXT_make_current_read                          
      WGL_EXT_multisample                                
      WGL_EXT_pbuffer                                    
      WGL_EXT_pixel_format                               
      WGL_EXT_pixel_format_packed_float                 
      WGL_EXT_render_texture                             
      WGL_EXT_swap_control                              
      WGL_EXT_swap_control_tear                         
      WGL_EXT_swap_interval                              
      WGL_I3D_digital_video_control                      
      WGL_I3D_gamma                                      
      WGL_I3D_genlock                                   
      WGL_I3D_image_buffer                               
      WGL_I3D_swap_frame_lock                            
      WGL_I3D_swap_frame_usage                           
      WGL_MTX_video_preview                              
      WGL_NV_copy_image                                  
      WGL_NV_delay_before_swap                           
      WGL_NV_DX_interop                                 
      WGL_NV_DX_interop2                                
      WGL_NV_float_buffer                               
      WGL_NV_gpu_affinity                                
      WGL_NV_multisample_coverage                        
      WGL_NV_present_video                               
      WGL_NV_render_depth_texture                        
      WGL_NV_render_texture_rectangle                    
      WGL_NV_swap_group                                 
      WGL_NV_texture_rectangle                           
      WGL_NV_vertex_array_range                          
      WGL_NV_video_capture                               
      WGL_NV_video_output                                
      WGL_NVX_DX_interop                                 
      WGL_OML_sync_control                               
      WGL_S3_cl_sharingWGL_ARB_create_context_profile    

       :
      RGB DXT1                                          
      RGBA DXT1                                         
      RGBA DXT3                                         
      RGBA DXT5                                         
      RGB FXT1                                           
      RGBA FXT1                                          
      3Dc                                               

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates


--------[ GPGPU ]-------------------------------------------------------------------------------------------------------

  [ Stream: Sumo ]

     :
                                           Sumo
                                               400 
      SIMDs                                             4
      UAVs                                              12
      Shader Engines                                    1
      Max Resource 1D Width                             16384
      Max Resource 2D Width / Height                    16384 / 16384
      Wavefront Size                                    64
      Pitch Alignment                                   256 elements
      Surface Alignment                                 4096 
       CAL                                        1.4.1848
      CAL DLL                                           aticalrt.dll (6.14.10.1848)

     :
                                           667 
      Total / Free Local Memory                         512  / 479 
      Total / Free Uncached Remote Memory               1587  / 1570 
      Total / Free Cached Remote Memory                 1587  / 1570 

     :
      Compute Shader                                    
      3D ProgramGrid                                    
      Double-Precision Floating-Point                    
      Global Data Share                                 
      Global GPR                                        
      Local Data Share                                  
      Memory Export                                     

     CAL:
      CAL/D3D9 Interaction                              
      CAL/D3D10 Interaction                             
      CAL/OpenGL Interaction                             
      CAL Counters                                      
      Compute Shader                                    
      Create Resource                                   
      Domain Parameters                                 
      Sampler                                           

  [ Stream: Caicos ]

     :
                                           Caicos
                                               400 
      SIMDs                                             2
      UAVs                                              12
      Shader Engines                                    1
      Max Resource 1D Width                             16384
      Max Resource 2D Width / Height                    16384 / 16384
      Wavefront Size                                    64
      Pitch Alignment                                   256 elements
      Surface Alignment                                 4096 
       CAL                                        1.4.1848
      CAL DLL                                           aticalrt.dll (6.14.10.1848)

     :
                                           667 
      Total / Free Local Memory                         1024  / 991 
      Total / Free Uncached Remote Memory               1587  / 1570 
      Total / Free Cached Remote Memory                 1587  / 1570 

     :
      Compute Shader                                    
      3D ProgramGrid                                    
      Double-Precision Floating-Point                    
      Global Data Share                                 
      Global GPR                                        
      Local Data Share                                  
      Memory Export                                     

     CAL:
      CAL/D3D9 Interaction                              
      CAL/D3D10 Interaction                             
      CAL/OpenGL Interaction                             
      CAL Counters                                      
      Compute Shader                                    
      Create Resource                                   
      Domain Parameters                                 
      Sampler                                           

  [ Direct3D: AMD Radeon HD 6520G ]

     :
                                           AMD Radeon HD 6520G
      PCI-                                    1002-9647 / 1179-FC51  (Rev 00)
                                        1511 
                                             aticfx32.dll
                                          8.17.10.1247
      Shader Model                                      SM 5.0
      Max Threads                                       1024
      Multiple UAV Access                               8 UAVs
      Thread Dispatch                                   3D
      Thread Local Storage                              32 

     :
      10-bit Precision Floating-Point                    
      16-bit Precision Floating-Point                    
      Append/Consume Buffers                            
      Atomic Operations                                 
      Double-Precision Floating-Point                    
      Gather4                                           
      Indirect Compute Dispatch                         
      Map On Default Buffers                             

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates

  [ OpenCL: AMD Radeon HD 6520G (BeaverCreek) ]

     OpenCL:
                                               AMD Accelerated Parallel Processing
                                      Advanced Micro Devices, Inc.
                                         OpenCL 1.2 AMD-APP (1348.5)
                                        Full

     :
                                           BeaverCreek
                                            AMD Radeon HD 6520G
                                            
                                     Advanced Micro Devices, Inc.
                                        OpenCL 1.2 AMD-APP (1348.5)
                                       Full
                                          1348.5 (VM)
       OpenCL C                                   OpenCL C 1.2 
                                                 400 
       /                       4 / 320
      SIMD                         1
       SIMD                                       16
        SIMD                            5
      Wavefront Width                                   64
      Address Space Size                                32 
      Max 2D Image Size                                 16384 x 16384
      Max 3D Image Size                                 2048 x 2048 x 2048
      Max Image Array Size                              2048
      Max Image Buffer Size                             65536
      Max Samplers                                      16
      Max Work-Item Size                                256 x 256 x 256
      Max Work-Group Size                               256
      Max Argument Size                                 1 
      Max Constant Buffer Size                          64 
      Max Constant Arguments                            8
      Max Printf Buffer Size                            1 
      Native ISA Vector Widths                          char16, short8, int2, float4
      Preferred Native Vector Widths                    char16, short8, int4, long2, float4
      Profiling Timer Resolution                        1 ns
      Profiling Timer Offset Since Epoch                1408301927782381026 ns
      OpenCL DLL                                        opencl.dll (1.2.11.0)

     :
      Global Memory                                     762 
      Free Global Memory                                490868  / 260852 
      Global Memory Channels                            4
      Global Memory Channel Banks                       4
      Global Memory Channel Bank Width                  256 
      Local Memory                                      32 
      Local Memory Size Per Compute Unit                32 
      Local Memory Banks                                16
      Max Memory Object Allocation Size                 195072 
      Memory Base Address Alignment                     2048 
      Min Data Type Alignment                           128 
      Image Row Pitch Alignment                         256 pixels
      Image Base Address Alignment                      256 pixels

     OpenCL:
      OpenCL 1.1                                          (100%)
      OpenCL 1.2                                          (100%)
      OpenCL 2.0                                          (75%)

     :
      Command-Queue Out Of Order Execution              
      Command-Queue Profiling                           
      Compiler Available                                
                                          
      Images                                            
      Kernel Execution                                  
      Linker Available                                  
      Little-Endian Device                              
      Native Kernel Execution                            
      SVM Atomics                                        
      SVM Coarse Grain Buffer                            
      SVM Fine Grain Buffer                              
      SVM Fine Grain System                              
      Thread Trace                                       
      Unified Memory                                    

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                            
      IEEE754-2008 FMA                                   
      INF and NaNs                                       
      Rounding to Infinity                               
      Rounding to Nearest Even                           
      Rounding to Zero                                   
      Software Basic Floating-Point Operations          

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                            
      IEEE754-2008 FMA                                  
      INF and NaNs                                      
      Rounding to Infinity                              
      Rounding to Nearest Even                          
      Rounding to Zero                                  
      Software Basic Floating-Point Operations          

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                            
      IEEE754-2008 FMA                                   
      INF and NaNs                                       
      Rounding to Infinity                               
      Rounding to Nearest Even                           
      Rounding to Zero                                   
      Software Basic Floating-Point Operations          

     :
       /                   84 / 17
      cl_altera_compiler_mode                            
      cl_altera_device_temperature                       
      cl_altera_live_object_tracking                     
      cl_amd_bus_addressable_memory                      
      cl_amd_c1x_atomics                                 
      cl_amd_compile_options                             
      cl_amd_core_id                                     
      cl_amd_d3d10_interop                               
      cl_amd_d3d9_interop                                
      cl_amd_device_attribute_query                     
      cl_amd_device_board_name                           
      cl_amd_device_memory_flags                         
      cl_amd_device_persistent_memory                    
      cl_amd_device_profiling_timer_offset               
      cl_amd_device_topology                             
      cl_amd_event_callback                              
      cl_amd_fp64                                        
      cl_amd_hsa                                         
      cl_amd_image2d_from_buffer_read_only              
      cl_amd_media_ops                                  
      cl_amd_media_ops2                                 
      cl_amd_offline_devices                             
      cl_amd_popcnt                                     
      cl_amd_predefined_macros                           
      cl_amd_printf                                     
      cl_amd_svm                                         
      cl_amd_vec3                                       
      cl_apple_contextloggingfunctions                   
      cl_apple_gl_sharing                                
      cl_apple_setmemobjectdestructor                    
      cl_arm_core_id                                     
      cl_arm_printf                                      
      cl_ext_atomic_counters_32                         
      cl_ext_atomic_counters_64                          
      cl_ext_device_fission                              
      cl_ext_migrate_memobject                           
      cl_intel_accelerator                               
      cl_intel_ctz                                       
      cl_intel_d3d11_nv12_media_sharing                  
      cl_intel_device_partition_by_names                 
      cl_intel_dx9_media_sharing                         
      cl_intel_exec_by_local_thread                      
      cl_intel_motion_estimation                         
      cl_intel_printf                                    
      cl_intel_thread_local_exec                         
      cl_khr_3d_image_writes                            
      cl_khr_byte_addressable_store                     
      cl_khr_context_abort                               
      cl_khr_d3d10_sharing                              
      cl_khr_d3d11_sharing                               
      cl_khr_depth_images                                
      cl_khr_dx9_media_sharing                          
      cl_khr_egl_event                                   
      cl_khr_egl_image                                   
      cl_khr_fp16                                        
      cl_khr_fp64                                        
      cl_khr_gl_depth_images                             
      cl_khr_gl_event                                    
      cl_khr_gl_msaa_sharing                             
      cl_khr_gl_sharing                                 
      cl_khr_global_int32_base_atomics                  
      cl_khr_global_int32_extended_atomics              
      cl_khr_icd                                         
      cl_khr_image2d_from_buffer                         
      cl_khr_initialize_memory                           
      cl_khr_int64_base_atomics                          
      cl_khr_int64_extended_atomics                      
      cl_khr_local_int32_base_atomics                   
      cl_khr_local_int32_extended_atomics               
      cl_khr_mipmap_image                                
      cl_khr_mipmap_image_writes                         
      cl_khr_select_fprounding_mode                      
      cl_khr_spir                                        
      cl_khr_srgb_image_writes                           
      cl_khr_subgroups                                   
      cl_khr_terminate_context                           
      cl_nv_compiler_options                             
      cl_nv_d3d10_sharing                                
      cl_nv_d3d11_sharing                                
      cl_nv_d3d9_sharing                                 
      cl_nv_device_attribute_query                       
      cl_nv_pragma_unroll                                
      cl_qcom_ext_host_ptr                               
      cl_qcom_ion_host_ptr                               

  [ OpenCL: AMD Radeon HD 7400M Series (Caicos) ]

     OpenCL:
                                               AMD Accelerated Parallel Processing
                                      Advanced Micro Devices, Inc.
                                         OpenCL 1.2 AMD-APP (1348.5)
                                        Full

     :
                                           Caicos
                                            AMD Radeon HD 7400M Series
                                            
                                     Advanced Micro Devices, Inc.
                                        OpenCL 1.2 AMD-APP (1348.5)
                                       Full
                                          1348.5 (VM)
       OpenCL C                                   OpenCL C 1.2 
                                                 400 
       /                       2 / 160
      SIMD                         1
       SIMD                                       16
        SIMD                            5
      Wavefront Width                                   64
      Address Space Size                                32 
      Max 2D Image Size                                 16384 x 16384
      Max 3D Image Size                                 2048 x 2048 x 2048
      Max Image Array Size                              2048
      Max Image Buffer Size                             65536
      Max Samplers                                      16
      Max Work-Item Size                                256 x 256 x 256
      Max Work-Group Size                               256
      Max Argument Size                                 1 
      Max Constant Buffer Size                          64 
      Max Constant Arguments                            8
      Max Printf Buffer Size                            1 
      Native ISA Vector Widths                          char16, short8, int2, float4
      Preferred Native Vector Widths                    char16, short8, int4, long2, float4
      Profiling Timer Resolution                        1 ns
      Profiling Timer Offset Since Epoch                1408301927782381026 ns
      OpenCL DLL                                        opencl.dll (1.2.11.0)

     :
      Global Memory                                     1 
      Free Global Memory                                1015156  / 785140 
      Global Memory Channels                            2
      Global Memory Channel Banks                       8
      Global Memory Channel Bank Width                  256 
      Local Memory                                      32 
      Local Memory Size Per Compute Unit                32 
      Local Memory Banks                                32
      Max Memory Object Allocation Size                 512 
      Memory Base Address Alignment                     2048 
      Min Data Type Alignment                           128 
      Image Row Pitch Alignment                         256 pixels
      Image Base Address Alignment                      256 pixels

     OpenCL:
      OpenCL 1.1                                          (100%)
      OpenCL 1.2                                          (100%)
      OpenCL 2.0                                          (75%)

     :
      Command-Queue Out Of Order Execution              
      Command-Queue Profiling                           
      Compiler Available                                
                                          
      Images                                            
      Kernel Execution                                  
      Linker Available                                  
      Little-Endian Device                              
      Native Kernel Execution                            
      SVM Atomics                                        
      SVM Coarse Grain Buffer                            
      SVM Fine Grain Buffer                              
      SVM Fine Grain System                              
      Thread Trace                                       
      Unified Memory                                    

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                            
      IEEE754-2008 FMA                                   
      INF and NaNs                                       
      Rounding to Infinity                               
      Rounding to Nearest Even                           
      Rounding to Zero                                   
      Software Basic Floating-Point Operations          

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                            
      IEEE754-2008 FMA                                  
      INF and NaNs                                      
      Rounding to Infinity                              
      Rounding to Nearest Even                          
      Rounding to Zero                                  
      Software Basic Floating-Point Operations          

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                            
      IEEE754-2008 FMA                                   
      INF and NaNs                                       
      Rounding to Infinity                               
      Rounding to Nearest Even                           
      Rounding to Zero                                   
      Software Basic Floating-Point Operations          

     :
       /                   84 / 17
      cl_altera_compiler_mode                            
      cl_altera_device_temperature                       
      cl_altera_live_object_tracking                     
      cl_amd_bus_addressable_memory                      
      cl_amd_c1x_atomics                                 
      cl_amd_compile_options                             
      cl_amd_core_id                                     
      cl_amd_d3d10_interop                               
      cl_amd_d3d9_interop                                
      cl_amd_device_attribute_query                     
      cl_amd_device_board_name                           
      cl_amd_device_memory_flags                         
      cl_amd_device_persistent_memory                    
      cl_amd_device_profiling_timer_offset               
      cl_amd_device_topology                             
      cl_amd_event_callback                              
      cl_amd_fp64                                        
      cl_amd_hsa                                         
      cl_amd_image2d_from_buffer_read_only              
      cl_amd_media_ops                                  
      cl_amd_media_ops2                                 
      cl_amd_offline_devices                             
      cl_amd_popcnt                                     
      cl_amd_predefined_macros                           
      cl_amd_printf                                     
      cl_amd_svm                                         
      cl_amd_vec3                                       
      cl_apple_contextloggingfunctions                   
      cl_apple_gl_sharing                                
      cl_apple_setmemobjectdestructor                    
      cl_arm_core_id                                     
      cl_arm_printf                                      
      cl_ext_atomic_counters_32                         
      cl_ext_atomic_counters_64                          
      cl_ext_device_fission                              
      cl_ext_migrate_memobject                           
      cl_intel_accelerator                               
      cl_intel_ctz                                       
      cl_intel_d3d11_nv12_media_sharing                  
      cl_intel_device_partition_by_names                 
      cl_intel_dx9_media_sharing                         
      cl_intel_exec_by_local_thread                      
      cl_intel_motion_estimation                         
      cl_intel_printf                                    
      cl_intel_thread_local_exec                         
      cl_khr_3d_image_writes                            
      cl_khr_byte_addressable_store                     
      cl_khr_context_abort                               
      cl_khr_d3d10_sharing                              
      cl_khr_d3d11_sharing                               
      cl_khr_depth_images                                
      cl_khr_dx9_media_sharing                          
      cl_khr_egl_event                                   
      cl_khr_egl_image                                   
      cl_khr_fp16                                        
      cl_khr_fp64                                        
      cl_khr_gl_depth_images                             
      cl_khr_gl_event                                    
      cl_khr_gl_msaa_sharing                             
      cl_khr_gl_sharing                                 
      cl_khr_global_int32_base_atomics                  
      cl_khr_global_int32_extended_atomics              
      cl_khr_icd                                         
      cl_khr_image2d_from_buffer                         
      cl_khr_initialize_memory                           
      cl_khr_int64_base_atomics                          
      cl_khr_int64_extended_atomics                      
      cl_khr_local_int32_base_atomics                   
      cl_khr_local_int32_extended_atomics               
      cl_khr_mipmap_image                                
      cl_khr_mipmap_image_writes                         
      cl_khr_select_fprounding_mode                      
      cl_khr_spir                                        
      cl_khr_srgb_image_writes                           
      cl_khr_subgroups                                   
      cl_khr_terminate_context                           
      cl_nv_compiler_options                             
      cl_nv_d3d10_sharing                                
      cl_nv_d3d11_sharing                                
      cl_nv_d3d9_sharing                                 
      cl_nv_device_attribute_query                       
      cl_nv_pragma_unroll                                
      cl_qcom_ext_host_ptr                               
      cl_qcom_ion_host_ptr                               

  [ OpenCL: AMD A6-3400M APU with Radeon(tm) HD Graphics ]

     OpenCL:
                                               AMD Accelerated Parallel Processing
                                      Advanced Micro Devices, Inc.
                                         OpenCL 1.2 AMD-APP (1348.5)
                                        Full

     :
                                           AMD A6-3400M APU with Radeon(tm) HD Graphics
                                           
                                     AuthenticAMD
                                        OpenCL 1.2 AMD-APP (1348.5)
                                       Full
                                          1348.5 (sse2)
       OpenCL C                                   OpenCL C 1.2 
                                                 1397 
                                   4
      Address Space Size                                32 
      Max 2D Image Size                                 8192 x 8192
      Max 3D Image Size                                 2048 x 2048 x 2048
      Max Image Array Size                              2048
      Max Image Buffer Size                             65536
      Max Samplers                                      16
      Max Work-Item Size                                1024 x 1024 x 1024
      Max Work-Group Size                               1024
      Max Argument Size                                 4 
      Max Constant Buffer Size                          64 
      Max Constant Arguments                            8
      Max Printf Buffer Size                            64 
      Native ISA Vector Widths                          char16, short8, int2, half2, float4, double2
      Preferred Native Vector Widths                    char16, short8, int4, long2, half2, float4, double2
      Profiling Timer Resolution                        69 ns
      Profiling Timer Offset Since Epoch                1408301927782381026 ns
      OpenCL DLL                                        opencl.dll (1.2.11.0)

     :
      Global Memory                                     2 
      Global Memory Cache                               64   (Read/Write, 64-byte line)
      Local Memory                                      32 
      Max Memory Object Allocation Size                 1 
      Memory Base Address Alignment                     1024 
      Min Data Type Alignment                           128 

     OpenCL:
      OpenCL 1.1                                          (100%)
      OpenCL 1.2                                          (100%)
      OpenCL 2.0                                          (75%)

     :
      Command-Queue Out Of Order Execution              
      Command-Queue Profiling                           
      Compiler Available                                
                                          
      Images                                            
      Kernel Execution                                  
      Linker Available                                  
      Little-Endian Device                              
      Native Kernel Execution                           
      SVM Atomics                                        
      SVM Coarse Grain Buffer                            
      SVM Fine Grain Buffer                              
      SVM Fine Grain System                              
      Thread Trace                                       
      Unified Memory                                    

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                            
      IEEE754-2008 FMA                                   
      INF and NaNs                                       
      Rounding to Infinity                               
      Rounding to Nearest Even                           
      Rounding to Zero                                   
      Software Basic Floating-Point Operations          

         :
      Correctly Rounded Divide and Sqrt                 
      Denorms                                           
      IEEE754-2008 FMA                                  
      INF and NaNs                                      
      Rounding to Infinity                              
      Rounding to Nearest Even                          
      Rounding to Zero                                  
      Software Basic Floating-Point Operations          

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                           
      IEEE754-2008 FMA                                  
      INF and NaNs                                      
      Rounding to Infinity                              
      Rounding to Nearest Even                          
      Rounding to Zero                                  
      Software Basic Floating-Point Operations          

     :
       /                   84 / 17
      cl_altera_compiler_mode                            
      cl_altera_device_temperature                       
      cl_altera_live_object_tracking                     
      cl_amd_bus_addressable_memory                      
      cl_amd_c1x_atomics                                 
      cl_amd_compile_options                             
      cl_amd_core_id                                     
      cl_amd_d3d10_interop                               
      cl_amd_d3d9_interop                                
      cl_amd_device_attribute_query                     
      cl_amd_device_board_name                           
      cl_amd_device_memory_flags                         
      cl_amd_device_persistent_memory                    
      cl_amd_device_profiling_timer_offset               
      cl_amd_device_topology                             
      cl_amd_event_callback                              
      cl_amd_fp64                                       
      cl_amd_hsa                                         
      cl_amd_image2d_from_buffer_read_only               
      cl_amd_media_ops                                  
      cl_amd_media_ops2                                 
      cl_amd_offline_devices                             
      cl_amd_popcnt                                     
      cl_amd_predefined_macros                           
      cl_amd_printf                                     
      cl_amd_svm                                         
      cl_amd_vec3                                       
      cl_apple_contextloggingfunctions                   
      cl_apple_gl_sharing                                
      cl_apple_setmemobjectdestructor                    
      cl_arm_core_id                                     
      cl_arm_printf                                      
      cl_ext_atomic_counters_32                          
      cl_ext_atomic_counters_64                          
      cl_ext_device_fission                             
      cl_ext_migrate_memobject                           
      cl_intel_accelerator                               
      cl_intel_ctz                                       
      cl_intel_d3d11_nv12_media_sharing                  
      cl_intel_device_partition_by_names                 
      cl_intel_dx9_media_sharing                         
      cl_intel_exec_by_local_thread                      
      cl_intel_motion_estimation                         
      cl_intel_printf                                    
      cl_intel_thread_local_exec                         
      cl_khr_3d_image_writes                            
      cl_khr_byte_addressable_store                     
      cl_khr_context_abort                               
      cl_khr_d3d10_sharing                              
      cl_khr_d3d11_sharing                               
      cl_khr_depth_images                                
      cl_khr_dx9_media_sharing                           
      cl_khr_egl_event                                   
      cl_khr_egl_image                                   
      cl_khr_fp16                                        
      cl_khr_fp64                                       
      cl_khr_gl_depth_images                             
      cl_khr_gl_event                                    
      cl_khr_gl_msaa_sharing                             
      cl_khr_gl_sharing                                 
      cl_khr_global_int32_base_atomics                  
      cl_khr_global_int32_extended_atomics              
      cl_khr_icd                                         
      cl_khr_image2d_from_buffer                         
      cl_khr_initialize_memory                           
      cl_khr_int64_base_atomics                          
      cl_khr_int64_extended_atomics                      
      cl_khr_local_int32_base_atomics                   
      cl_khr_local_int32_extended_atomics               
      cl_khr_mipmap_image                                
      cl_khr_mipmap_image_writes                         
      cl_khr_select_fprounding_mode                      
      cl_khr_spir                                        
      cl_khr_srgb_image_writes                           
      cl_khr_subgroups                                   
      cl_khr_terminate_context                           
      cl_nv_compiler_options                             
      cl_nv_d3d10_sharing                                
      cl_nv_d3d11_sharing                                
      cl_nv_d3d9_sharing                                 
      cl_nv_device_attribute_query                       
      cl_nv_pragma_unroll                                
      cl_qcom_ext_host_ptr                               
      cl_qcom_ion_host_ptr                               

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates


--------[  ]------------------------------------------------------------------------------------------------------

    @Arial Unicode MS                         Swiss                               14 x 43   40 %
    @Arial Unicode MS                         Swiss                             14 x 43   40 %
    @Arial Unicode MS                         Swiss                            14 x 43   40 %
    @Arial Unicode MS                         Swiss                              14 x 43   40 %
    @Arial Unicode MS                         Swiss                               14 x 43   40 %
    @Arial Unicode MS                         Swiss                                  14 x 43   40 %
    @Arial Unicode MS                         Swiss                          14 x 43   40 %
    @Arial Unicode MS                         Swiss                (2312)        14 x 43   40 %
    @Arial Unicode MS                         Swiss                (BIG5)        14 x 43   40 %
    @Arial Unicode MS                         Swiss                                14 x 43   40 %
    @Arial Unicode MS                         Swiss                               14 x 43   40 %
    @Arial Unicode MS                         Swiss                (Johab)         14 x 43   40 %
    @Arial Unicode MS                         Swiss                                14 x 43   40 %
    @Arial Unicode MS                         Swiss                  14 x 43   40 %
    @Arial Unicode MS                         Swiss                               14 x 43   40 %
    @Batang                                   Roman       Regular                      16 x 32   40 %
    @Batang                                   Roman       Regular                       16 x 32   40 %
    @Batang                                   Roman       Regular                        16 x 32   40 %
    @Batang                                   Roman       Regular                   16 x 32   40 %
    @Batang                                   Roman       Regular                        16 x 32   40 %
    @Batang                                   Roman       Regular                         16 x 32   40 %
    @Batang                                   Roman       Regular           16 x 32   40 %
    @BatangChe                                Modern      Regular                      16 x 32   40 %
    @BatangChe                                Modern      Regular                       16 x 32   40 %
    @BatangChe                                Modern      Regular                        16 x 32   40 %
    @BatangChe                                Modern      Regular                   16 x 32   40 %
    @BatangChe                                Modern      Regular                        16 x 32   40 %
    @BatangChe                                Modern      Regular                         16 x 32   40 %
    @BatangChe                                Modern      Regular           16 x 32   40 %
    @DFKai-SB                                 Script      Regular                        16 x 32   40 %
    @DFKai-SB                                 Script      Regular         (BIG5)        16 x 32   40 %
    @Dotum                                    Swiss       Regular                      16 x 32   40 %
    @Dotum                                    Swiss       Regular                       16 x 32   40 %
    @Dotum                                    Swiss       Regular                        16 x 32   40 %
    @Dotum                                    Swiss       Regular                   16 x 32   40 %
    @Dotum                                    Swiss       Regular                        16 x 32   40 %
    @Dotum                                    Swiss       Regular                         16 x 32   40 %
    @Dotum                                    Swiss       Regular           16 x 32   40 %
    @DotumChe                                 Modern      Regular                      16 x 32   40 %
    @DotumChe                                 Modern      Regular                       16 x 32   40 %
    @DotumChe                                 Modern      Regular                        16 x 32   40 %
    @DotumChe                                 Modern      Regular                   16 x 32   40 %
    @DotumChe                                 Modern      Regular                        16 x 32   40 %
    @DotumChe                                 Modern      Regular                         16 x 32   40 %
    @DotumChe                                 Modern      Regular           16 x 32   40 %
    @FangSong                                 Modern                              16 x 32   40 %
    @FangSong                                 Modern               (2312)        16 x 32   40 %
    @Gulim                                    Swiss       Regular                      16 x 32   40 %
    @Gulim                                    Swiss       Regular                       16 x 32   40 %
    @Gulim                                    Swiss       Regular                        16 x 32   40 %
    @Gulim                                    Swiss       Regular                   16 x 32   40 %
    @Gulim                                    Swiss       Regular                        16 x 32   40 %
    @Gulim                                    Swiss       Regular                         16 x 32   40 %
    @Gulim                                    Swiss       Regular           16 x 32   40 %
    @GulimChe                                 Modern      Regular                      16 x 32   40 %
    @GulimChe                                 Modern      Regular                       16 x 32   40 %
    @GulimChe                                 Modern      Regular                        16 x 32   40 %
    @GulimChe                                 Modern      Regular                   16 x 32   40 %
    @GulimChe                                 Modern      Regular                        16 x 32   40 %
    @GulimChe                                 Modern      Regular                         16 x 32   40 %
    @GulimChe                                 Modern      Regular           16 x 32   40 %
    @Gungsuh                                  Roman       Regular                      16 x 32   40 %
    @Gungsuh                                  Roman       Regular                       16 x 32   40 %
    @Gungsuh                                  Roman       Regular                        16 x 32   40 %
    @Gungsuh                                  Roman       Regular                   16 x 32   40 %
    @Gungsuh                                  Roman       Regular                        16 x 32   40 %
    @Gungsuh                                  Roman       Regular                         16 x 32   40 %
    @Gungsuh                                  Roman       Regular           16 x 32   40 %
    @GungsuhChe                               Modern      Regular                      16 x 32   40 %
    @GungsuhChe                               Modern      Regular                       16 x 32   40 %
    @GungsuhChe                               Modern      Regular                        16 x 32   40 %
    @GungsuhChe                               Modern      Regular                   16 x 32   40 %
    @GungsuhChe                               Modern      Regular                        16 x 32   40 %
    @GungsuhChe                               Modern      Regular                         16 x 32   40 %
    @GungsuhChe                               Modern      Regular           16 x 32   40 %
    @KaiTi                                    Modern                              16 x 32   40 %
    @KaiTi                                    Modern               (2312)        16 x 32   40 %
    @Malgun Gothic                            Swiss       Regular                        15 x 43   40 %
    @Malgun Gothic                            Swiss       Regular                         15 x 43   40 %
    @Meiryo UI                                Swiss                             17 x 41   40 %
    @Meiryo UI                                Swiss                              17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo UI                                Swiss                          17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo UI                                Swiss                  17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo                                   Swiss                             31 x 48   40 %
    @Meiryo                                   Swiss                              31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Meiryo                                   Swiss                          31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Meiryo                                   Swiss                  31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Microsoft JhengHei Light                 Swiss       Regular                      32 x 43   29 %
    @Microsoft JhengHei Light                 Swiss       Regular                     32 x 43   29 %
    @Microsoft JhengHei Light                 Swiss       Regular                       32 x 43   29 %
    @Microsoft JhengHei Light                 Swiss       Regular                        32 x 43   29 %
    @Microsoft JhengHei Light                 Swiss       Regular                           32 x 43   29 %
    @Microsoft JhengHei Light                 Swiss       Regular                   32 x 43   29 %
    @Microsoft JhengHei Light                 Swiss       Regular         (2312)        32 x 43   29 %
    @Microsoft JhengHei Light                 Swiss       Regular         (BIG5)        32 x 43   29 %
    @Microsoft JhengHei Light                 Swiss       Regular                        32 x 43   29 %
    @Microsoft JhengHei Light                 Swiss       Regular         (Johab)         32 x 43   29 %
    @Microsoft JhengHei Light                 Swiss       Regular                         32 x 43   29 %
    @Microsoft JhengHei Light                 Swiss       Regular           32 x 43   29 %
    @Microsoft JhengHei Light                 Swiss       Regular                        32 x 43   29 %
    @Microsoft JhengHei UI Light              Swiss       Regular                      32 x 41   29 %
    @Microsoft JhengHei UI Light              Swiss       Regular                     32 x 41   29 %
    @Microsoft JhengHei UI Light              Swiss       Regular                       32 x 41   29 %
    @Microsoft JhengHei UI Light              Swiss       Regular                        32 x 41   29 %
    @Microsoft JhengHei UI Light              Swiss       Regular                           32 x 41   29 %
    @Microsoft JhengHei UI Light              Swiss       Regular                   32 x 41   29 %
    @Microsoft JhengHei UI Light              Swiss       Regular         (2312)        32 x 41   29 %
    @Microsoft JhengHei UI Light              Swiss       Regular         (BIG5)        32 x 41   29 %
    @Microsoft JhengHei UI Light              Swiss       Regular                        32 x 41   29 %
    @Microsoft JhengHei UI Light              Swiss       Regular         (Johab)         32 x 41   29 %
    @Microsoft JhengHei UI Light              Swiss       Regular                         32 x 41   29 %
    @Microsoft JhengHei UI Light              Swiss       Regular           32 x 41   29 %
    @Microsoft JhengHei UI Light              Swiss       Regular                        32 x 41   29 %
    @Microsoft JhengHei UI                    Swiss                              15 x 41   40 %
    @Microsoft JhengHei UI                    Swiss                               15 x 41   40 %
    @Microsoft JhengHei UI                    Swiss                (BIG5)        15 x 41   40 %
    @Microsoft JhengHei                       Swiss                              15 x 43   40 %
    @Microsoft JhengHei                       Swiss                               15 x 43   40 %
    @Microsoft JhengHei                       Swiss                (BIG5)        15 x 43   40 %
    @Microsoft YaHei Light                    Swiss       Regular                       15 x 41   29 %
    @Microsoft YaHei Light                    Swiss       Regular                        15 x 41   29 %
    @Microsoft YaHei Light                    Swiss       Regular                   15 x 41   29 %
    @Microsoft YaHei Light                    Swiss       Regular         (2312)        15 x 41   29 %
    @Microsoft YaHei Light                    Swiss       Regular           15 x 41   29 %
    @Microsoft YaHei UI Light                 Swiss       Regular                       15 x 42   29 %
    @Microsoft YaHei UI Light                 Swiss       Regular                        15 x 42   29 %
    @Microsoft YaHei UI Light                 Swiss       Regular                   15 x 42   29 %
    @Microsoft YaHei UI Light                 Swiss       Regular         (2312)        15 x 42   29 %
    @Microsoft YaHei UI Light                 Swiss       Regular           15 x 42   29 %
    @Microsoft YaHei UI                       Swiss                              15 x 41   40 %
    @Microsoft YaHei UI                       Swiss                               15 x 41   40 %
    @Microsoft YaHei UI                       Swiss                          15 x 41   40 %
    @Microsoft YaHei UI                       Swiss                (2312)        15 x 41   40 %
    @Microsoft YaHei UI                       Swiss                               15 x 41   40 %
    @Microsoft YaHei UI                       Swiss                  15 x 41   40 %
    @Microsoft YaHei                          Swiss                              15 x 42   40 %
    @Microsoft YaHei                          Swiss                               15 x 42   40 %
    @Microsoft YaHei                          Swiss                          15 x 42   40 %
    @Microsoft YaHei                          Swiss                (2312)        15 x 42   40 %
    @Microsoft YaHei                          Swiss                               15 x 42   40 %
    @Microsoft YaHei                          Swiss                  15 x 42   40 %
    @MingLiU_HKSCS                            Roman       Regular                        16 x 32   40 %
    @MingLiU_HKSCS                            Roman       Regular         (BIG5)        16 x 32   40 %
    @MingLiU_HKSCS-ExtB                       Roman       Regular                        16 x 32   40 %
    @MingLiU_HKSCS-ExtB                       Roman       Regular         (BIG5)        16 x 32   40 %
    @MingLiU                                  Modern      Regular                        16 x 32   40 %
    @MingLiU                                  Modern      Regular         (BIG5)        16 x 32   40 %
    @MingLiU-ExtB                             Roman       Regular                        16 x 32   40 %
    @MingLiU-ExtB                             Roman       Regular         (BIG5)        16 x 32   40 %
    @MS Gothic                                Modern      Regular                      16 x 32   40 %
    @MS Gothic                                Modern      Regular                       16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Gothic                                Modern      Regular                   16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Gothic                                Modern      Regular           16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular                      16 x 32   40 %
    @MS Mincho                                Modern      Regular                       16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular                   16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular           16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS PGothic                               Swiss       Regular                      13 x 32   40 %
    @MS PGothic                               Swiss       Regular                       13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PGothic                               Swiss       Regular                   13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PGothic                               Swiss       Regular           13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular                      13 x 32   40 %
    @MS PMincho                               Roman       Regular                       13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular                   13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular           13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                      13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                       13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                   13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular           13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @NSimSun                                  Modern      Regular                        16 x 32   40 %
    @NSimSun                                  Modern      Regular         (2312)        16 x 32   40 %
    @PMingLiU                                 Roman       Regular                        16 x 32   40 %
    @PMingLiU                                 Roman       Regular         (BIG5)        16 x 32   40 %
    @PMingLiU-ExtB                            Roman       Regular                        16 x 32   40 %
    @PMingLiU-ExtB                            Roman       Regular         (BIG5)        16 x 32   40 %
    @SimHei                                   Modern                              16 x 32   40 %
    @SimHei                                   Modern               (2312)        16 x 32   40 %
    @SimSun                                   Special     Regular                        16 x 32   40 %
    @SimSun                                   Special     Regular         (2312)        16 x 32   40 %
    @SimSun-ExtB                              Modern                              16 x 32   40 %
    @SimSun-ExtB                              Modern               (2312)        16 x 32   40 %
    @Yu Gothic Light                          Swiss       Regular                      31 x 41   30 %
    @Yu Gothic Light                          Swiss       Regular                       31 x 41   30 %
    @Yu Gothic Light                          Swiss       Regular                        31 x 41   30 %
    @Yu Gothic Light                          Swiss       Regular                   31 x 41   30 %
    @Yu Gothic Light                          Swiss       Regular                        31 x 41   30 %
    @Yu Gothic Light                          Swiss       Regular           31 x 41   30 %
    @Yu Gothic Light                          Swiss       Regular                        31 x 41   30 %
    @Yu Gothic                                Swiss       Regular                      31 x 41   40 %
    @Yu Gothic                                Swiss       Regular                       31 x 41   40 %
    @Yu Gothic                                Swiss       Regular                        31 x 41   40 %
    @Yu Gothic                                Swiss       Regular                   31 x 41   40 %
    @Yu Gothic                                Swiss       Regular                        31 x 41   40 %
    @Yu Gothic                                Swiss       Regular           31 x 41   40 %
    @Yu Gothic                                Swiss       Regular                        31 x 41   40 %
    @Yu Mincho Demibold                       Roman       Bold                         31 x 41   60 %
    @Yu Mincho Demibold                       Roman       Bold                          31 x 41   60 %
    @Yu Mincho Demibold                       Roman       Bold                           31 x 41   60 %
    @Yu Mincho Demibold                       Roman       Bold                      31 x 41   60 %
    @Yu Mincho Demibold                       Roman       Bold                           31 x 41   60 %
    @Yu Mincho Demibold                       Roman       Bold              31 x 41   60 %
    @Yu Mincho Demibold                       Roman       Bold                           31 x 41   60 %
    @Yu Mincho Light                          Roman       Regular                      31 x 41   30 %
    @Yu Mincho Light                          Roman       Regular                       31 x 41   30 %
    @Yu Mincho Light                          Roman       Regular                        31 x 41   30 %
    @Yu Mincho Light                          Roman       Regular                   31 x 41   30 %
    @Yu Mincho Light                          Roman       Regular                        31 x 41   30 %
    @Yu Mincho Light                          Roman       Regular           31 x 41   30 %
    @Yu Mincho Light                          Roman       Regular                        31 x 41   30 %
    @Yu Mincho                                Roman       Regular                      31 x 41   40 %
    @Yu Mincho                                Roman       Regular                       31 x 41   40 %
    @Yu Mincho                                Roman       Regular                        31 x 41   40 %
    @Yu Mincho                                Roman       Regular                   31 x 41   40 %
    @Yu Mincho                                Roman       Regular                        31 x 41   40 %
    @Yu Mincho                                Roman       Regular           31 x 41   40 %
    @Yu Mincho                                Roman       Regular                        31 x 41   40 %
    AcadEref                                  Special     Regular                        39 x 33   40 %
    Agency FB                                 Swiss                               10 x 36   40 %
    Aharoni                                   Special                          15 x 32   70 %
    Aharoni                                   Special                             15 x 32   70 %
    AIGDT                                     Special     Regular                      33 x 48   40 %
    Aldhabi                                   Special     Regular                        16 x 56   40 %
    Aldhabi                                   Special     Regular                        16 x 56   40 %
    Algerian                                  Decorative  Regular                        17 x 36   40 %
    AmdtSymbols                               Special     Regular                        40 x 25   40 %
    AMGDT_IV25                                Special     Regular                        41 x 48   40 %
    AMGDT_IV50                                Special     Regular                        41 x 48   40 %
    AMGDT                                     Special     Regular                        32 x 48   40 %
    Andalus                                   Roman                               15 x 49   40 %
    Andalus                                   Roman                               15 x 49   40 %
    Angsana New                               Roman                                8 x 43   40 %
    Angsana New                               Roman                                 8 x 43   40 %
    AngsanaUPC                                Roman                                8 x 43   40 %
    AngsanaUPC                                Roman                                 8 x 43   40 %
    Aparajita                                 Swiss                               16 x 38   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                             9 x 36   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                  9 x 36   40 %
    Arial Black                               Swiss                             18 x 45   90 %
    Arial Black                               Swiss                              18 x 45   90 %
    Arial Black                               Swiss                               18 x 45   90 %
    Arial Black                               Swiss                          18 x 45   90 %
    Arial Black                               Swiss                               18 x 45   90 %
    Arial Black                               Swiss                  18 x 45   90 %
    Arial Narrow                              Swiss                             12 x 36   40 %
    Arial Narrow                              Swiss                              12 x 36   40 %
    Arial Narrow                              Swiss                               12 x 36   40 %
    Arial Narrow                              Swiss                          12 x 36   40 %
    Arial Narrow                              Swiss                               12 x 36   40 %
    Arial Narrow                              Swiss                  12 x 36   40 %
    Arial Rounded MT Bold                     Swiss                               15 x 37   40 %
    Arial Unicode MS                          Swiss                               14 x 43   40 %
    Arial Unicode MS                          Swiss                             14 x 43   40 %
    Arial Unicode MS                          Swiss                            14 x 43   40 %
    Arial Unicode MS                          Swiss                              14 x 43   40 %
    Arial Unicode MS                          Swiss                               14 x 43   40 %
    Arial Unicode MS                          Swiss                                  14 x 43   40 %
    Arial Unicode MS                          Swiss                          14 x 43   40 %
    Arial Unicode MS                          Swiss                (2312)        14 x 43   40 %
    Arial Unicode MS                          Swiss                (BIG5)        14 x 43   40 %
    Arial Unicode MS                          Swiss                                14 x 43   40 %
    Arial Unicode MS                          Swiss                               14 x 43   40 %
    Arial Unicode MS                          Swiss                (Johab)         14 x 43   40 %
    Arial Unicode MS                          Swiss                                14 x 43   40 %
    Arial Unicode MS                          Swiss                  14 x 43   40 %
    Arial Unicode MS                          Swiss                               14 x 43   40 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                             14 x 36   40 %
    Arial                                     Swiss                            14 x 36   40 %
    Arial                                     Swiss                              14 x 36   40 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                                  14 x 36   40 %
    Arial                                     Swiss                          14 x 36   40 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                  14 x 36   40 %
    BankGothic Lt BT                          Swiss       Light                         18 x 33   40 %
    BankGothic Lt BT                          Swiss       Light                          18 x 33   40 %
    BankGothic Lt BT                          Swiss       Light                          18 x 33   40 %
    BankGothic Lt BT                          Swiss       Light                          18 x 33   40 %
    BankGothic Lt BT                          Swiss       Light             18 x 33   40 %
    BankGothic Md BT                          Swiss       Medium                        19 x 34   40 %
    BankGothic Md BT                          Swiss       Medium                         19 x 34   40 %
    BankGothic Md BT                          Swiss       Medium                         19 x 34   40 %
    BankGothic Md BT                          Swiss       Medium                         19 x 34   40 %
    BankGothic Md BT                          Swiss       Medium            19 x 34   40 %
    Baskerville Old Face                      Roman                               13 x 37   40 %
    Batang                                    Roman       Regular                      16 x 32   40 %
    Batang                                    Roman       Regular                       16 x 32   40 %
    Batang                                    Roman       Regular                        16 x 32   40 %
    Batang                                    Roman       Regular                   16 x 32   40 %
    Batang                                    Roman       Regular                        16 x 32   40 %
    Batang                                    Roman       Regular                         16 x 32   40 %
    Batang                                    Roman       Regular           16 x 32   40 %
    BatangChe                                 Modern      Regular                      16 x 32   40 %
    BatangChe                                 Modern      Regular                       16 x 32   40 %
    BatangChe                                 Modern      Regular                        16 x 32   40 %
    BatangChe                                 Modern      Regular                   16 x 32   40 %
    BatangChe                                 Modern      Regular                        16 x 32   40 %
    BatangChe                                 Modern      Regular                         16 x 32   40 %
    BatangChe                                 Modern      Regular           16 x 32   40 %
    Bauhaus 93                                Decorative                          14 x 36   40 %
    Bell MT                                   Roman                               13 x 35   40 %
    Berlin Sans FB Demi                       Swiss                            14 x 36   70 %
    Berlin Sans FB                            Swiss                               13 x 35   40 %
    Bernard MT Condensed                      Roman                               12 x 38   40 %
    Blackadder ITC                            Decorative                          10 x 41   40 %
    Bodoni MT Black                           Roman                               16 x 37   90 %
    Bodoni MT Condensed                       Roman                                9 x 38   40 %
    Bodoni MT Poster Compressed               Roman                                8 x 37   30 %
    Bodoni MT Poster Compressed               Roman                                8 x 37   30 %
    Bodoni MT                                 Roman                               13 x 38   40 %
    Book Antiqua                              Roman                             14 x 40   40 %
    Book Antiqua                              Roman                              14 x 40   40 %
    Book Antiqua                              Roman                               14 x 40   40 %
    Book Antiqua                              Roman                          14 x 40   40 %
    Book Antiqua                              Roman                               14 x 40   40 %
    Book Antiqua                              Roman                  14 x 40   40 %
    Bookman Old Style                         Roman                             16 x 36   30 %
    Bookman Old Style                         Roman                              16 x 36   30 %
    Bookman Old Style                         Roman                               16 x 36   30 %
    Bookman Old Style                         Roman                          16 x 36   30 %
    Bookman Old Style                         Roman                               16 x 36   30 %
    Bookman Old Style                         Roman                  16 x 36   30 %
    Bookshelf Symbol 7                        Special     Regular                      21 x 32   40 %
    Bradley Hand ITC                          Script                              13 x 40   40 %
    Britannic Bold                            Swiss                               14 x 35   40 %
    Broadway                                  Decorative                          17 x 36   40 %
    Browallia New                             Swiss       Regular                         9 x 40   40 %
    Browallia New                             Swiss       Regular                          9 x 40   40 %
    BrowalliaUPC                              Swiss       Regular                         9 x 40   40 %
    BrowalliaUPC                              Swiss       Regular                          9 x 40   40 %
    Brush Script MT                           Script                               10 x 39   40 %
    Calibri Light                             Swiss       Regular                      17 x 39   30 %
    Calibri Light                             Swiss       Regular                     17 x 39   30 %
    Calibri Light                             Swiss       Regular                       17 x 39   30 %
    Calibri Light                             Swiss       Regular                        17 x 39   30 %
    Calibri Light                             Swiss       Regular                   17 x 39   30 %
    Calibri Light                             Swiss       Regular                        17 x 39   30 %
    Calibri Light                             Swiss       Regular           17 x 39   30 %
    Calibri                                   Swiss       Regular                      17 x 39   40 %
    Calibri                                   Swiss       Regular                     17 x 39   40 %
    Calibri                                   Swiss       Regular                       17 x 39   40 %
    Calibri                                   Swiss       Regular                        17 x 39   40 %
    Calibri                                   Swiss       Regular                   17 x 39   40 %
    Calibri                                   Swiss       Regular                        17 x 39   40 %
    Calibri                                   Swiss       Regular           17 x 39   40 %
    Californian FB                            Roman                               13 x 36   40 %
    Calisto MT                                Roman                               13 x 37   40 %
    Cambria Math                              Roman       Regular                      20 x 179   40 %
    Cambria Math                              Roman       Regular                     20 x 179   40 %
    Cambria Math                              Roman       Regular                       20 x 179   40 %
    Cambria Math                              Roman       Regular                        20 x 179   40 %
    Cambria Math                              Roman       Regular                   20 x 179   40 %
    Cambria Math                              Roman       Regular                        20 x 179   40 %
    Cambria Math                              Roman       Regular           20 x 179   40 %
    Cambria                                   Roman       Regular                      20 x 38   40 %
    Cambria                                   Roman       Regular                     20 x 38   40 %
    Cambria                                   Roman       Regular                       20 x 38   40 %
    Cambria                                   Roman       Regular                        20 x 38   40 %
    Cambria                                   Roman       Regular                   20 x 38   40 %
    Cambria                                   Roman       Regular                        20 x 38   40 %
    Cambria                                   Roman       Regular           20 x 38   40 %
    Candara                                   Swiss       Regular                      17 x 39   40 %
    Candara                                   Swiss       Regular                     17 x 39   40 %
    Candara                                   Swiss       Regular                       17 x 39   40 %
    Candara                                   Swiss       Regular                        17 x 39   40 %
    Candara                                   Swiss       Regular                   17 x 39   40 %
    Candara                                   Swiss       Regular                        17 x 39   40 %
    Candara                                   Swiss       Regular           17 x 39   40 %
    Castellar                                 Roman                               21 x 39   40 %
    Centaur                                   Roman                               12 x 36   40 %
    Century Gothic                            Swiss                             16 x 38   40 %
    Century Gothic                            Swiss                              16 x 38   40 %
    Century Gothic                            Swiss                               16 x 38   40 %
    Century Gothic                            Swiss                          16 x 38   40 %
    Century Gothic                            Swiss                               16 x 38   40 %
    Century Gothic                            Swiss                  16 x 38   40 %
    Century Schoolbook                        Roman                             15 x 38   40 %
    Century Schoolbook                        Roman                              15 x 38   40 %
    Century Schoolbook                        Roman                               15 x 38   40 %
    Century Schoolbook                        Roman                          15 x 38   40 %
    Century Schoolbook                        Roman                               15 x 38   40 %
    Century Schoolbook                        Roman                  15 x 38   40 %
    Century                                   Roman                             15 x 38   40 %
    Century                                   Roman                              15 x 38   40 %
    Century                                   Roman                               15 x 38   40 %
    Century                                   Roman                          15 x 38   40 %
    Century                                   Roman                               15 x 38   40 %
    Century                                   Roman                  15 x 38   40 %
    Chiller                                   Decorative                           9 x 37   40 %
    CityBlueprint                             Special     Regular                      11 x 41   40 %
    Colonna MT                                Decorative                          13 x 34   40 %
    Comic Sans MS                             Script                            15 x 45   40 %
    Comic Sans MS                             Script                             15 x 45   40 %
    Comic Sans MS                             Script                              15 x 45   40 %
    Comic Sans MS                             Script                         15 x 45   40 %
    Comic Sans MS                             Script                              15 x 45   40 %
    Comic Sans MS                             Script                 15 x 45   40 %
    CommercialPi BT                           Roman       Regular                      22 x 32   40 %
    CommercialScript BT                       Script      Regular                       12 x 37   40 %
    CommercialScript BT                       Script      Regular                        12 x 37   40 %
    CommercialScript BT                       Script      Regular                        12 x 37   40 %
    CommercialScript BT                       Script      Regular                        12 x 37   40 %
    CommercialScript BT                       Script      Regular           12 x 37   40 %
    Complex_IV25                              Special     Regular                        22 x 45   40 %
    Complex_IV25                              Special     Regular                      22 x 45   40 %
    Complex_IV25                              Special     Regular                     22 x 45   40 %
    Complex_IV25                              Special     Regular                       22 x 45   40 %
    Complex_IV25                              Special     Regular                        22 x 45   40 %
    Complex_IV25                              Special     Regular                           22 x 45   40 %
    Complex_IV25                              Special     Regular                   22 x 45   40 %
    Complex_IV25                              Special     Regular                        22 x 45   40 %
    Complex_IV25                              Special     Regular           22 x 45   40 %
    Complex_IV50                              Special     Regular                        22 x 45   40 %
    Complex_IV50                              Special     Regular                      22 x 45   40 %
    Complex_IV50                              Special     Regular                     22 x 45   40 %
    Complex_IV50                              Special     Regular                       22 x 45   40 %
    Complex_IV50                              Special     Regular                        22 x 45   40 %
    Complex_IV50                              Special     Regular                           22 x 45   40 %
    Complex_IV50                              Special     Regular                   22 x 45   40 %
    Complex_IV50                              Special     Regular                        22 x 45   40 %
    Complex_IV50                              Special     Regular           22 x 45   40 %
    Complex                                   Special     Regular                        22 x 45   40 %
    Complex                                   Special     Regular                      22 x 45   40 %
    Complex                                   Special     Regular                     22 x 45   40 %
    Complex                                   Special     Regular                       22 x 45   40 %
    Complex                                   Special     Regular                        22 x 45   40 %
    Complex                                   Special     Regular                           22 x 45   40 %
    Complex                                   Special     Regular                   22 x 45   40 %
    Complex                                   Special     Regular                        22 x 45   40 %
    Complex                                   Special     Regular           22 x 45   40 %
    Consolas                                  Modern      Regular                      18 x 37   40 %
    Consolas                                  Modern      Regular                     18 x 37   40 %
    Consolas                                  Modern      Regular                       18 x 37   40 %
    Consolas                                  Modern      Regular                        18 x 37   40 %
    Consolas                                  Modern      Regular                   18 x 37   40 %
    Consolas                                  Modern      Regular                        18 x 37   40 %
    Consolas                                  Modern      Regular           18 x 37   40 %
    Constantia                                Roman       Regular                      17 x 39   40 %
    Constantia                                Roman       Regular                     17 x 39   40 %
    Constantia                                Roman       Regular                       17 x 39   40 %
    Constantia                                Roman       Regular                        17 x 39   40 %
    Constantia                                Roman       Regular                   17 x 39   40 %
    Constantia                                Roman       Regular                        17 x 39   40 %
    Constantia                                Roman       Regular           17 x 39   40 %
    Cooper Black                              Roman                               16 x 37   40 %
    Copperplate Gothic Bold                   Swiss                               19 x 36   40 %
    Copperplate Gothic Light                  Swiss                               18 x 35   40 %
    Corbel                                    Swiss       Regular                      17 x 39   40 %
    Corbel                                    Swiss       Regular                     17 x 39   40 %
    Corbel                                    Swiss       Regular                       17 x 39   40 %
    Corbel                                    Swiss       Regular                        17 x 39   40 %
    Corbel                                    Swiss       Regular                   17 x 39   40 %
    Corbel                                    Swiss       Regular                        17 x 39   40 %
    Corbel                                    Swiss       Regular           17 x 39   40 %
    Cordia New                                Swiss       Regular                         9 x 44   40 %
    Cordia New                                Swiss       Regular                          9 x 44   40 %
    CordiaUPC                                 Swiss       Regular                         9 x 44   40 %
    CordiaUPC                                 Swiss       Regular                          9 x 44   40 %
    CountryBlueprint                          Special     Regular                      13 x 44   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                            19 x 36   40 %
    Courier New                               Modern                           19 x 36   40 %
    Courier New                               Modern                             19 x 36   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                                 19 x 36   40 %
    Courier New                               Modern                         19 x 36   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                 19 x 36   40 %
    Courier                                   Roman                                  8 x 13   40 %
    Curlz MT                                  Decorative                          12 x 42   40 %
    DaunPenh                                  Special                             12 x 43   40 %
    David                                     Swiss       Regular                        16 x 31   40 %
    David                                     Swiss       Regular                           16 x 31   40 %
    DFKai-SB                                  Script      Regular                        16 x 32   40 %
    DFKai-SB                                  Script      Regular         (BIG5)        16 x 32   40 %
    DilleniaUPC                               Roman                                9 x 42   40 %
    DilleniaUPC                               Roman                                 9 x 42   40 %
    DokChampa                                 Swiss                               19 x 62   40 %
    DokChampa                                 Swiss                                19 x 62   40 %
    Dotum                                     Swiss       Regular                      16 x 32   40 %
    Dotum                                     Swiss       Regular                       16 x 32   40 %
    Dotum                                     Swiss       Regular                        16 x 32   40 %
    Dotum                                     Swiss       Regular                   16 x 32   40 %
    Dotum                                     Swiss       Regular                        16 x 32   40 %
    Dotum                                     Swiss       Regular                         16 x 32   40 %
    Dotum                                     Swiss       Regular           16 x 32   40 %
    DotumChe                                  Modern      Regular                      16 x 32   40 %
    DotumChe                                  Modern      Regular                       16 x 32   40 %
    DotumChe                                  Modern      Regular                        16 x 32   40 %
    DotumChe                                  Modern      Regular                   16 x 32   40 %
    DotumChe                                  Modern      Regular                        16 x 32   40 %
    DotumChe                                  Modern      Regular                         16 x 32   40 %
    DotumChe                                  Modern      Regular           16 x 32   40 %
    Dutch801 Rm BT                            Roman       Roman                         14 x 39   40 %
    Dutch801 Rm BT                            Roman       Roman                          14 x 39   40 %
    Dutch801 Rm BT                            Roman       Roman                          14 x 39   40 %
    Dutch801 Rm BT                            Roman       Roman                          14 x 39   40 %
    Dutch801 Rm BT                            Roman       Roman             14 x 39   40 %
    Dutch801 XBd BT                           Roman       Extra Bold                    15 x 39   40 %
    Dutch801 XBd BT                           Roman       Extra Bold                     15 x 39   40 %
    Dutch801 XBd BT                           Roman       Extra Bold                     15 x 39   40 %
    Dutch801 XBd BT                           Roman       Extra Bold                     15 x 39   40 %
    Dutch801 XBd BT                           Roman       Extra Bold        15 x 39   40 %
    Ebrima                                    Special                           19 x 43   40 %
    Ebrima                                    Special                             19 x 43   40 %
    Ebrima                                    Special                             19 x 43   40 %
    Ebrima                                    Special                19 x 43   40 %
    Edwardian Script ITC                      Script                               8 x 38   40 %
    Elephant                                  Roman                               16 x 41   40 %
    Engravers MT                              Roman                               25 x 37   50 %
    Eras Bold ITC                             Swiss                               16 x 37   40 %
    Eras Demi ITC                             Swiss                               15 x 36   40 %
    Eras Light ITC                            Swiss                               13 x 36   40 %
    Eras Medium ITC                           Swiss                               14 x 36   40 %
    Estrangelo Edessa                         Script                              16 x 36   40 %
    EucrosiaUPC                               Roman                                9 x 39   40 %
    EucrosiaUPC                               Roman                                 9 x 39   40 %
    Euphemia                                  Swiss       Regular                        22 x 42   40 %
    EuroRoman                                 Special     Regular                      13 x 34   40 %
    FangSong                                  Modern                              16 x 32   40 %
    FangSong                                  Modern               (2312)        16 x 32   40 %
    Felix Titling                             Decorative                          19 x 37   40 %
    Fixedsys                                  Swiss                                  8 x 16   40 %
    Footlight MT Light                        Roman                               13 x 34   30 %
    Forte                                     Script      Regular                        14 x 35   40 %
    Franklin Gothic Book                      Swiss                             13 x 36   40 %
    Franklin Gothic Book                      Swiss                              13 x 36   40 %
    Franklin Gothic Book                      Swiss                               13 x 36   40 %
    Franklin Gothic Book                      Swiss                          13 x 36   40 %
    Franklin Gothic Book                      Swiss                               13 x 36   40 %
    Franklin Gothic Book                      Swiss                  13 x 36   40 %
    Franklin Gothic Demi Cond                 Swiss                             12 x 36   40 %
    Franklin Gothic Demi Cond                 Swiss                              12 x 36   40 %
    Franklin Gothic Demi Cond                 Swiss                               12 x 36   40 %
    Franklin Gothic Demi Cond                 Swiss                          12 x 36   40 %
    Franklin Gothic Demi Cond                 Swiss                               12 x 36   40 %
    Franklin Gothic Demi Cond                 Swiss                  12 x 36   40 %
    Franklin Gothic Demi                      Swiss                             14 x 36   40 %
    Franklin Gothic Demi                      Swiss                              14 x 36   40 %
    Franklin Gothic Demi                      Swiss                               14 x 36   40 %
    Franklin Gothic Demi                      Swiss                          14 x 36   40 %
    Franklin Gothic Demi                      Swiss                               14 x 36   40 %
    Franklin Gothic Demi                      Swiss                  14 x 36   40 %
    Franklin Gothic Heavy                     Swiss                             15 x 36   40 %
    Franklin Gothic Heavy                     Swiss                              15 x 36   40 %
    Franklin Gothic Heavy                     Swiss                               15 x 36   40 %
    Franklin Gothic Heavy                     Swiss                          15 x 36   40 %
    Franklin Gothic Heavy                     Swiss                               15 x 36   40 %
    Franklin Gothic Heavy                     Swiss                  15 x 36   40 %
    Franklin Gothic Medium Cond               Swiss                             12 x 36   40 %
    Franklin Gothic Medium Cond               Swiss                              12 x 36   40 %
    Franklin Gothic Medium Cond               Swiss                               12 x 36   40 %
    Franklin Gothic Medium Cond               Swiss                          12 x 36   40 %
    Franklin Gothic Medium Cond               Swiss                               12 x 36   40 %
    Franklin Gothic Medium Cond               Swiss                  12 x 36   40 %
    Franklin Gothic Medium                    Swiss                             14 x 36   40 %
    Franklin Gothic Medium                    Swiss                              14 x 36   40 %
    Franklin Gothic Medium                    Swiss                               14 x 36   40 %
    Franklin Gothic Medium                    Swiss                          14 x 36   40 %
    Franklin Gothic Medium                    Swiss                               14 x 36   40 %
    Franklin Gothic Medium                    Swiss                  14 x 36   40 %
    FrankRuehl                                Swiss       Regular                        13 x 30   40 %
    FrankRuehl                                Swiss       Regular                           13 x 30   40 %
    FreesiaUPC                                Swiss       Regular                         9 x 38   40 %
    FreesiaUPC                                Swiss       Regular                          9 x 38   40 %
    Freestyle Script                          Script                               8 x 38   40 %
    French Script MT                          Script                               9 x 36   40 %
    Gabriola                                  Decorative  Regular                      16 x 59   40 %
    Gabriola                                  Decorative  Regular                       16 x 59   40 %
    Gabriola                                  Decorative  Regular                        16 x 59   40 %
    Gabriola                                  Decorative  Regular                   16 x 59   40 %
    Gabriola                                  Decorative  Regular                        16 x 59   40 %
    Gabriola                                  Decorative  Regular           16 x 59   40 %
    Gadugi                                    Swiss                               18 x 43   40 %
    Garamond                                  Roman                             12 x 36   40 %
    Garamond                                  Roman                              12 x 36   40 %
    Garamond                                  Roman                               12 x 36   40 %
    Garamond                                  Roman                          12 x 36   40 %
    Garamond                                  Roman                               12 x 36   40 %
    Garamond                                  Roman                  12 x 36   40 %
    Gautami                                   Swiss                               18 x 56   40 %
    GDT_IV25                                  Special     Regular                        41 x 48   40 %
    GDT_IV50                                  Special     Regular                        41 x 48   40 %
    GDT                                       Special     Regular                        41 x 48   40 %
    GENISO                                    Special     Regular                        17 x 51   40 %
    GENISO                                    Special     Regular                      17 x 51   40 %
    GENISO                                    Special     Regular                     17 x 51   40 %
    GENISO                                    Special     Regular                       17 x 51   40 %
    GENISO                                    Special     Regular                        17 x 51   40 %
    GENISO                                    Special     Regular                           17 x 51   40 %
    GENISO                                    Special     Regular                   17 x 51   40 %
    GENISO                                    Special     Regular                        17 x 51   40 %
    GENISO                                    Special     Regular           17 x 51   40 %
    Georgia                                   Roman                             14 x 36   40 %
    Georgia                                   Roman                              14 x 36   40 %
    Georgia                                   Roman                               14 x 36   40 %
    Georgia                                   Roman                          14 x 36   40 %
    Georgia                                   Roman                               14 x 36   40 %
    Georgia                                   Roman                  14 x 36   40 %
    Gigi                                      Decorative                          13 x 44   40 %
    Gill Sans MT Condensed                    Swiss                               10 x 39   40 %
    Gill Sans MT Condensed                    Swiss                  10 x 39   40 %
    Gill Sans MT Ext Condensed Bold           Swiss                                7 x 38   40 %
    Gill Sans MT Ext Condensed Bold           Swiss                   7 x 38   40 %
    Gill Sans MT                              Swiss                               13 x 37   40 %
    Gill Sans MT                              Swiss                  13 x 37   40 %
    Gill Sans Ultra Bold Condensed            Swiss                               14 x 40   40 %
    Gill Sans Ultra Bold Condensed            Swiss                  14 x 40   40 %
    Gill Sans Ultra Bold                      Swiss                               20 x 40   40 %
    Gill Sans Ultra Bold                      Swiss                  20 x 40   40 %
    Gisha                                     Swiss                               16 x 38   40 %
    Gisha                                     Swiss                                  16 x 38   40 %
    Gloucester MT Extra Condensed             Roman       Regular                         9 x 37   40 %
    GOST Common                               Swiss       Regular                      14 x 39   40 %
    GOST Common                               Swiss       Regular                       14 x 39   40 %
    GOST Common                               Swiss       Regular                        14 x 39   40 %
    GOST Common                               Swiss       Regular                   14 x 39   40 %
    GOST Common                               Swiss       Regular                        14 x 39   40 %
    GOST Common                               Swiss       Regular           14 x 39   40 %
    GothicE                                   Special     Regular                        19 x 46   40 %
    GothicE                                   Special     Regular                      19 x 46   40 %
    GothicE                                   Special     Regular                     19 x 46   40 %
    GothicE                                   Special     Regular                       19 x 46   40 %
    GothicE                                   Special     Regular                        19 x 46   40 %
    GothicE                                   Special     Regular                           19 x 46   40 %
    GothicE                                   Special     Regular                   19 x 46   40 %
    GothicE                                   Special     Regular                        19 x 46   40 %
    GothicE                                   Special     Regular           19 x 46   40 %
    GothicG                                   Special     Regular                        18 x 45   40 %
    GothicG                                   Special     Regular                      18 x 45   40 %
    GothicG                                   Special     Regular                     18 x 45   40 %
    GothicG                                   Special     Regular                       18 x 45   40 %
    GothicG                                   Special     Regular                        18 x 45   40 %
    GothicG                                   Special     Regular                           18 x 45   40 %
    GothicG                                   Special     Regular                   18 x 45   40 %
    GothicG                                   Special     Regular                        18 x 45   40 %
    GothicG                                   Special     Regular           18 x 45   40 %
    GothicI                                   Special     Regular                        18 x 45   40 %
    GothicI                                   Special     Regular                      18 x 45   40 %
    GothicI                                   Special     Regular                     18 x 45   40 %
    GothicI                                   Special     Regular                       18 x 45   40 %
    GothicI                                   Special     Regular                        18 x 45   40 %
    GothicI                                   Special     Regular                           18 x 45   40 %
    GothicI                                   Special     Regular                   18 x 45   40 %
    GothicI                                   Special     Regular                        18 x 45   40 %
    GothicI                                   Special     Regular           18 x 45   40 %
    Goudy Old Style                           Roman                               13 x 36   40 %
    Goudy Stout                               Roman                               36 x 44   40 %
    GreekC_IV25                               Special     Regular                        23 x 44   40 %
    GreekC_IV25                               Special     Regular                      23 x 44   40 %
    GreekC_IV25                               Special     Regular                     23 x 44   40 %
    GreekC_IV25                               Special     Regular                       23 x 44   40 %
    GreekC_IV25                               Special     Regular                        23 x 44   40 %
    GreekC_IV25                               Special     Regular                           23 x 44   40 %
    GreekC_IV25                               Special     Regular                   23 x 44   40 %
    GreekC_IV25                               Special     Regular                        23 x 44   40 %
    GreekC_IV25                               Special     Regular           23 x 44   40 %
    GreekC_IV50                               Special     Regular                        23 x 44   40 %
    GreekC_IV50                               Special     Regular                      23 x 44   40 %
    GreekC_IV50                               Special     Regular                     23 x 44   40 %
    GreekC_IV50                               Special     Regular                       23 x 44   40 %
    GreekC_IV50                               Special     Regular                        23 x 44   40 %
    GreekC_IV50                               Special     Regular                           23 x 44   40 %
    GreekC_IV50                               Special     Regular                   23 x 44   40 %
    GreekC_IV50                               Special     Regular                        23 x 44   40 %
    GreekC_IV50                               Special     Regular           23 x 44   40 %
    GreekC                                    Special     Regular                        23 x 44   40 %
    GreekC                                    Special     Regular                      23 x 44   40 %
    GreekC                                    Special     Regular                     23 x 44   40 %
    GreekC                                    Special     Regular                       23 x 44   40 %
    GreekC                                    Special     Regular                        23 x 44   40 %
    GreekC                                    Special     Regular                           23 x 44   40 %
    GreekC                                    Special     Regular                   23 x 44   40 %
    GreekC                                    Special     Regular                        23 x 44   40 %
    GreekC                                    Special     Regular           23 x 44   40 %
    GreekS_IV25                               Special     Regular                        22 x 46   40 %
    GreekS_IV25                               Special     Regular                      22 x 46   40 %
    GreekS_IV25                               Special     Regular                     22 x 46   40 %
    GreekS_IV25                               Special     Regular                       22 x 46   40 %
    GreekS_IV25                               Special     Regular                        22 x 46   40 %
    GreekS_IV25                               Special     Regular                           22 x 46   40 %
    GreekS_IV25                               Special     Regular                   22 x 46   40 %
    GreekS_IV25                               Special     Regular                        22 x 46   40 %
    GreekS_IV25                               Special     Regular           22 x 46   40 %
    GreekS_IV50                               Special     Regular                        22 x 46   40 %
    GreekS_IV50                               Special     Regular                      22 x 46   40 %
    GreekS_IV50                               Special     Regular                     22 x 46   40 %
    GreekS_IV50                               Special     Regular                       22 x 46   40 %
    GreekS_IV50                               Special     Regular                        22 x 46   40 %
    GreekS_IV50                               Special     Regular                           22 x 46   40 %
    GreekS_IV50                               Special     Regular                   22 x 46   40 %
    GreekS_IV50                               Special     Regular                        22 x 46   40 %
    GreekS_IV50                               Special     Regular           22 x 46   40 %
    GreekS                                    Special     Regular                        22 x 46   40 %
    GreekS                                    Special     Regular                      22 x 46   40 %
    GreekS                                    Special     Regular                     22 x 46   40 %
    GreekS                                    Special     Regular                       22 x 46   40 %
    GreekS                                    Special     Regular                        22 x 46   40 %
    GreekS                                    Special     Regular                           22 x 46   40 %
    GreekS                                    Special     Regular                   22 x 46   40 %
    GreekS                                    Special     Regular                        22 x 46   40 %
    GreekS                                    Special     Regular           22 x 46   40 %
    Gulim                                     Swiss       Regular                      16 x 32   40 %
    Gulim                                     Swiss       Regular                       16 x 32   40 %
    Gulim                                     Swiss       Regular                        16 x 32   40 %
    Gulim                                     Swiss       Regular                   16 x 32   40 %
    Gulim                                     Swiss       Regular                        16 x 32   40 %
    Gulim                                     Swiss       Regular                         16 x 32   40 %
    Gulim                                     Swiss       Regular           16 x 32   40 %
    GulimChe                                  Modern      Regular                      16 x 32   40 %
    GulimChe                                  Modern      Regular                       16 x 32   40 %
    GulimChe                                  Modern      Regular                        16 x 32   40 %
    GulimChe                                  Modern      Regular                   16 x 32   40 %
    GulimChe                                  Modern      Regular                        16 x 32   40 %
    GulimChe                                  Modern      Regular                         16 x 32   40 %
    GulimChe                                  Modern      Regular           16 x 32   40 %
    Gungsuh                                   Roman       Regular                      16 x 32   40 %
    Gungsuh                                   Roman       Regular                       16 x 32   40 %
    Gungsuh                                   Roman       Regular                        16 x 32   40 %
    Gungsuh                                   Roman       Regular                   16 x 32   40 %
    Gungsuh                                   Roman       Regular                        16 x 32   40 %
    Gungsuh                                   Roman       Regular                         16 x 32   40 %
    Gungsuh                                   Roman       Regular           16 x 32   40 %
    GungsuhChe                                Modern      Regular                      16 x 32   40 %
    GungsuhChe                                Modern      Regular                       16 x 32   40 %
    GungsuhChe                                Modern      Regular                        16 x 32   40 %
    GungsuhChe                                Modern      Regular                   16 x 32   40 %
    GungsuhChe                                Modern      Regular                        16 x 32   40 %
    GungsuhChe                                Modern      Regular                         16 x 32   40 %
    GungsuhChe                                Modern      Regular           16 x 32   40 %
    Haettenschweiler                          Swiss                             10 x 33   40 %
    Haettenschweiler                          Swiss                              10 x 33   40 %
    Haettenschweiler                          Swiss                               10 x 33   40 %
    Haettenschweiler                          Swiss                          10 x 33   40 %
    Haettenschweiler                          Swiss                               10 x 33   40 %
    Haettenschweiler                          Swiss                  10 x 33   40 %
    Harlow Solid Italic                       Decorative  Italic                         12 x 40   40 %
    Harrington                                Decorative                          14 x 38   40 %
    High Tower Text                           Roman                               13 x 37   40 %
    Impact                                    Swiss                             19 x 39   40 %
    Impact                                    Swiss                              19 x 39   40 %
    Impact                                    Swiss                               19 x 39   40 %
    Impact                                    Swiss                          19 x 39   40 %
    Impact                                    Swiss                               19 x 39   40 %
    Impact                                    Swiss                  19 x 39   40 %
    Imprint MT Shadow                         Decorative                          13 x 38   40 %
    Informal Roman                            Script                              12 x 32   40 %
    IrisUPC                                   Swiss       Regular                         9 x 40   40 %
    IrisUPC                                   Swiss       Regular                          9 x 40   40 %
    Iskoola Pota                              Swiss                               22 x 36   40 %
    ISOCP_IV25                                Special     Regular                        14 x 51   40 %
    ISOCP_IV25                                Special     Regular                      14 x 51   40 %
    ISOCP_IV25                                Special     Regular                     14 x 51   40 %
    ISOCP_IV25                                Special     Regular                       14 x 51   40 %
    ISOCP_IV25                                Special     Regular                        14 x 51   40 %
    ISOCP_IV25                                Special     Regular                           14 x 51   40 %
    ISOCP_IV25                                Special     Regular                   14 x 51   40 %
    ISOCP_IV25                                Special     Regular                        14 x 51   40 %
    ISOCP_IV25                                Special     Regular           14 x 51   40 %
    ISOCP_IV50                                Special     Regular                        14 x 51   40 %
    ISOCP_IV50                                Special     Regular                      14 x 51   40 %
    ISOCP_IV50                                Special     Regular                     14 x 51   40 %
    ISOCP_IV50                                Special     Regular                       14 x 51   40 %
    ISOCP_IV50                                Special     Regular                        14 x 51   40 %
    ISOCP_IV50                                Special     Regular                           14 x 51   40 %
    ISOCP_IV50                                Special     Regular                   14 x 51   40 %
    ISOCP_IV50                                Special     Regular                        14 x 51   40 %
    ISOCP_IV50                                Special     Regular           14 x 51   40 %
    ISOCP                                     Special     Regular                        16 x 51   40 %
    ISOCP                                     Special     Regular                      16 x 51   40 %
    ISOCP                                     Special     Regular                     16 x 51   40 %
    ISOCP                                     Special     Regular                       16 x 51   40 %
    ISOCP                                     Special     Regular                        16 x 51   40 %
    ISOCP                                     Special     Regular                           16 x 51   40 %
    ISOCP                                     Special     Regular                   16 x 51   40 %
    ISOCP                                     Special     Regular                        16 x 51   40 %
    ISOCP                                     Special     Regular           16 x 51   40 %
    ISOCP2_IV25                               Special     Regular                        14 x 51   40 %
    ISOCP2_IV25                               Special     Regular                      14 x 51   40 %
    ISOCP2_IV25                               Special     Regular                     14 x 51   40 %
    ISOCP2_IV25                               Special     Regular                       14 x 51   40 %
    ISOCP2_IV25                               Special     Regular                        14 x 51   40 %
    ISOCP2_IV25                               Special     Regular                           14 x 51   40 %
    ISOCP2_IV25                               Special     Regular                   14 x 51   40 %
    ISOCP2_IV25                               Special     Regular                        14 x 51   40 %
    ISOCP2_IV25                               Special     Regular           14 x 51   40 %
    ISOCP2_IV50                               Special     Regular                        14 x 51   40 %
    ISOCP2_IV50                               Special     Regular                      14 x 51   40 %
    ISOCP2_IV50                               Special     Regular                     14 x 51   40 %
    ISOCP2_IV50                               Special     Regular                       14 x 51   40 %
    ISOCP2_IV50                               Special     Regular                        14 x 51   40 %
    ISOCP2_IV50                               Special     Regular                           14 x 51   40 %
    ISOCP2_IV50                               Special     Regular                   14 x 51   40 %
    ISOCP2_IV50                               Special     Regular                        14 x 51   40 %
    ISOCP2_IV50                               Special     Regular           14 x 51   40 %
    ISOCP2                                    Special     Regular                        14 x 51   40 %
    ISOCP2                                    Special     Regular                      14 x 51   40 %
    ISOCP2                                    Special     Regular                     14 x 51   40 %
    ISOCP2                                    Special     Regular                       14 x 51   40 %
    ISOCP2                                    Special     Regular                        14 x 51   40 %
    ISOCP2                                    Special     Regular                           14 x 51   40 %
    ISOCP2                                    Special     Regular                   14 x 51   40 %
    ISOCP2                                    Special     Regular                        14 x 51   40 %
    ISOCP2                                    Special     Regular           14 x 51   40 %
    ISOCP3_IV25                               Special     Regular                        14 x 51   40 %
    ISOCP3_IV25                               Special     Regular                      14 x 51   40 %
    ISOCP3_IV25                               Special     Regular                     14 x 51   40 %
    ISOCP3_IV25                               Special     Regular                       14 x 51   40 %
    ISOCP3_IV25                               Special     Regular                        14 x 51   40 %
    ISOCP3_IV25                               Special     Regular                           14 x 51   40 %
    ISOCP3_IV25                               Special     Regular                   14 x 51   40 %
    ISOCP3_IV25                               Special     Regular                        14 x 51   40 %
    ISOCP3_IV25                               Special     Regular           14 x 51   40 %
    ISOCP3_IV50                               Special     Regular                        14 x 51   40 %
    ISOCP3_IV50                               Special     Regular                      14 x 51   40 %
    ISOCP3_IV50                               Special     Regular                     14 x 51   40 %
    ISOCP3_IV50                               Special     Regular                       14 x 51   40 %
    ISOCP3_IV50                               Special     Regular                        14 x 51   40 %
    ISOCP3_IV50                               Special     Regular                           14 x 51   40 %
    ISOCP3_IV50                               Special     Regular                   14 x 51   40 %
    ISOCP3_IV50                               Special     Regular                        14 x 51   40 %
    ISOCP3_IV50                               Special     Regular           14 x 51   40 %
    ISOCP3                                    Special     Regular                        14 x 51   40 %
    ISOCP3                                    Special     Regular                      14 x 51   40 %
    ISOCP3                                    Special     Regular                     14 x 51   40 %
    ISOCP3                                    Special     Regular                       14 x 51   40 %
    ISOCP3                                    Special     Regular                        14 x 51   40 %
    ISOCP3                                    Special     Regular                           14 x 51   40 %
    ISOCP3                                    Special     Regular                   14 x 51   40 %
    ISOCP3                                    Special     Regular                        14 x 51   40 %
    ISOCP3                                    Special     Regular           14 x 51   40 %
    ISOCPEUR                                  Swiss       Regular                      16 x 39   40 %
    ISOCPEUR                                  Swiss       Regular                       16 x 39   40 %
    ISOCPEUR                                  Swiss       Regular                        16 x 39   40 %
    ISOCPEUR                                  Swiss       Regular                   16 x 39   40 %
    ISOCPEUR                                  Swiss       Regular                        16 x 39   40 %
    ISOCPEUR                                  Swiss       Regular           16 x 39   40 %
    ISOCT_IV25                                Special     Regular                        25 x 55   40 %
    ISOCT_IV25                                Special     Regular                      25 x 55   40 %
    ISOCT_IV25                                Special     Regular                     25 x 55   40 %
    ISOCT_IV25                                Special     Regular                       25 x 55   40 %
    ISOCT_IV25                                Special     Regular                        25 x 55   40 %
    ISOCT_IV25                                Special     Regular                           25 x 55   40 %
    ISOCT_IV25                                Special     Regular                   25 x 55   40 %
    ISOCT_IV25                                Special     Regular                        25 x 55   40 %
    ISOCT_IV25                                Special     Regular           25 x 55   40 %
    ISOCT_IV50                                Special     Regular                        25 x 55   40 %
    ISOCT_IV50                                Special     Regular                      25 x 55   40 %
    ISOCT_IV50                                Special     Regular                     25 x 55   40 %
    ISOCT_IV50                                Special     Regular                       25 x 55   40 %
    ISOCT_IV50                                Special     Regular                        25 x 55   40 %
    ISOCT_IV50                                Special     Regular                           25 x 55   40 %
    ISOCT_IV50                                Special     Regular                   25 x 55   40 %
    ISOCT_IV50                                Special     Regular                        25 x 55   40 %
    ISOCT_IV50                                Special     Regular           25 x 55   40 %
    ISOCT                                     Special     Regular                        25 x 55   40 %
    ISOCT                                     Special     Regular                      25 x 55   40 %
    ISOCT                                     Special     Regular                     25 x 55   40 %
    ISOCT                                     Special     Regular                       25 x 55   40 %
    ISOCT                                     Special     Regular                        25 x 55   40 %
    ISOCT                                     Special     Regular                           25 x 55   40 %
    ISOCT                                     Special     Regular                   25 x 55   40 %
    ISOCT                                     Special     Regular                        25 x 55   40 %
    ISOCT                                     Special     Regular           25 x 55   40 %
    ISOCT2_IV25                               Special     Regular                        25 x 55   40 %
    ISOCT2_IV25                               Special     Regular                      25 x 55   40 %
    ISOCT2_IV25                               Special     Regular                     25 x 55   40 %
    ISOCT2_IV25                               Special     Regular                       25 x 55   40 %
    ISOCT2_IV25                               Special     Regular                        25 x 55   40 %
    ISOCT2_IV25                               Special     Regular                           25 x 55   40 %
    ISOCT2_IV25                               Special     Regular                   25 x 55   40 %
    ISOCT2_IV25                               Special     Regular                        25 x 55   40 %
    ISOCT2_IV25                               Special     Regular           25 x 55   40 %
    ISOCT2_IV50                               Special     Regular                        25 x 55   40 %
    ISOCT2_IV50                               Special     Regular                      25 x 55   40 %
    ISOCT2_IV50                               Special     Regular                     25 x 55   40 %
    ISOCT2_IV50                               Special     Regular                       25 x 55   40 %
    ISOCT2_IV50                               Special     Regular                        25 x 55   40 %
    ISOCT2_IV50                               Special     Regular                           25 x 55   40 %
    ISOCT2_IV50                               Special     Regular                   25 x 55   40 %
    ISOCT2_IV50                               Special     Regular                        25 x 55   40 %
    ISOCT2_IV50                               Special     Regular           25 x 55   40 %
    ISOCT2                                    Special     Regular                        25 x 55   40 %
    ISOCT2                                    Special     Regular                      25 x 55   40 %
    ISOCT2                                    Special     Regular                     25 x 55   40 %
    ISOCT2                                    Special     Regular                       25 x 55   40 %
    ISOCT2                                    Special     Regular                        25 x 55   40 %
    ISOCT2                                    Special     Regular                           25 x 55   40 %
    ISOCT2                                    Special     Regular                   25 x 55   40 %
    ISOCT2                                    Special     Regular                        25 x 55   40 %
    ISOCT2                                    Special     Regular           25 x 55   40 %
    ISOCT3_IV25                               Special     Regular                        25 x 55   40 %
    ISOCT3_IV25                               Special     Regular                      25 x 55   40 %
    ISOCT3_IV25                               Special     Regular                     25 x 55   40 %
    ISOCT3_IV25                               Special     Regular                       25 x 55   40 %
    ISOCT3_IV25                               Special     Regular                        25 x 55   40 %
    ISOCT3_IV25                               Special     Regular                           25 x 55   40 %
    ISOCT3_IV25                               Special     Regular                   25 x 55   40 %
    ISOCT3_IV25                               Special     Regular                        25 x 55   40 %
    ISOCT3_IV25                               Special     Regular           25 x 55   40 %
    ISOCT3_IV50                               Special     Regular                        25 x 55   40 %
    ISOCT3_IV50                               Special     Regular                      25 x 55   40 %
    ISOCT3_IV50                               Special     Regular                     25 x 55   40 %
    ISOCT3_IV50                               Special     Regular                       25 x 55   40 %
    ISOCT3_IV50                               Special     Regular                        25 x 55   40 %
    ISOCT3_IV50                               Special     Regular                           25 x 55   40 %
    ISOCT3_IV50                               Special     Regular                   25 x 55   40 %
    ISOCT3_IV50                               Special     Regular                        25 x 55   40 %
    ISOCT3_IV50                               Special     Regular           25 x 55   40 %
    ISOCT3                                    Special     Regular                        25 x 55   40 %
    ISOCT3                                    Special     Regular                      25 x 55   40 %
    ISOCT3                                    Special     Regular                     25 x 55   40 %
    ISOCT3                                    Special     Regular                       25 x 55   40 %
    ISOCT3                                    Special     Regular                        25 x 55   40 %
    ISOCT3                                    Special     Regular                           25 x 55   40 %
    ISOCT3                                    Special     Regular                   25 x 55   40 %
    ISOCT3                                    Special     Regular                        25 x 55   40 %
    ISOCT3                                    Special     Regular           25 x 55   40 %
    ISOCTEUR                                  Modern      Regular                      23 x 39   40 %
    ISOCTEUR                                  Modern      Regular                       23 x 39   40 %
    ISOCTEUR                                  Modern      Regular                        23 x 39   40 %
    ISOCTEUR                                  Modern      Regular                   23 x 39   40 %
    ISOCTEUR                                  Modern      Regular                        23 x 39   40 %
    ISOCTEUR                                  Modern      Regular           23 x 39   40 %
    Italic_IV25                               Special     Regular                        22 x 47   40 %
    Italic_IV25                               Special     Regular                      22 x 47   40 %
    Italic_IV25                               Special     Regular                     22 x 47   40 %
    Italic_IV25                               Special     Regular                       22 x 47   40 %
    Italic_IV25                               Special     Regular                        22 x 47   40 %
    Italic_IV25                               Special     Regular                           22 x 47   40 %
    Italic_IV25                               Special     Regular                   22 x 47   40 %
    Italic_IV25                               Special     Regular                        22 x 47   40 %
    Italic_IV25                               Special     Regular           22 x 47   40 %
    Italic_IV50                               Special     Regular                        22 x 47   40 %
    Italic_IV50                               Special     Regular                      22 x 47   40 %
    Italic_IV50                               Special     Regular                     22 x 47   40 %
    Italic_IV50                               Special     Regular                       22 x 47   40 %
    Italic_IV50                               Special     Regular                        22 x 47   40 %
    Italic_IV50                               Special     Regular                           22 x 47   40 %
    Italic_IV50                               Special     Regular                   22 x 47   40 %
    Italic_IV50                               Special     Regular                        22 x 47   40 %
    Italic_IV50                               Special     Regular           22 x 47   40 %
    Italic                                    Special     Regular                        22 x 47   40 %
    Italic                                    Special     Regular                      22 x 47   40 %
    Italic                                    Special     Regular                     22 x 47   40 %
    Italic                                    Special     Regular                       22 x 47   40 %
    Italic                                    Special     Regular                        22 x 47   40 %
    Italic                                    Special     Regular                           22 x 47   40 %
    Italic                                    Special     Regular                   22 x 47   40 %
    Italic                                    Special     Regular                        22 x 47   40 %
    Italic                                    Special     Regular           22 x 47   40 %
    ItalicC                                   Special     Regular                        22 x 45   40 %
    ItalicC                                   Special     Regular                      22 x 45   40 %
    ItalicC                                   Special     Regular                     22 x 45   40 %
    ItalicC                                   Special     Regular                       22 x 45   40 %
    ItalicC                                   Special     Regular                        22 x 45   40 %
    ItalicC                                   Special     Regular                           22 x 45   40 %
    ItalicC                                   Special     Regular                   22 x 45   40 %
    ItalicC                                   Special     Regular                        22 x 45   40 %
    ItalicC                                   Special     Regular           22 x 45   40 %
    ItalicT                                   Special     Regular                        22 x 48   40 %
    ItalicT                                   Special     Regular                      22 x 48   40 %
    ItalicT                                   Special     Regular                     22 x 48   40 %
    ItalicT                                   Special     Regular                       22 x 48   40 %
    ItalicT                                   Special     Regular                        22 x 48   40 %
    ItalicT                                   Special     Regular                           22 x 48   40 %
    ItalicT                                   Special     Regular                   22 x 48   40 %
    ItalicT                                   Special     Regular                        22 x 48   40 %
    ItalicT                                   Special     Regular           22 x 48   40 %
    JasmineUPC                                Roman       Regular                         9 x 34   40 %
    JasmineUPC                                Roman       Regular                          9 x 34   40 %
    Javanese Text                             Special     Regular                        26 x 73   40 %
    Jokerman                                  Decorative                          16 x 48   40 %
    Juice ITC                                 Decorative                           9 x 36   40 %
    KaiTi                                     Modern                              16 x 32   40 %
    KaiTi                                     Modern               (2312)        16 x 32   40 %
    Kalinga                                   Swiss                               19 x 48   40 %
    Kartika                                   Roman                               27 x 46   40 %
    Khmer UI                                  Swiss                               21 x 36   40 %
    KodchiangUPC                              Roman       Regular                         9 x 31   40 %
    KodchiangUPC                              Roman       Regular                          9 x 31   40 %
    Kokila                                    Swiss                               13 x 37   40 %
    Kristen ITC                               Script                              16 x 44   40 %
    Kunstler Script                           Script                               8 x 35   40 %
    Lao UI                                    Swiss                               18 x 43   40 %
    Latha                                     Swiss                               23 x 44   40 %
    Leelawadee UI Semilight                   Swiss                            17 x 43   35 %
    Leelawadee UI Semilight                   Swiss                               17 x 43   35 %
    Leelawadee UI Semilight                   Swiss                                17 x 43   35 %
    Leelawadee UI                             Swiss                            17 x 43   40 %
    Leelawadee UI                             Swiss                               17 x 43   40 %
    Leelawadee UI                             Swiss                                17 x 43   40 %
    Leelawadee                                Swiss                               17 x 38   40 %
    Leelawadee                                Swiss                                17 x 38   40 %
    Levenim MT                                Special     Regular                        16 x 42   40 %
    Levenim MT                                Special     Regular                           16 x 42   40 %
    LilyUPC                                   Swiss                                9 x 30   40 %
    LilyUPC                                   Swiss                                 9 x 30   40 %
    Lucida Bright                             Roman       Regular                        16 x 36   40 %
    Lucida Calligraphy                        Script      Italic                         17 x 40   40 %
    Lucida Console                            Modern                             19 x 32   40 %
    Lucida Console                            Modern                              19 x 32   40 %
    Lucida Console                            Modern                         19 x 32   40 %
    Lucida Console                            Modern                              19 x 32   40 %
    Lucida Console                            Modern                 19 x 32   40 %
    Lucida Fax                                Roman       Regular                        16 x 37   40 %
    Lucida Handwriting                        Script      Italic                         18 x 41   40 %
    Lucida Sans Typewriter                    Modern      Regular                        19 x 36   40 %
    Lucida Sans Unicode                       Swiss                             16 x 49   40 %
    Lucida Sans Unicode                       Swiss                              16 x 49   40 %
    Lucida Sans Unicode                       Swiss                               16 x 49   40 %
    Lucida Sans Unicode                       Swiss                                  16 x 49   40 %
    Lucida Sans Unicode                       Swiss                          16 x 49   40 %
    Lucida Sans Unicode                       Swiss                               16 x 49   40 %
    Lucida Sans Unicode                       Swiss                  16 x 49   40 %
    Lucida Sans                               Swiss       Regular                        16 x 36   40 %
    Magneto                                   Decorative                       18 x 39   70 %
    Maiandra GD                               Swiss                               14 x 38   40 %
    Malgun Gothic                             Swiss       Regular                        15 x 43   40 %
    Malgun Gothic                             Swiss       Regular                         15 x 43   40 %
    Mangal                                    Roman                               19 x 54   40 %
    Marlett                                   Special     Regular                      31 x 32   50 %
    Matura MT Script Capitals                 Script                              14 x 43   40 %
    Meiryo UI                                 Swiss                             17 x 41   40 %
    Meiryo UI                                 Swiss                              17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo UI                                 Swiss                          17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo UI                                 Swiss                  17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo                                    Swiss                             31 x 48   40 %
    Meiryo                                    Swiss                              31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Meiryo                                    Swiss                          31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Meiryo                                    Swiss                  31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Microsoft Himalaya                        Special     Regular                        13 x 32   40 %
    Microsoft JhengHei Light                  Swiss       Regular                      32 x 43   29 %
    Microsoft JhengHei Light                  Swiss       Regular                     32 x 43   29 %
    Microsoft JhengHei Light                  Swiss       Regular                       32 x 43   29 %
    Microsoft JhengHei Light                  Swiss       Regular                        32 x 43   29 %
    Microsoft JhengHei Light                  Swiss       Regular                           32 x 43   29 %
    Microsoft JhengHei Light                  Swiss       Regular                   32 x 43   29 %
    Microsoft JhengHei Light                  Swiss       Regular         (2312)        32 x 43   29 %
    Microsoft JhengHei Light                  Swiss       Regular         (BIG5)        32 x 43   29 %
    Microsoft JhengHei Light                  Swiss       Regular                        32 x 43   29 %
    Microsoft JhengHei Light                  Swiss       Regular         (Johab)         32 x 43   29 %
    Microsoft JhengHei Light                  Swiss       Regular                         32 x 43   29 %
    Microsoft JhengHei Light                  Swiss       Regular           32 x 43   29 %
    Microsoft JhengHei Light                  Swiss       Regular                        32 x 43   29 %
    Microsoft JhengHei UI Light               Swiss       Regular                      32 x 41   29 %
    Microsoft JhengHei UI Light               Swiss       Regular                     32 x 41   29 %
    Microsoft JhengHei UI Light               Swiss       Regular                       32 x 41   29 %
    Microsoft JhengHei UI Light               Swiss       Regular                        32 x 41   29 %
    Microsoft JhengHei UI Light               Swiss       Regular                           32 x 41   29 %
    Microsoft JhengHei UI Light               Swiss       Regular                   32 x 41   29 %
    Microsoft JhengHei UI Light               Swiss       Regular         (2312)        32 x 41   29 %
    Microsoft JhengHei UI Light               Swiss       Regular         (BIG5)        32 x 41   29 %
    Microsoft JhengHei UI Light               Swiss       Regular                        32 x 41   29 %
    Microsoft JhengHei UI Light               Swiss       Regular         (Johab)         32 x 41   29 %
    Microsoft JhengHei UI Light               Swiss       Regular                         32 x 41   29 %
    Microsoft JhengHei UI Light               Swiss       Regular           32 x 41   29 %
    Microsoft JhengHei UI Light               Swiss       Regular                        32 x 41   29 %
    Microsoft JhengHei UI                     Swiss                              15 x 41   40 %
    Microsoft JhengHei UI                     Swiss                               15 x 41   40 %
    Microsoft JhengHei UI                     Swiss                (BIG5)        15 x 41   40 %
    Microsoft JhengHei                        Swiss                              15 x 43   40 %
    Microsoft JhengHei                        Swiss                               15 x 43   40 %
    Microsoft JhengHei                        Swiss                (BIG5)        15 x 43   40 %
    Microsoft New Tai Lue                     Swiss                               19 x 42   40 %
    Microsoft PhagsPa                         Swiss                               24 x 41   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                             14 x 36   40 %
    Microsoft Sans Serif                      Swiss                            14 x 36   40 %
    Microsoft Sans Serif                      Swiss                              14 x 36   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                                  14 x 36   40 %
    Microsoft Sans Serif                      Swiss                          14 x 36   40 %
    Microsoft Sans Serif                      Swiss                                14 x 36   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                  14 x 36   40 %
    Microsoft Tai Le                          Swiss                               19 x 41   40 %
    Microsoft Uighur                          Special                             13 x 32   40 %
    Microsoft Uighur                          Special                             13 x 32   40 %
    Microsoft YaHei Light                     Swiss       Regular                       15 x 41   29 %
    Microsoft YaHei Light                     Swiss       Regular                        15 x 41   29 %
    Microsoft YaHei Light                     Swiss       Regular                   15 x 41   29 %
    Microsoft YaHei Light                     Swiss       Regular         (2312)        15 x 41   29 %
    Microsoft YaHei Light                     Swiss       Regular           15 x 41   29 %
    Microsoft YaHei UI Light                  Swiss       Regular                       15 x 42   29 %
    Microsoft YaHei UI Light                  Swiss       Regular                        15 x 42   29 %
    Microsoft YaHei UI Light                  Swiss       Regular                   15 x 42   29 %
    Microsoft YaHei UI Light                  Swiss       Regular         (2312)        15 x 42   29 %
    Microsoft YaHei UI Light                  Swiss       Regular           15 x 42   29 %
    Microsoft YaHei UI                        Swiss                              15 x 41   40 %
    Microsoft YaHei UI                        Swiss                               15 x 41   40 %
    Microsoft YaHei UI                        Swiss                          15 x 41   40 %
    Microsoft YaHei UI                        Swiss                (2312)        15 x 41   40 %
    Microsoft YaHei UI                        Swiss                               15 x 41   40 %
    Microsoft YaHei UI                        Swiss                  15 x 41   40 %
    Microsoft YaHei                           Swiss                              15 x 42   40 %
    Microsoft YaHei                           Swiss                               15 x 42   40 %
    Microsoft YaHei                           Swiss                          15 x 42   40 %
    Microsoft YaHei                           Swiss                (2312)        15 x 42   40 %
    Microsoft YaHei                           Swiss                               15 x 42   40 %
    Microsoft YaHei                           Swiss                  15 x 42   40 %
    Microsoft Yi Baiti                        Script                              21 x 32   40 %
    MingLiU_HKSCS                             Roman       Regular                        16 x 32   40 %
    MingLiU_HKSCS                             Roman       Regular         (BIG5)        16 x 32   40 %
    MingLiU_HKSCS-ExtB                        Roman       Regular                        16 x 32   40 %
    MingLiU_HKSCS-ExtB                        Roman       Regular         (BIG5)        16 x 32   40 %
    MingLiU                                   Modern      Regular                        16 x 32   40 %
    MingLiU                                   Modern      Regular         (BIG5)        16 x 32   40 %
    MingLiU-ExtB                              Roman       Regular                        16 x 32   40 %
    MingLiU-ExtB                              Roman       Regular         (BIG5)        16 x 32   40 %
    Miriam Fixed                              Modern      Regular                        19 x 32   40 %
    Miriam Fixed                              Modern      Regular                           19 x 32   40 %
    Miriam                                    Swiss       Regular                        13 x 32   40 %
    Miriam                                    Swiss       Regular                           13 x 32   40 %
    Mistral                                   Script                            10 x 39   40 %
    Mistral                                   Script                             10 x 39   40 %
    Mistral                                   Script                              10 x 39   40 %
    Mistral                                   Script                         10 x 39   40 %
    Mistral                                   Script                              10 x 39   40 %
    Mistral                                   Script                 10 x 39   40 %
    Modern No. 20                             Roman                               13 x 33   40 %
    Modern                                    Modern                     OEM/DOS                 19 x 37   40 %
    Mongolian Baiti                           Script                              14 x 34   40 %
    Monospac821 BT                            Modern      Roman                         19 x 38   40 %
    Monospac821 BT                            Modern      Roman                          19 x 38   40 %
    Monospac821 BT                            Modern      Roman                          19 x 38   40 %
    Monospac821 BT                            Modern      Roman                          19 x 38   40 %
    Monospac821 BT                            Modern      Roman             19 x 38   40 %
    Monotxt_IV25                              Special     Regular                        23 x 40   40 %
    Monotxt_IV25                              Special     Regular                      23 x 40   40 %
    Monotxt_IV25                              Special     Regular                     23 x 40   40 %
    Monotxt_IV25                              Special     Regular                       23 x 40   40 %
    Monotxt_IV25                              Special     Regular                        23 x 40   40 %
    Monotxt_IV25                              Special     Regular                           23 x 40   40 %
    Monotxt_IV25                              Special     Regular                   23 x 40   40 %
    Monotxt_IV25                              Special     Regular                        23 x 40   40 %
    Monotxt_IV25                              Special     Regular           23 x 40   40 %
    Monotxt_IV50                              Special     Regular                        23 x 40   40 %
    Monotxt_IV50                              Special     Regular                      23 x 40   40 %
    Monotxt_IV50                              Special     Regular                     23 x 40   40 %
    Monotxt_IV50                              Special     Regular                       23 x 40   40 %
    Monotxt_IV50                              Special     Regular                        23 x 40   40 %
    Monotxt_IV50                              Special     Regular                           23 x 40   40 %
    Monotxt_IV50                              Special     Regular                   23 x 40   40 %
    Monotxt_IV50                              Special     Regular                        23 x 40   40 %
    Monotxt_IV50                              Special     Regular           23 x 40   40 %
    Monotxt                                   Special     Regular                        23 x 40   40 %
    Monotxt                                   Special     Regular                      23 x 40   40 %
    Monotxt                                   Special     Regular                     23 x 40   40 %
    Monotxt                                   Special     Regular                       23 x 40   40 %
    Monotxt                                   Special     Regular                        23 x 40   40 %
    Monotxt                                   Special     Regular                           23 x 40   40 %
    Monotxt                                   Special     Regular                   23 x 40   40 %
    Monotxt                                   Special     Regular                        23 x 40   40 %
    Monotxt                                   Special     Regular           23 x 40   40 %
    Monotype Corsiva                          Script                            11 x 35   40 %
    Monotype Corsiva                          Script                             11 x 35   40 %
    Monotype Corsiva                          Script                              11 x 35   40 %
    Monotype Corsiva                          Script                         11 x 35   40 %
    Monotype Corsiva                          Script                              11 x 35   40 %
    Monotype Corsiva                          Script                 11 x 35   40 %
    MoolBoran                                 Swiss                               13 x 43   40 %
    MS Gothic                                 Modern      Regular                      16 x 32   40 %
    MS Gothic                                 Modern      Regular                       16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Gothic                                 Modern      Regular                   16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Gothic                                 Modern      Regular           16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular                      16 x 32   40 %
    MS Mincho                                 Modern      Regular                       16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular                   16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular           16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS Outlook                                Special                           31 x 33   40 %
    MS PGothic                                Swiss       Regular                      13 x 32   40 %
    MS PGothic                                Swiss       Regular                       13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PGothic                                Swiss       Regular                   13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PGothic                                Swiss       Regular           13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular                      13 x 32   40 %
    MS PMincho                                Roman       Regular                       13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular                   13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular           13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS Reference Sans Serif                   Swiss                             16 x 39   40 %
    MS Reference Sans Serif                   Swiss                            16 x 39   40 %
    MS Reference Sans Serif                   Swiss                              16 x 39   40 %
    MS Reference Sans Serif                   Swiss                               16 x 39   40 %
    MS Reference Sans Serif                   Swiss                          16 x 39   40 %
    MS Reference Sans Serif                   Swiss                               16 x 39   40 %
    MS Reference Sans Serif                   Swiss                  16 x 39   40 %
    MS Reference Specialty                    Special                           23 x 39   40 %
    MS Sans Serif                             Swiss                                  5 x 13   40 %
    MS Serif                                  Roman                                  5 x 13   40 %
    MS UI Gothic                              Swiss       Regular                      13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                       13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                   13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MS UI Gothic                              Swiss       Regular           13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MT Extra                                  Roman       Regular                      20 x 32   40 %
    MV Boli                                   Special                             18 x 52   40 %
    Myanmar Text                              Swiss                               18 x 60   40 %
    Narkisim                                  Swiss                               12 x 32   40 %
    Narkisim                                  Swiss                                  12 x 32   40 %
    Niagara Engraved                          Decorative                           8 x 34   40 %
    Niagara Solid                             Decorative                           8 x 34   40 %
    Nirmala UI Semilight                      Swiss                               17 x 43   35 %
    Nirmala UI                                Swiss                               31 x 43   40 %
    NSimSun                                   Modern      Regular                        16 x 32   40 %
    NSimSun                                   Modern      Regular         (2312)        16 x 32   40 %
    Nyala                                     Special                           18 x 33   40 %
    Nyala                                     Special                             18 x 33   40 %
    Nyala                                     Special                             18 x 33   40 %
    Nyala                                     Special                18 x 33   40 %
    OCR A Extended                            Modern                              19 x 33   40 %
    Old English Text MT                       Script                              12 x 39   40 %
    Onyx                                      Decorative                           8 x 37   40 %
    Palace Script MT                          Script      Regular                         7 x 30   40 %
    Palatino Linotype                         Roman                             14 x 43   40 %
    Palatino Linotype                         Roman                            14 x 43   40 %
    Palatino Linotype                         Roman                              14 x 43   40 %
    Palatino Linotype                         Roman                               14 x 43   40 %
    Palatino Linotype                         Roman                          14 x 43   40 %
    Palatino Linotype                         Roman                               14 x 43   40 %
    Palatino Linotype                         Roman                  14 x 43   40 %
    PanRoman                                  Special     Regular                      13 x 32   40 %
    Papyrus                                   Script                              13 x 50   40 %
    Parchment                                 Script                               6 x 34   40 %
    Perpetua Titling MT                       Roman       Light                          19 x 38   30 %
    Perpetua                                  Roman                               12 x 37   40 %
    Plantagenet Cherokee                      Roman                               14 x 41   40 %
    Playbill                                  Decorative                           8 x 32   40 %
    PMingLiU                                  Roman       Regular                        16 x 32   40 %
    PMingLiU                                  Roman       Regular         (BIG5)        16 x 32   40 %
    PMingLiU-ExtB                             Roman       Regular                        16 x 32   40 %
    PMingLiU-ExtB                             Roman       Regular         (BIG5)        16 x 32   40 %
    Poor Richard                              Roman                               12 x 36   40 %
    Pristina                                  Script                              10 x 42   40 %
    Proxy 1                                   Special     Regular                        20 x 39   40 %
    Proxy 1                                   Special     Regular                      20 x 39   40 %
    Proxy 1                                   Special     Regular                     20 x 39   40 %
    Proxy 1                                   Special     Regular                       20 x 39   40 %
    Proxy 1                                   Special     Regular                        20 x 39   40 %
    Proxy 1                                   Special     Regular                           20 x 39   40 %
    Proxy 1                                   Special     Regular                   20 x 39   40 %
    Proxy 1                                   Special     Regular                        20 x 39   40 %
    Proxy 1                                   Special     Regular           20 x 39   40 %
    Proxy 2                                   Special     Regular                        20 x 39   40 %
    Proxy 2                                   Special     Regular                      20 x 39   40 %
    Proxy 2                                   Special     Regular                     20 x 39   40 %
    Proxy 2                                   Special     Regular                       20 x 39   40 %
    Proxy 2                                   Special     Regular                        20 x 39   40 %
    Proxy 2                                   Special     Regular                           20 x 39   40 %
    Proxy 2                                   Special     Regular                   20 x 39   40 %
    Proxy 2                                   Special     Regular                        20 x 39   40 %
    Proxy 2                                   Special     Regular           20 x 39   40 %
    Proxy 3                                   Special     Regular                        20 x 39   40 %
    Proxy 3                                   Special     Regular                      20 x 39   40 %
    Proxy 3                                   Special     Regular                     20 x 39   40 %
    Proxy 3                                   Special     Regular                       20 x 39   40 %
    Proxy 3                                   Special     Regular                        20 x 39   40 %
    Proxy 3                                   Special     Regular                           20 x 39   40 %
    Proxy 3                                   Special     Regular                   20 x 39   40 %
    Proxy 3                                   Special     Regular                        20 x 39   40 %
    Proxy 3                                   Special     Regular           20 x 39   40 %
    Proxy 4                                   Special     Regular                        20 x 39   40 %
    Proxy 4                                   Special     Regular                      20 x 39   40 %
    Proxy 4                                   Special     Regular                     20 x 39   40 %
    Proxy 4                                   Special     Regular                       20 x 39   40 %
    Proxy 4                                   Special     Regular                        20 x 39   40 %
    Proxy 4                                   Special     Regular                           20 x 39   40 %
    Proxy 4                                   Special     Regular                   20 x 39   40 %
    Proxy 4                                   Special     Regular                        20 x 39   40 %
    Proxy 4                                   Special     Regular           20 x 39   40 %
    Proxy 5                                   Special     Regular                        20 x 39   40 %
    Proxy 5                                   Special     Regular                      20 x 39   40 %
    Proxy 5                                   Special     Regular                     20 x 39   40 %
    Proxy 5                                   Special     Regular                       20 x 39   40 %
    Proxy 5                                   Special     Regular                        20 x 39   40 %
    Proxy 5                                   Special     Regular                           20 x 39   40 %
    Proxy 5                                   Special     Regular                   20 x 39   40 %
    Proxy 5                                   Special     Regular                        20 x 39   40 %
    Proxy 5                                   Special     Regular           20 x 39   40 %
    Proxy 6                                   Special     Regular                        20 x 39   40 %
    Proxy 6                                   Special     Regular                      20 x 39   40 %
    Proxy 6                                   Special     Regular                     20 x 39   40 %
    Proxy 6                                   Special     Regular                       20 x 39   40 %
    Proxy 6                                   Special     Regular                        20 x 39   40 %
    Proxy 6                                   Special     Regular                           20 x 39   40 %
    Proxy 6                                   Special     Regular                   20 x 39   40 %
    Proxy 6                                   Special     Regular                        20 x 39   40 %
    Proxy 6                                   Special     Regular           20 x 39   40 %
    Proxy 7                                   Special     Regular                        20 x 39   40 %
    Proxy 7                                   Special     Regular                      20 x 39   40 %
    Proxy 7                                   Special     Regular                     20 x 39   40 %
    Proxy 7                                   Special     Regular                       20 x 39   40 %
    Proxy 7                                   Special     Regular                        20 x 39   40 %
    Proxy 7                                   Special     Regular                           20 x 39   40 %
    Proxy 7                                   Special     Regular                   20 x 39   40 %
    Proxy 7                                   Special     Regular                        20 x 39   40 %
    Proxy 7                                   Special     Regular           20 x 39   40 %
    Proxy 8                                   Special     Regular                        20 x 39   40 %
    Proxy 8                                   Special     Regular                      20 x 39   40 %
    Proxy 8                                   Special     Regular                     20 x 39   40 %
    Proxy 8                                   Special     Regular                       20 x 39   40 %
    Proxy 8                                   Special     Regular                        20 x 39   40 %
    Proxy 8                                   Special     Regular                           20 x 39   40 %
    Proxy 8                                   Special     Regular                   20 x 39   40 %
    Proxy 8                                   Special     Regular                        20 x 39   40 %
    Proxy 8                                   Special     Regular           20 x 39   40 %
    Proxy 9                                   Special     Regular                        20 x 39   40 %
    Proxy 9                                   Special     Regular                      20 x 39   40 %
    Proxy 9                                   Special     Regular                     20 x 39   40 %
    Proxy 9                                   Special     Regular                       20 x 39   40 %
    Proxy 9                                   Special     Regular                        20 x 39   40 %
    Proxy 9                                   Special     Regular                           20 x 39   40 %
    Proxy 9                                   Special     Regular                   20 x 39   40 %
    Proxy 9                                   Special     Regular                        20 x 39   40 %
    Proxy 9                                   Special     Regular           20 x 39   40 %
    Raavi                                     Swiss                               13 x 53   40 %
    Rage Italic                               Script                              11 x 40   40 %
    Ravie                                     Decorative                          22 x 43   40 %
    Rockwell Condensed                        Roman                               11 x 38   40 %
    Rockwell Extra Bold                       Roman                               19 x 38   80 %
    Rockwell                                  Roman                               15 x 38   40 %
    Rod                                       Modern      Regular                        19 x 31   40 %
    Rod                                       Modern      Regular                           19 x 31   40 %
    Roman                                     Roman                      OEM/DOS                 22 x 37   40 %
    RomanC                                    Special     Regular                        21 x 45   40 %
    RomanC                                    Special     Regular                      21 x 45   40 %
    RomanC                                    Special     Regular                     21 x 45   40 %
    RomanC                                    Special     Regular                       21 x 45   40 %
    RomanC                                    Special     Regular                        21 x 45   40 %
    RomanC                                    Special     Regular                           21 x 45   40 %
    RomanC                                    Special     Regular                   21 x 45   40 %
    RomanC                                    Special     Regular                        21 x 45   40 %
    RomanC                                    Special     Regular           21 x 45   40 %
    RomanD                                    Special     Regular                        20 x 46   40 %
    RomanD                                    Special     Regular                      20 x 46   40 %
    RomanD                                    Special     Regular                     20 x 46   40 %
    RomanD                                    Special     Regular                       20 x 46   40 %
    RomanD                                    Special     Regular                        20 x 46   40 %
    RomanD                                    Special     Regular                           20 x 46   40 %
    RomanD                                    Special     Regular                   20 x 46   40 %
    RomanD                                    Special     Regular                        20 x 46   40 %
    RomanD                                    Special     Regular           20 x 46   40 %
    RomanS_IV25                               Special     Regular                        20 x 39   40 %
    RomanS_IV25                               Special     Regular                      20 x 39   40 %
    RomanS_IV25                               Special     Regular                     20 x 39   40 %
    RomanS_IV25                               Special     Regular                       20 x 39   40 %
    RomanS_IV25                               Special     Regular                        20 x 39   40 %
    RomanS_IV25                               Special     Regular                           20 x 39   40 %
    RomanS_IV25                               Special     Regular                   20 x 39   40 %
    RomanS_IV25                               Special     Regular                        20 x 39   40 %
    RomanS_IV25                               Special     Regular           20 x 39   40 %
    RomanS_IV50                               Special     Regular                        20 x 39   40 %
    RomanS_IV50                               Special     Regular                      20 x 39   40 %
    RomanS_IV50                               Special     Regular                     20 x 39   40 %
    RomanS_IV50                               Special     Regular                       20 x 39   40 %
    RomanS_IV50                               Special     Regular                        20 x 39   40 %
    RomanS_IV50                               Special     Regular                           20 x 39   40 %
    RomanS_IV50                               Special     Regular                   20 x 39   40 %
    RomanS_IV50                               Special     Regular                        20 x 39   40 %
    RomanS_IV50                               Special     Regular           20 x 39   40 %
    RomanS                                    Special     Regular                        20 x 39   40 %
    RomanS                                    Special     Regular                      20 x 39   40 %
    RomanS                                    Special     Regular                     20 x 39   40 %
    RomanS                                    Special     Regular                       20 x 39   40 %
    RomanS                                    Special     Regular                        20 x 39   40 %
    RomanS                                    Special     Regular                           20 x 39   40 %
    RomanS                                    Special     Regular                   20 x 39   40 %
    RomanS                                    Special     Regular                        20 x 39   40 %
    RomanS                                    Special     Regular           20 x 39   40 %
    RomanT                                    Special     Regular                        22 x 45   40 %
    RomanT                                    Special     Regular                      22 x 45   40 %
    RomanT                                    Special     Regular                     22 x 45   40 %
    RomanT                                    Special     Regular                       22 x 45   40 %
    RomanT                                    Special     Regular                        22 x 45   40 %
    RomanT                                    Special     Regular                           22 x 45   40 %
    RomanT                                    Special     Regular                   22 x 45   40 %
    RomanT                                    Special     Regular                        22 x 45   40 %
    RomanT                                    Special     Regular           22 x 45   40 %
    Romantic                                  Special     Regular                      13 x 36   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                           16 x 45   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                16 x 45   40 %
    SansSerif                                 Special     Regular                      14 x 37   40 %
    Script MT Bold                            Script      Regular                        13 x 39   70 %
    Script                                    Script                     OEM/DOS                 16 x 36   40 %
    ScriptC                                   Special     Regular                        15 x 51   40 %
    ScriptC                                   Special     Regular                      15 x 51   40 %
    ScriptC                                   Special     Regular                     15 x 51   40 %
    ScriptC                                   Special     Regular                       15 x 51   40 %
    ScriptC                                   Special     Regular                        15 x 51   40 %
    ScriptC                                   Special     Regular                           15 x 51   40 %
    ScriptC                                   Special     Regular                   15 x 51   40 %
    ScriptC                                   Special     Regular                        15 x 51   40 %
    ScriptC                                   Special     Regular           15 x 51   40 %
    ScriptS_IV25                              Special     Regular                        16 x 51   40 %
    ScriptS_IV25                              Special     Regular                      16 x 51   40 %
    ScriptS_IV25                              Special     Regular                     16 x 51   40 %
    ScriptS_IV25                              Special     Regular                       16 x 51   40 %
    ScriptS_IV25                              Special     Regular                        16 x 51   40 %
    ScriptS_IV25                              Special     Regular                           16 x 51   40 %
    ScriptS_IV25                              Special     Regular                   16 x 51   40 %
    ScriptS_IV25                              Special     Regular                        16 x 51   40 %
    ScriptS_IV25                              Special     Regular           16 x 51   40 %
    ScriptS_IV50                              Special     Regular                        16 x 51   40 %
    ScriptS_IV50                              Special     Regular                      16 x 51   40 %
    ScriptS_IV50                              Special     Regular                     16 x 51   40 %
    ScriptS_IV50                              Special     Regular                       16 x 51   40 %
    ScriptS_IV50                              Special     Regular                        16 x 51   40 %
    ScriptS_IV50                              Special     Regular                           16 x 51   40 %
    ScriptS_IV50                              Special     Regular                   16 x 51   40 %
    ScriptS_IV50                              Special     Regular                        16 x 51   40 %
    ScriptS_IV50                              Special     Regular           16 x 51   40 %
    ScriptS                                   Special     Regular                        16 x 51   40 %
    ScriptS                                   Special     Regular                      16 x 51   40 %
    ScriptS                                   Special     Regular                     16 x 51   40 %
    ScriptS                                   Special     Regular                       16 x 51   40 %
    ScriptS                                   Special     Regular                        16 x 51   40 %
    ScriptS                                   Special     Regular                           16 x 51   40 %
    ScriptS                                   Special     Regular                   16 x 51   40 %
    ScriptS                                   Special     Regular                        16 x 51   40 %
    ScriptS                                   Special     Regular           16 x 51   40 %
    Segoe Print                               Special     Regular                      21 x 56   40 %
    Segoe Print                               Special     Regular                       21 x 56   40 %
    Segoe Print                               Special     Regular                        21 x 56   40 %
    Segoe Print                               Special     Regular                   21 x 56   40 %
    Segoe Print                               Special     Regular                        21 x 56   40 %
    Segoe Print                               Special     Regular           21 x 56   40 %
    Segoe Script                              Swiss                             22 x 51   40 %
    Segoe Script                              Swiss                              22 x 51   40 %
    Segoe Script                              Swiss                               22 x 51   40 %
    Segoe Script                              Swiss                          22 x 51   40 %
    Segoe Script                              Swiss                               22 x 51   40 %
    Segoe Script                              Swiss                  22 x 51   40 %
    Segoe UI Black                            Swiss       Regular                      20 x 43   90 %
    Segoe UI Black                            Swiss       Regular                     20 x 43   90 %
    Segoe UI Black                            Swiss       Regular                       20 x 43   90 %
    Segoe UI Black                            Swiss       Regular                        20 x 43   90 %
    Segoe UI Black                            Swiss       Regular                   20 x 43   90 %
    Segoe UI Black                            Swiss       Regular                        20 x 43   90 %
    Segoe UI Black                            Swiss       Regular           20 x 43   90 %
    Segoe UI Emoji                            Swiss                               23 x 43   40 %
    Segoe UI Light                            Swiss       Regular                        17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                      17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                     17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                       17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                        17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                           17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                   17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                        17 x 43   30 %
    Segoe UI Light                            Swiss       Regular           17 x 43   30 %
    Segoe UI Semibold                         Swiss       Regular                        18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                      18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                     18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                       18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                        18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                           18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                   18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                        18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular           18 x 43   60 %
    Segoe UI Semilight                        Swiss       Regular                        17 x 43   35 %
    Segoe UI Semilight                        Swiss       Regular                      17 x 43   35 %
    Segoe UI Semilight                        Swiss       Regular                     17 x 43   35 %
    Segoe UI Semilight                        Swiss       Regular                       17 x 43   35 %
    Segoe UI Semilight                        Swiss       Regular                        17 x 43   35 %
    Segoe UI Semilight                        Swiss       Regular                           17 x 43   35 %
    Segoe UI Semilight                        Swiss       Regular                   17 x 43   35 %
    Segoe UI Semilight                        Swiss       Regular                        17 x 43   35 %
    Segoe UI Semilight                        Swiss       Regular           17 x 43   35 %
    Segoe UI Symbol                           Swiss                               23 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                             17 x 43   40 %
    Segoe UI                                  Swiss                            17 x 43   40 %
    Segoe UI                                  Swiss                              17 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                                  17 x 43   40 %
    Segoe UI                                  Swiss                          17 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                  17 x 43   40 %
    Shonar Bangla                             Swiss                               16 x 41   40 %
    Showcard Gothic                           Decorative                          18 x 40   40 %
    Shruti                                    Swiss                               14 x 54   40 %
    SimHei                                    Modern                              16 x 32   40 %
    SimHei                                    Modern               (2312)        16 x 32   40 %
    Simplex_IV25                              Special     Regular                        19 x 44   40 %
    Simplex_IV25                              Special     Regular                      19 x 44   40 %
    Simplex_IV25                              Special     Regular                     19 x 44   40 %
    Simplex_IV25                              Special     Regular                       19 x 44   40 %
    Simplex_IV25                              Special     Regular                        19 x 44   40 %
    Simplex_IV25                              Special     Regular                           19 x 44   40 %
    Simplex_IV25                              Special     Regular                   19 x 44   40 %
    Simplex_IV25                              Special     Regular                        19 x 44   40 %
    Simplex_IV25                              Special     Regular           19 x 44   40 %
    Simplex_IV50                              Special     Regular                        19 x 44   40 %
    Simplex_IV50                              Special     Regular                      19 x 44   40 %
    Simplex_IV50                              Special     Regular                     19 x 44   40 %
    Simplex_IV50                              Special     Regular                       19 x 44   40 %
    Simplex_IV50                              Special     Regular                        19 x 44   40 %
    Simplex_IV50                              Special     Regular                           19 x 44   40 %
    Simplex_IV50                              Special     Regular                   19 x 44   40 %
    Simplex_IV50                              Special     Regular                        19 x 44   40 %
    Simplex_IV50                              Special     Regular           19 x 44   40 %
    Simplex                                   Special     Regular                        19 x 44   40 %
    Simplex                                   Special     Regular                      19 x 44   40 %
    Simplex                                   Special     Regular                     19 x 44   40 %
    Simplex                                   Special     Regular                       19 x 44   40 %
    Simplex                                   Special     Regular                        19 x 44   40 %
    Simplex                                   Special     Regular                           19 x 44   40 %
    Simplex                                   Special     Regular                   19 x 44   40 %
    Simplex                                   Special     Regular                        19 x 44   40 %
    Simplex                                   Special     Regular           19 x 44   40 %
    Simplified Arabic Fixed                   Modern      Regular                        19 x 35   40 %
    Simplified Arabic Fixed                   Modern      Regular                        19 x 35   40 %
    Simplified Arabic                         Roman                               13 x 53   40 %
    Simplified Arabic                         Roman                               13 x 53   40 %
    SimSun                                    Special     Regular                        16 x 32   40 %
    SimSun                                    Special     Regular         (2312)        16 x 32   40 %
    SimSun-ExtB                               Modern                              16 x 32   40 %
    SimSun-ExtB                               Modern               (2312)        16 x 32   40 %
    Sitka Banner                              Special     Regular                      16 x 46   40 %
    Sitka Banner                              Special     Regular                     16 x 46   40 %
    Sitka Banner                              Special     Regular                       16 x 46   40 %
    Sitka Banner                              Special     Regular                        16 x 46   40 %
    Sitka Banner                              Special     Regular                   16 x 46   40 %
    Sitka Banner                              Special     Regular                        16 x 46   40 %
    Sitka Banner                              Special     Regular           16 x 46   40 %
    Sitka Display                             Special     Regular                      17 x 46   40 %
    Sitka Display                             Special     Regular                     17 x 46   40 %
    Sitka Display                             Special     Regular                       17 x 46   40 %
    Sitka Display                             Special     Regular                        17 x 46   40 %
    Sitka Display                             Special     Regular                   17 x 46   40 %
    Sitka Display                             Special     Regular                        17 x 46   40 %
    Sitka Display                             Special     Regular           17 x 46   40 %
    Sitka Heading                             Special     Regular                      17 x 46   40 %
    Sitka Heading                             Special     Regular                     17 x 46   40 %
    Sitka Heading                             Special     Regular                       17 x 46   40 %
    Sitka Heading                             Special     Regular                        17 x 46   40 %
    Sitka Heading                             Special     Regular                   17 x 46   40 %
    Sitka Heading                             Special     Regular                        17 x 46   40 %
    Sitka Heading                             Special     Regular           17 x 46   40 %
    Sitka Small                               Special     Regular                      21 x 47   40 %
    Sitka Small                               Special     Regular                     21 x 47   40 %
    Sitka Small                               Special     Regular                       21 x 47   40 %
    Sitka Small                               Special     Regular                        21 x 47   40 %
    Sitka Small                               Special     Regular                   21 x 47   40 %
    Sitka Small                               Special     Regular                        21 x 47   40 %
    Sitka Small                               Special     Regular           21 x 47   40 %
    Sitka Subheading                          Special     Regular                      18 x 46   40 %
    Sitka Subheading                          Special     Regular                     18 x 46   40 %
    Sitka Subheading                          Special     Regular                       18 x 46   40 %
    Sitka Subheading                          Special     Regular                        18 x 46   40 %
    Sitka Subheading                          Special     Regular                   18 x 46   40 %
    Sitka Subheading                          Special     Regular                        18 x 46   40 %
    Sitka Subheading                          Special     Regular           18 x 46   40 %
    Sitka Text                                Special     Regular                      19 x 46   40 %
    Sitka Text                                Special     Regular                     19 x 46   40 %
    Sitka Text                                Special     Regular                       19 x 46   40 %
    Sitka Text                                Special     Regular                        19 x 46   40 %
    Sitka Text                                Special     Regular                   19 x 46   40 %
    Sitka Text                                Special     Regular                        19 x 46   40 %
    Sitka Text                                Special     Regular           19 x 46   40 %
    Small Fonts                               Swiss                                   1 x 3   40 %
    Snap ITC                                  Decorative                          19 x 41   40 %
    Stencil                                   Decorative                          18 x 38   40 %
    Stylus BT                                 Swiss       Roman                         14 x 39   30 %
    Stylus BT                                 Swiss       Roman                          14 x 39   30 %
    Stylus BT                                 Swiss       Roman                          14 x 39   30 %
    Stylus BT                                 Swiss       Roman                          14 x 39   30 %
    Stylus BT                                 Swiss       Roman             14 x 39   30 %
    SuperFrench                               Special     Regular                      13 x 32   40 %
    Swis721 BdCnOul BT                        Decorative  Bold Outline                  13 x 39   40 %
    Swis721 BdCnOul BT                        Decorative  Bold Outline                   13 x 39   40 %
    Swis721 BdCnOul BT                        Decorative  Bold Outline                   13 x 39   40 %
    Swis721 BdCnOul BT                        Decorative  Bold Outline                   13 x 39   40 %
    Swis721 BdCnOul BT                        Decorative  Bold Outline      13 x 39   40 %
    Swis721 BdOul BT                          Decorative  Bold                          15 x 38   40 %
    Swis721 BdOul BT                          Decorative  Bold                           15 x 38   40 %
    Swis721 BdOul BT                          Decorative  Bold                           15 x 38   40 %
    Swis721 BdOul BT                          Decorative  Bold                           15 x 38   40 %
    Swis721 BdOul BT                          Decorative  Bold              15 x 38   40 %
    Swis721 Blk BT                            Swiss       Black                         18 x 38   40 %
    Swis721 Blk BT                            Swiss       Black                          18 x 38   40 %
    Swis721 Blk BT                            Swiss       Black                          18 x 38   40 %
    Swis721 Blk BT                            Swiss       Black                          18 x 38   40 %
    Swis721 Blk BT                            Swiss       Black             18 x 38   40 %
    Swis721 BlkCn BT                          Swiss       Black                         13 x 38   40 %
    Swis721 BlkCn BT                          Swiss       Black                          13 x 38   40 %
    Swis721 BlkCn BT                          Swiss       Black                          13 x 38   40 %
    Swis721 BlkCn BT                          Swiss       Black                          13 x 38   40 %
    Swis721 BlkCn BT                          Swiss       Black             13 x 38   40 %
    Swis721 BlkEx BT                          Swiss       Black                         23 x 38   40 %
    Swis721 BlkEx BT                          Swiss       Black                          23 x 38   40 %
    Swis721 BlkEx BT                          Swiss       Black                          23 x 38   40 %
    Swis721 BlkEx BT                          Swiss       Black                          23 x 38   40 %
    Swis721 BlkEx BT                          Swiss       Black             23 x 38   40 %
    Swis721 BlkOul BT                         Decorative  Black                         18 x 38   40 %
    Swis721 BlkOul BT                         Decorative  Black                          18 x 38   40 %
    Swis721 BlkOul BT                         Decorative  Black                          18 x 38   40 %
    Swis721 BlkOul BT                         Decorative  Black                          18 x 38   40 %
    Swis721 BlkOul BT                         Decorative  Black             18 x 38   40 %
    Swis721 BT                                Swiss       Roman                         14 x 38   40 %
    Swis721 BT                                Swiss       Roman                          14 x 38   40 %
    Swis721 BT                                Swiss       Roman                          14 x 38   40 %
    Swis721 BT                                Swiss       Roman                          14 x 38   40 %
    Swis721 BT                                Swiss       Roman             14 x 38   40 %
    Swis721 Cn BT                             Swiss       Roman                         12 x 38   40 %
    Swis721 Cn BT                             Swiss       Roman                          12 x 38   40 %
    Swis721 Cn BT                             Swiss       Roman                          12 x 38   40 %
    Swis721 Cn BT                             Swiss       Roman                          12 x 38   40 %
    Swis721 Cn BT                             Swiss       Roman             12 x 38   40 %
    Swis721 Ex BT                             Swiss       Roman                         17 x 38   40 %
    Swis721 Ex BT                             Swiss       Roman                          17 x 38   40 %
    Swis721 Ex BT                             Swiss       Roman                          17 x 38   40 %
    Swis721 Ex BT                             Swiss       Roman                          17 x 38   40 %
    Swis721 Ex BT                             Swiss       Roman             17 x 38   40 %
    Swis721 Lt BT                             Swiss       Light                         14 x 38   40 %
    Swis721 Lt BT                             Swiss       Light                          14 x 38   40 %
    Swis721 Lt BT                             Swiss       Light                          14 x 38   40 %
    Swis721 Lt BT                             Swiss       Light                          14 x 38   40 %
    Swis721 Lt BT                             Swiss       Light             14 x 38   40 %
    Swis721 LtCn BT                           Swiss       Light                         11 x 38   40 %
    Swis721 LtCn BT                           Swiss       Light                          11 x 38   40 %
    Swis721 LtCn BT                           Swiss       Light                          11 x 38   40 %
    Swis721 LtCn BT                           Swiss       Light                          11 x 38   40 %
    Swis721 LtCn BT                           Swiss       Light             11 x 38   40 %
    Swis721 LtEx BT                           Swiss       Light                         16 x 38   40 %
    Swis721 LtEx BT                           Swiss       Light                          16 x 38   40 %
    Swis721 LtEx BT                           Swiss       Light                          16 x 38   40 %
    Swis721 LtEx BT                           Swiss       Light                          16 x 38   40 %
    Swis721 LtEx BT                           Swiss       Light             16 x 38   40 %
    Syastro_IV25                              Special     Regular                        24 x 37   40 %
    Syastro_IV25                              Special     Regular                      24 x 37   40 %
    Syastro_IV25                              Special     Regular                     24 x 37   40 %
    Syastro_IV25                              Special     Regular                       24 x 37   40 %
    Syastro_IV25                              Special     Regular                        24 x 37   40 %
    Syastro_IV25                              Special     Regular                           24 x 37   40 %
    Syastro_IV25                              Special     Regular                   24 x 37   40 %
    Syastro_IV25                              Special     Regular                        24 x 37   40 %
    Syastro_IV25                              Special     Regular           24 x 37   40 %
    Syastro_IV50                              Special     Regular                        24 x 37   40 %
    Syastro_IV50                              Special     Regular                      24 x 37   40 %
    Syastro_IV50                              Special     Regular                     24 x 37   40 %
    Syastro_IV50                              Special     Regular                       24 x 37   40 %
    Syastro_IV50                              Special     Regular                        24 x 37   40 %
    Syastro_IV50                              Special     Regular                           24 x 37   40 %
    Syastro_IV50                              Special     Regular                   24 x 37   40 %
    Syastro_IV50                              Special     Regular                        24 x 37   40 %
    Syastro_IV50                              Special     Regular           24 x 37   40 %
    Syastro                                   Special     Regular                        24 x 37   40 %
    Syastro                                   Special     Regular                      24 x 37   40 %
    Syastro                                   Special     Regular                     24 x 37   40 %
    Syastro                                   Special     Regular                       24 x 37   40 %
    Syastro                                   Special     Regular                        24 x 37   40 %
    Syastro                                   Special     Regular                           24 x 37   40 %
    Syastro                                   Special     Regular                   24 x 37   40 %
    Syastro                                   Special     Regular                        24 x 37   40 %
    Syastro                                   Special     Regular           24 x 37   40 %
    Sylfaen                                   Roman                             13 x 42   40 %
    Sylfaen                                   Roman                              13 x 42   40 %
    Sylfaen                                   Roman                               13 x 42   40 %
    Sylfaen                                   Roman                          13 x 42   40 %
    Sylfaen                                   Roman                               13 x 42   40 %
    Sylfaen                                   Roman                  13 x 42   40 %
    Symap_IV25                                Special     Regular                        28 x 91   40 %
    Symap_IV25                                Special     Regular                      28 x 91   40 %
    Symap_IV25                                Special     Regular                     28 x 91   40 %
    Symap_IV25                                Special     Regular                       28 x 91   40 %
    Symap_IV25                                Special     Regular                        28 x 91   40 %
    Symap_IV25                                Special     Regular                           28 x 91   40 %
    Symap_IV25                                Special     Regular                   28 x 91   40 %
    Symap_IV25                                Special     Regular                        28 x 91   40 %
    Symap_IV25                                Special     Regular           28 x 91   40 %
    Symap_IV50                                Special     Regular                        28 x 91   40 %
    Symap_IV50                                Special     Regular                      28 x 91   40 %
    Symap_IV50                                Special     Regular                     28 x 91   40 %
    Symap_IV50                                Special     Regular                       28 x 91   40 %
    Symap_IV50                                Special     Regular                        28 x 91   40 %
    Symap_IV50                                Special     Regular                           28 x 91   40 %
    Symap_IV50                                Special     Regular                   28 x 91   40 %
    Symap_IV50                                Special     Regular                        28 x 91   40 %
    Symap_IV50                                Special     Regular           28 x 91   40 %
    Symap                                     Special     Regular                        28 x 91   40 %
    Symap                                     Special     Regular                      28 x 91   40 %
    Symap                                     Special     Regular                     28 x 91   40 %
    Symap                                     Special     Regular                       28 x 91   40 %
    Symap                                     Special     Regular                        28 x 91   40 %
    Symap                                     Special     Regular                           28 x 91   40 %
    Symap                                     Special     Regular                   28 x 91   40 %
    Symap                                     Special     Regular                        28 x 91   40 %
    Symap                                     Special     Regular           28 x 91   40 %
    Symath_IV25                               Special     Regular                        26 x 98   40 %
    Symath_IV25                               Special     Regular                      26 x 98   40 %
    Symath_IV25                               Special     Regular                     26 x 98   40 %
    Symath_IV25                               Special     Regular                       26 x 98   40 %
    Symath_IV25                               Special     Regular                        26 x 98   40 %
    Symath_IV25                               Special     Regular                           26 x 98   40 %
    Symath_IV25                               Special     Regular                   26 x 98   40 %
    Symath_IV25                               Special     Regular                        26 x 98   40 %
    Symath_IV25                               Special     Regular           26 x 98   40 %
    Symath_IV50                               Special     Regular                        26 x 98   40 %
    Symath_IV50                               Special     Regular                      26 x 98   40 %
    Symath_IV50                               Special     Regular                     26 x 98   40 %
    Symath_IV50                               Special     Regular                       26 x 98   40 %
    Symath_IV50                               Special     Regular                        26 x 98   40 %
    Symath_IV50                               Special     Regular                           26 x 98   40 %
    Symath_IV50                               Special     Regular                   26 x 98   40 %
    Symath_IV50                               Special     Regular                        26 x 98   40 %
    Symath_IV50                               Special     Regular           26 x 98   40 %
    Symath                                    Special     Regular                        26 x 98   40 %
    Symath                                    Special     Regular                      26 x 98   40 %
    Symath                                    Special     Regular                     26 x 98   40 %
    Symath                                    Special     Regular                       26 x 98   40 %
    Symath                                    Special     Regular                        26 x 98   40 %
    Symath                                    Special     Regular                           26 x 98   40 %
    Symath                                    Special     Regular                   26 x 98   40 %
    Symath                                    Special     Regular                        26 x 98   40 %
    Symath                                    Special     Regular           26 x 98   40 %
    Symbol                                    Roman                             19 x 39   40 %
    Symeteo_IV25                              Special     Regular                        17 x 45   40 %
    Symeteo_IV25                              Special     Regular                      17 x 45   40 %
    Symeteo_IV25                              Special     Regular                     17 x 45   40 %
    Symeteo_IV25                              Special     Regular                       17 x 45   40 %
    Symeteo_IV25                              Special     Regular                        17 x 45   40 %
    Symeteo_IV25                              Special     Regular                           17 x 45   40 %
    Symeteo_IV25                              Special     Regular                   17 x 45   40 %
    Symeteo_IV25                              Special     Regular                        17 x 45   40 %
    Symeteo_IV25                              Special     Regular           17 x 45   40 %
    Symeteo_IV50                              Special     Regular                        17 x 45   40 %
    Symeteo_IV50                              Special     Regular                      17 x 45   40 %
    Symeteo_IV50                              Special     Regular                     17 x 45   40 %
    Symeteo_IV50                              Special     Regular                       17 x 45   40 %
    Symeteo_IV50                              Special     Regular                        17 x 45   40 %
    Symeteo_IV50                              Special     Regular                           17 x 45   40 %
    Symeteo_IV50                              Special     Regular                   17 x 45   40 %
    Symeteo_IV50                              Special     Regular                        17 x 45   40 %
    Symeteo_IV50                              Special     Regular           17 x 45   40 %
    Symeteo                                   Special     Regular                        17 x 45   40 %
    Symeteo                                   Special     Regular                      17 x 45   40 %
    Symeteo                                   Special     Regular                     17 x 45   40 %
    Symeteo                                   Special     Regular                       17 x 45   40 %
    Symeteo                                   Special     Regular                        17 x 45   40 %
    Symeteo                                   Special     Regular                           17 x 45   40 %
    Symeteo                                   Special     Regular                   17 x 45   40 %
    Symeteo                                   Special     Regular                        17 x 45   40 %
    Symeteo                                   Special     Regular           17 x 45   40 %
    Symusic_IV25                              Special     Regular                        23 x 69   40 %
    Symusic_IV25                              Special     Regular                      23 x 69   40 %
    Symusic_IV25                              Special     Regular                     23 x 69   40 %
    Symusic_IV25                              Special     Regular                       23 x 69   40 %
    Symusic_IV25                              Special     Regular                        23 x 69   40 %
    Symusic_IV25                              Special     Regular                           23 x 69   40 %
    Symusic_IV25                              Special     Regular                   23 x 69   40 %
    Symusic_IV25                              Special     Regular                        23 x 69   40 %
    Symusic_IV25                              Special     Regular           23 x 69   40 %
    Symusic_IV50                              Special     Regular                        23 x 69   40 %
    Symusic_IV50                              Special     Regular                      23 x 69   40 %
    Symusic_IV50                              Special     Regular                     23 x 69   40 %
    Symusic_IV50                              Special     Regular                       23 x 69   40 %
    Symusic_IV50                              Special     Regular                        23 x 69   40 %
    Symusic_IV50                              Special     Regular                           23 x 69   40 %
    Symusic_IV50                              Special     Regular                   23 x 69   40 %
    Symusic_IV50                              Special     Regular                        23 x 69   40 %
    Symusic_IV50                              Special     Regular           23 x 69   40 %
    Symusic                                   Special     Regular                        23 x 69   40 %
    Symusic                                   Special     Regular                      23 x 69   40 %
    Symusic                                   Special     Regular                     23 x 69   40 %
    Symusic                                   Special     Regular                       23 x 69   40 %
    Symusic                                   Special     Regular                        23 x 69   40 %
    Symusic                                   Special     Regular                           23 x 69   40 %
    Symusic                                   Special     Regular                   23 x 69   40 %
    Symusic                                   Special     Regular                        23 x 69   40 %
    Symusic                                   Special     Regular           23 x 69   40 %
    System                                    Swiss                                  7 x 16   70 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                             14 x 39   40 %
    Tahoma                                    Swiss                            14 x 39   40 %
    Tahoma                                    Swiss                              14 x 39   40 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                                  14 x 39   40 %
    Tahoma                                    Swiss                          14 x 39   40 %
    Tahoma                                    Swiss                                14 x 39   40 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                  14 x 39   40 %
    Technic                                   Special     Regular                      15 x 34   40 %
    TechnicBold                               Special     Regular                      15 x 35   40 %
    TechnicLite                               Special     Regular                      15 x 34   40 %
    Tempus Sans ITC                           Decorative                          13 x 42   40 %
    Terminal                                  Modern                     OEM/DOS                  8 x 12   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                             13 x 35   40 %
    Times New Roman                           Roman                            13 x 35   40 %
    Times New Roman                           Roman                              13 x 35   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                                  13 x 35   40 %
    Times New Roman                           Roman                          13 x 35   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                  13 x 35   40 %
    Traditional Arabic                        Roman                               15 x 48   40 %
    Traditional Arabic                        Roman                               15 x 48   40 %
    Trebuchet MS                              Swiss                             15 x 37   40 %
    Trebuchet MS                              Swiss                              15 x 37   40 %
    Trebuchet MS                              Swiss                               15 x 37   40 %
    Trebuchet MS                              Swiss                          15 x 37   40 %
    Trebuchet MS                              Swiss                               15 x 37   40 %
    Trebuchet MS                              Swiss                  15 x 37   40 %
    Tunga                                     Swiss                               18 x 53   40 %
    Tw Cen MT Condensed Extra Bold            Swiss                               12 x 35   40 %
    Tw Cen MT Condensed Extra Bold            Swiss                  12 x 35   40 %
    Tw Cen MT Condensed                       Swiss                               10 x 34   40 %
    Tw Cen MT Condensed                       Swiss                  10 x 34   40 %
    Tw Cen MT                                 Swiss                               13 x 35   40 %
    Tw Cen MT                                 Swiss                  13 x 35   40 %
    Txt_IV25                                  Special     Regular                        22 x 40   40 %
    Txt_IV25                                  Special     Regular                      22 x 40   40 %
    Txt_IV25                                  Special     Regular                     22 x 40   40 %
    Txt_IV25                                  Special     Regular                       22 x 40   40 %
    Txt_IV25                                  Special     Regular                        22 x 40   40 %
    Txt_IV25                                  Special     Regular                           22 x 40   40 %
    Txt_IV25                                  Special     Regular                   22 x 40   40 %
    Txt_IV25                                  Special     Regular                        22 x 40   40 %
    Txt_IV25                                  Special     Regular           22 x 40   40 %
    Txt_IV50                                  Special     Regular                        22 x 40   40 %
    Txt_IV50                                  Special     Regular                      22 x 40   40 %
    Txt_IV50                                  Special     Regular                     22 x 40   40 %
    Txt_IV50                                  Special     Regular                       22 x 40   40 %
    Txt_IV50                                  Special     Regular                        22 x 40   40 %
    Txt_IV50                                  Special     Regular                           22 x 40   40 %
    Txt_IV50                                  Special     Regular                   22 x 40   40 %
    Txt_IV50                                  Special     Regular                        22 x 40   40 %
    Txt_IV50                                  Special     Regular           22 x 40   40 %
    Txt                                       Special     Regular                        22 x 40   40 %
    Txt                                       Special     Regular                      22 x 40   40 %
    Txt                                       Special     Regular                     22 x 40   40 %
    Txt                                       Special     Regular                       22 x 40   40 %
    Txt                                       Special     Regular                        22 x 40   40 %
    Txt                                       Special     Regular                           22 x 40   40 %
    Txt                                       Special     Regular                   22 x 40   40 %
    Txt                                       Special     Regular                        22 x 40   40 %
    Txt                                       Special     Regular           22 x 40   40 %
    UniversalMath1 BT                         Roman       Regular                      15 x 34   40 %
    Urdu Typesetting                          Script                              13 x 55   40 %
    Urdu Typesetting                          Script                              13 x 55   40 %
    Utsaah                                    Swiss                               13 x 36   40 %
    Vani                                      Swiss                               23 x 54   40 %
    Verdana                                   Swiss                             16 x 39   40 %
    Verdana                                   Swiss                            16 x 39   40 %
    Verdana                                   Swiss                              16 x 39   40 %
    Verdana                                   Swiss                               16 x 39   40 %
    Verdana                                   Swiss                          16 x 39   40 %
    Verdana                                   Swiss                               16 x 39   40 %
    Verdana                                   Swiss                  16 x 39   40 %
    Vijaya                                    Swiss                               19 x 32   40 %
    Viner Hand ITC                            Script                              15 x 52   40 %
    Vineta BT                                 Decorative  Regular                       25 x 43   40 %
    Vineta BT                                 Decorative  Regular                        25 x 43   40 %
    Vineta BT                                 Decorative  Regular                        25 x 43   40 %
    Vineta BT                                 Decorative  Regular                        25 x 43   40 %
    Vineta BT                                 Decorative  Regular           25 x 43   40 %
    Vivaldi                                   Script                                9 x 38   40 %
    Vladimir Script                           Script                              10 x 39   40 %
    Vrinda                                    Swiss                               20 x 44   40 %
    Webdings                                  Roman                             31 x 32   40 %
    Wide Latin                                Roman                               26 x 39   40 %
    Wingdings 2                               Roman       Regular                      27 x 34   40 %
    Wingdings 3                               Roman       Regular                      25 x 36   40 %
    Wingdings                                 Special     Regular                      28 x 36   40 %
    Yu Gothic Light                           Swiss       Regular                      31 x 41   30 %
    Yu Gothic Light                           Swiss       Regular                       31 x 41   30 %
    Yu Gothic Light                           Swiss       Regular                        31 x 41   30 %
    Yu Gothic Light                           Swiss       Regular                   31 x 41   30 %
    Yu Gothic Light                           Swiss       Regular                        31 x 41   30 %
    Yu Gothic Light                           Swiss       Regular           31 x 41   30 %
    Yu Gothic Light                           Swiss       Regular                        31 x 41   30 %
    Yu Gothic                                 Swiss       Regular                      31 x 41   40 %
    Yu Gothic                                 Swiss       Regular                       31 x 41   40 %
    Yu Gothic                                 Swiss       Regular                        31 x 41   40 %
    Yu Gothic                                 Swiss       Regular                   31 x 41   40 %
    Yu Gothic                                 Swiss       Regular                        31 x 41   40 %
    Yu Gothic                                 Swiss       Regular           31 x 41   40 %
    Yu Gothic                                 Swiss       Regular                        31 x 41   40 %
    Yu Mincho Demibold                        Roman       Bold                         31 x 41   60 %
    Yu Mincho Demibold                        Roman       Bold                          31 x 41   60 %
    Yu Mincho Demibold                        Roman       Bold                           31 x 41   60 %
    Yu Mincho Demibold                        Roman       Bold                      31 x 41   60 %
    Yu Mincho Demibold                        Roman       Bold                           31 x 41   60 %
    Yu Mincho Demibold                        Roman       Bold              31 x 41   60 %
    Yu Mincho Demibold                        Roman       Bold                           31 x 41   60 %
    Yu Mincho Light                           Roman       Regular                      31 x 41   30 %
    Yu Mincho Light                           Roman       Regular                       31 x 41   30 %
    Yu Mincho Light                           Roman       Regular                        31 x 41   30 %
    Yu Mincho Light                           Roman       Regular                   31 x 41   30 %
    Yu Mincho Light                           Roman       Regular                        31 x 41   30 %
    Yu Mincho Light                           Roman       Regular           31 x 41   30 %
    Yu Mincho Light                           Roman       Regular                        31 x 41   30 %
    Yu Mincho                                 Roman       Regular                      31 x 41   40 %
    Yu Mincho                                 Roman       Regular                       31 x 41   40 %
    Yu Mincho                                 Roman       Regular                        31 x 41   40 %
    Yu Mincho                                 Roman       Regular                   31 x 41   40 %
    Yu Mincho                                 Roman       Regular                        31 x 41   40 %
    Yu Mincho                                 Roman       Regular           31 x 41   40 %
    Yu Mincho                                 Roman       Regular                        31 x 41   40 %


--------[  Windows ]-----------------------------------------------------------------------------------------------

    midi-out.0   0001 001B  Microsoft GS Wavetable Synth
    mixer.0      0001 FFFF   (2-   
    mixer.1      0001 FFFF   (2-   
    wave-in.0    0001 FFFF   (2-   
    wave-out.0   0001 FFFF   (2-   


--------[  PCI / PnP ]---------------------------------------------------------------------------------------------

    ATI Radeon HDMI @ AMD K12 - High Definition Audio Controller                      PCI
    Conexant Cx20585 @ AMD Hudson-2 FCH - High Definition Audio Controller            PCI


--------[ HD Audio ]----------------------------------------------------------------------------------------------------

  [ AMD Hudson-2 FCH - High Definition Audio Controller ]

     :
                                      AMD Hudson-2 FCH - High Definition Audio Controller
        (Windows)                      High Definition Audio (Microsoft)
                                                 PCI
       /  /                        0 / 20 / 2
      ID                                      1022-780D
                               1179-FC50
                                                  01
       ID                                     PCI\VEN_1022&DEV_780D&SUBSYS_FC501179&REV_01

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/chipsets
                                       http://support.amd.com
       BIOS                                 http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [ Conexant Cx20585 ]

     :
                                      Conexant Cx20585
        (Windows)                        High Definition Audio
                                           Audio
                                                 HDAUDIO
      ID                                      14F1-5069
                               1179-FC50
                                                  1003
       ID                                     HDAUDIO\FUNC_01&VEN_14F1&DEV_5069&SUBSYS_1179FC50&REV_1003

  [ AMD K12 - High Definition Audio Controller ]

     :
                                      AMD K12 - High Definition Audio Controller
        (Windows)                      High Definition Audio (Microsoft)
                                                 PCI
       /  /                        0 / 1 / 1
      ID                                      1002-1714
                               1002-1714
                                                  00
       ID                                     PCI\VEN_1002&DEV_1714&SUBSYS_17141002&REV_00

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/chipsets
                                       http://support.amd.com
       BIOS                                 http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [ ATI Radeon HDMI ]

     :
                                      ATI Radeon HDMI
        (Windows)                     AMD High Definition Audio Device
                                           Audio
                                                 HDAUDIO
      ID                                      1002-AA01
                               00AA-0100
                                                  1002
       ID                                     HDAUDIO\FUNC_01&VEN_1002&DEV_AA01&SUBSYS_00AA0100&REV_1002

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/chipsets
                                       http://support.amd.com
                                     http://www.aida64.com/driver-updates


--------[   ]------------------------------------------------------------------------------------------------

  [ Fraunhofer IIS MPEG Layer-3 Codec (decode only) ]

      ACM:
                                        Fraunhofer IIS MPEG Layer-3 Codec (decode only)
      Copyright-                                  Copyright  1996-1999 Fraunhofer Institut Integrierte Schaltungen IIS
                                         decoder only version
                                          1.09

  [  ADPCM (Microsoft) ]

      ACM:
                                         ADPCM (Microsoft)
      Copyright-                                    , 1992-1996.
                                             Microsoft ADPCM.
                                          4.00

  [  CCITT G.711 A-Law  u-Law (Microsoft) ]

      ACM:
                                         CCITT G.711 A-Law  u-Law (Microsoft)
      Copyright-                                  ()  , 1993-1996.
                                             CCITT G.711 A-Law / u-Law.
                                          4.00

  [  GSM 6.10 (Microsoft) ]

      ACM:
                                         GSM 6.10 (Microsoft)
      Copyright-                                  ()  , 1993-1996.
                                                 ETSI-GSM (European Telecommunications Standards Institute-Groupe Special Mobile)  6.10.
                                          4.00

  [  IMA ADPCM (Microsoft) ]

      ACM:
                                         IMA ADPCM (Microsoft)
      Copyright-                                    , 1992-1996.
                                             IMA ADPCM.
                                          4.00

  [  PCM Microsoft ]

      ACM:
                                         PCM Microsoft
      Copyright-                                    , 1992-1996.
                                                PCM.
                                          5.00


--------[   ]------------------------------------------------------------------------------------------------

    iccvid.dll                 1.10.0.11                            Cinepak
    iyuv_32.dll                6.3.9600.16384 (winblue_rtm.130821-1623)  Intel Indeo(R) Video YUV 
    msrle32.dll                6.3.9600.16384 (winblue_rtm.130821-1623)  Microsoft RLE Compressor
    msvidc32.dll               6.3.9600.16384 (winblue_rtm.130821-1623)    Microsoft Video 1
    msyuv.dll                  6.3.9600.16384 (winblue_rtm.130821-1623)  Microsoft UYVY Video Decompressor
    tsbyuv.dll                 6.3.9600.16384 (winblue_rtm.130821-1623)  Toshiba Video Codec


--------[ MCI ]---------------------------------------------------------------------------------------------------------

  [ AVIVideo ]

      MCI:
                                              AVIVideo
                                                       Windows
                                                 MCI Video  Windows
                                                     Digital Video Device
                                                 mciavi32.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                 
                                                  
                                        
      ''                             
                                      
                                         
                                         
                                            
                                          
                                          
                                

  [ CDAudio ]

      MCI:
                                              CDAudio
                                                     -
                                                 MCI   cdaudio
                                                     CD Audio Device
                                                 mcicda.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                                  
                                        
                                          
                                          

  [ MPEGVideo ]

      MCI:
                                              MPEGVideo
                                                     DirectShow
                                                 MCI DirectShow
                                                     Digital Video Device
                                                 mciqtz32.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                 
                                                  
                                        
      ''                             
                                      
                                         
                                         
                                            
                                          
                                          
                                

  [ Sequencer ]

      MCI:
                                              Sequencer
                                                      MIDI
                                                 MCI   MIDI
                                                     Sequencer Device
                                                 mciseq.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                                  
                                        
                                          
                                          

  [ WaveAudio ]

      MCI:
                                              WaveAudio
                                                     Sound
                                                 MCI   
                                                     Waveform Audio Device
                                                 mciwave.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                                  
                                        
                                          
                                          


--------[ SAPI ]--------------------------------------------------------------------------------------------------------

     SAPI:
       SAPI4                                      -
       SAPI5                                      5.3.16513.0

     (SAPI5):
                                                     Microsoft Irina Desktop - Russian
                                              C:\Windows\Speech\Engines\TTS\ru-RU\M1049IRI
                                                 
                                                     
                                                     ()
                                           Microsoft
                                                  11.0
       DLL                                          C:\Windows\SysWOW64\speech\engines\tts\MSTTSEngine.dll  (x86)
      CLSID                                             {C64501F6-E6E6-451f-A150-25D0839BC510}

     (SAPI5):
                                                     Microsoft Zira Desktop - English (United States)
                                              C:\Windows\Speech\Engines\TTS\en-US\M1033ZIR
                                                 
                                                     
                                                     ()
                                           Microsoft
                                                  11.0
       DLL                                          C:\Windows\SysWOW64\speech\engines\tts\MSTTSEngine.dll  (x86)
      CLSID                                             {C64501F6-E6E6-451f-A150-25D0839BC510}


--------[   Windows ]-------------------------------------------------------------------------------------

  [ WDC WD5000BPKX-22HPJT0 ]

     :
                                        WDC WD5000BPKX-22HPJT0
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          disk.inf

       :
                                           Western Digital
                                  Scorpio Black
      -                                       2.5"
                                  500 
                                      100.2 x 69.85 x 9.5 mm
                                         115 g
                                4.2 ms
                                        7200 RPM
      .                     1280 /
                                               SATA-III
        '-'                600 /
                                             16 
                                          3.2 

     :
                                                   Western Digital Corporation
                                     http://www.wdc.com/en

  [ DTSOFT Virtual CdRom Device ]

     :
                                        DTSOFT Virtual CdRom Device
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          cdrom.inf

  [ TSSTcorp CDDVDW TS-L633F ]

     :
                                        TSSTcorp CDDVDW TS-L633F
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          cdrom.inf

     :
                                                   Toshiba Samsung Storage Technology
                                     http://www.tsstorage.com/tsst/index_e.html
                                        http://www.samsungodd.com/eng/LiveUpdate/LiveUpdate.asp

  [ AMD SATA Controller ]

     :
                                        AMD SATA Controller
                                            20.03.2014
                                          1.3.1.220
                                       AMD
      INF-                                          oem9.inf

     :
      IRQ                                               19
                                                  F034F000-F034F7FF
                                                    5100-510F
                                                    5110-5117
                                                    5118-511F
                                                    5120-5123
                                                    5124-5127

  [    () ]

     :
                                        Microsoft Storage Spaces Controller
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          spaceport.inf


--------[   ]--------------------------------------------------------------------------------------------

    C:                                               NTFS         204448       97222      107226    52 %  6E08-A449
    E:                                               NTFS         272138      211629       60509    22 %  9A56-42EB
    G:                                                                                                               
    H:                                                                                                               


--------[   ]--------------------------------------------------------------------------------------------

  [  #1 - WDC WD5000BPKX-22HPJT0 (465 ) ]

    #1 ()    NTFS                                                             1 MB      350 MB
    #2               NTFS             C:                                            351 MB   204449 MB
    #3               NTFS             E:                                         204801 MB   272139 MB


--------[   ]---------------------------------------------------------------------------------------

  [ G:\  TSSTcorp CDDVDW TS-L633F ]

      :
                                      TSSTcorp CDDVDW TS-L633F
                                           R8BO6GDB694789
                                          TF01
                                             1536 
                                              2
                               4
                                      4

      :
      BD-ROM                                             
      BD-R                                               
      BD-RE                                              
      HD DVD-ROM                                         
      HD DVD-R Dual Layer                                
      HD DVD-RW Dual Layer                               
      HD DVD-R                                           
      HD DVD-RW                                          
      HD DVD-RAM                                         
      DVD-ROM                                           
      DVD+R9 Dual Layer                                  + 
      DVD+RW9 Dual Layer                                 
      DVD+R                                              + 
      DVD+RW                                             + 
      DVD-R9 Dual Layer                                  + 
      DVD-RW9 Dual Layer                                 
      DVD-R                                              + 
      DVD-RW                                             + 
      DVD-RAM                                            + 
      CD-ROM                                            
      CD-R                                               + 
      CD-RW                                              + 

      :
      AACS                                               
      BD CPS                                             
      Buffer Underrun Protection                        
      C2 Error Pointers                                 
      CD+G                                              
      CD-Text                                           
      DVD-Download Disc Recording                        
      Hybrid Disc                                        
      JustLink                                          
      CPRM                                              
      CSS                                               
      LabelFlash                                         
      Layer-Jump Recording                               
      LightScribe                                        
      Mount Rainier                                      
      OSSC                                               
      Qflix Recording                                    
      SecurDisc                                          
      SMART                                             
      VCPS                                               

  [ H:\  DTSOFT Virtual CdRom Device ]

      :
                                      DTSOFT Virtual CdRom Device
                                          1.05
                                             128 
                                              1
                               4
                                      4

      :
      BD-ROM                                            
      BD-R                                              
      BD-RE                                             
      HD DVD-ROM                                         
      HD DVD-R Dual Layer                                
      HD DVD-RW Dual Layer                               
      HD DVD-R                                           
      HD DVD-RW                                          
      HD DVD-RAM                                         
      DVD-ROM                                           
      DVD+R9 Dual Layer                                 
      DVD+RW9 Dual Layer                                
      DVD+R                                             
      DVD+RW                                            
      DVD-R9 Dual Layer                                 
      DVD-RW9 Dual Layer                                 
      DVD-R                                             
      DVD-RW                                            
      DVD-RAM                                            
      CD-ROM                                            
      CD-R                                              
      CD-RW                                             

      :
      AACS                                               
      BD CPS                                             
      Buffer Underrun Protection                         
      C2 Error Pointers                                 
      CD+G                                              
      CD-Text                                           
      DVD-Download Disc Recording                        
      Hybrid Disc                                        
      JustLink                                           
      CPRM                                               
      CSS                                                
      LabelFlash                                         
      Layer-Jump Recording                               
      LightScribe                                        
      Mount Rainier                                      
      OSSC                                               
      Qflix Recording                                    
      SecurDisc                                          
      SMART                                              
      VCPS                                               


--------[ ASPI ]--------------------------------------------------------------------------------------------------------

    00  00  00         WDC       WD5000BPKX-22HPJ  01.0  
    00  00  00       TSSTcorp  CDDVDW TS-L633F   TF01  
    00  07  00  -             amd_sata                          


--------[ ATA ]---------------------------------------------------------------------------------------------------------

  [ WDC WD5000BPKX-22HPJT0 (WD-WXH1E93WLD88) ]

      ATA:
      ID                                          WDC WD5000BPKX-22HPJT0
                                           WD-WXH1E93WLD88
                                                  01.01A01
      World Wide Name                                   5-0014EE-659615D7F
                                           SATA-III
                                               : 969021, : 16,   : 63,   : 512
       LBA                                       976773168
       /             4  / 512 
                                                   16 
                                           16
      .  PIO                                   PIO 4
      .  MWDMA                                 MWDMA 2
      .  UDMA                                  UDMA 6
        UDMA                               UDMA 6
                                476940 
                                        7200 RPM
       ATA                                      ATA8-ACS

      ATA:
      48-bit LBA                                        , 
      Automatic Acoustic Management (AAM)                
      Device Configuration Overlay (DCO)                , 
      DMA Setup Auto-Activate                           , 
      Free-Fall Control                                  
      General Purpose Logging (GPL)                     , 
      Hardware Feature Control                           
      Host Protected Area (HPA)                         , 
      HPA Security Extensions                           , 
      Hybrid Information Feature                         
      In-Order Data Delivery                             
      Native Command Queuing (NCQ)                      
      NCQ Autosense                                      
      NCQ Priority Information                          
      NCQ Queue Management Command                       
      NCQ Streaming                                      
      Phy Event Counters                                
      Read Look-Ahead                                   , 
      Release Interrupt                                  
                                       , 
      Sense Data Reporting (SDR)                         
      Service Interrupt                                  
      SMART                                             , 
      SMART Error Logging                               , 
      SMART Self-Test                                   , 
      Software Settings Preservation (SSP)              , 
      Streaming                                          
      Tagged Command Queuing (TCQ)                       
                                               , 
      Write-Read-Verify                                  

     SSD:
      Data Set Management                                
      Deterministic Read After TRIM                      
       TRIM                                       

     :
       (APM)                            , 
      Automatic Partial to Slumber Transitions (APST)   
      Device Initiated Interface Power Management (DIPM), 
      Device Sleep (DEVSLP)                              
      Extended Power Conditions (EPC)                    
      Host Initiated Interface Power Management (HIPM)  
      IDLE IMMEDIATE With UNLOAD FEATURE                , 
      Link Power State Device Sleep                      
                                          , 
      Power-Up In Standby (PUIS)                        , 

     ATA:
      DEVICE RESET                                       
      DOWNLOAD MICROCODE                                , 
      FLUSH CACHE                                       , 
      FLUSH CACHE EXT                                   , 
      NOP                                               , 
      READ BUFFER                                       , 
      WRITE BUFFER                                      , 

       ATA:
                                           Western Digital
                                  Scorpio Black
      -                                       2.5"
                                  500 
                                      100.2 x 69.85 x 9.5 mm
                                         115 g
                                4.2 ms
                                        7200 RPM
      .                     1280 /
                                               SATA-III
        '-'                600 /
                                             16 
                                          3.2 

     ATA-:
                                                   Western Digital Corporation
                                     http://www.wdc.com/en
                                     http://www.aida64.com/driver-updates


--------[ SMART ]-------------------------------------------------------------------------------------------------------

  [ WDC WD5000BPKX-22HPJT0 (WD-WXH1E93WLD88) ]

    01  Raw Read Error Rate                  51   200  200           0  OK:  
    03  Spinup Time                          21   187  168        1641  OK:  
    04  Start/Stop Count                     0    100  100         489  OK:  
    05  Reallocated Sector Count             140  200  200           0  OK:  
    07  Seek Error Rate                      0    200  200           0  OK:  
    09  Power-On Time Count                  0    99   99         1254  OK:  
    0A  Spinup Retry Count                   0    100  100           0  OK:  
    0B  Calibration Retry Count              0    100  100           0  OK:  
    0C  Power Cycle Count                    0    100  100         429  OK:  
    C0  Power-Off Retract Count              0    200  200          28  OK:  
    C1  Load/Unload Cycle Count              0    199  199        4527  OK:  
    C2  Temperature                          0    106  99           41  OK:  
    C4  Reallocation Event Count             0    200  200           0  OK:  
    C5  Current Pending Sector Count         0    200  200           0  OK:  
    C6  Offline Uncorrectable Sector Count   0    100  253           0  OK:  
    C7  Ultra ATA CRC Error Rate             0    200  200           0  OK:  
    C8  Write Error Rate                     0    100  253           0  OK:  


--------[  Windows ]------------------------------------------------------------------------------------------------

  [ Qualcomm Atheros AR8152 PCI-E Fast Ethernet Controller (NDIS 6.30) ]

      :
                                          Qualcomm Atheros AR8152 PCI-E Fast Ethernet Controller (NDIS 6.30)
                                           Ethernet
                                         00-13-74-00-00-00
                                              Ethernet
      MTU                                               1500 
                                            0
                                          0

  [ Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC ]

      :
                                          Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC
                                           802.11 Wireless Ethernet
                                         D0-DF-9A-66-47-2C
                                               
                                      120 Mbps
      MTU                                               1500 
      DHCP-                               17.08.2014 22:59:41
      DHCP-                               18.08.2014 22:59:41
                                            52820755 (50.4 )
                                          506976351 (483.5 )

      :
      IP /                                  192.168.1.136 / 255.255.255.0
                                                    192.168.1.1
      DHCP                                              192.168.1.1
      DNS                                               192.168.1.1

      :
                                                   Realtek Semiconductor Corp.
                                     http://www.realtek.com.tw/products/productsView.aspx?Langid=1&PNid=7&PFid=10&Level=3&Conn=2
                                       http://www.realtek.com.tw/downloads
                                     http://www.aida64.com/driver-updates

  [   Wi-Fi Direct () ]

      :
                                            Wi-Fi Direct ()
                                           802.11 Wireless Ethernet
                                         D0-DF-9A-66-47-2C
                                                 * 1
      MTU                                               1500 
                                            0
                                          0


--------[  PCI / PnP ]----------------------------------------------------------------------------------------------

    Atheros AR8152/8158 PCI-E Fast Ethernet Controller                                PCI
    Realtek RTL8188CE Wireless LAN 802.11n PCI-E Network Adapter                      PCI


--------[  ]----------------------------------------------------------------------------------------------------

     :
                                        http://www.yandex.ru/?win=134&clid=1969031
                                          http://go.microsoft.com/fwlink/?LinkId=54896
                                       C:\Windows\system32\blank.htm
                               

     :
                                            

    LAN-:
                                            


--------[  ]----------------------------------------------------------------------------------------------------

                  0.0.0.0          0.0.0.0      192.168.1.1  25   192.168.1.136 (Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC)
                127.0.0.0        255.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
                127.0.0.1  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          127.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
              192.168.1.0    255.255.255.0    192.168.1.136  281  192.168.1.136 (Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC)
            192.168.1.136  255.255.255.255    192.168.1.136  281  192.168.1.136 (Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC)
            192.168.1.255  255.255.255.255    192.168.1.136  281  192.168.1.136 (Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC)
                224.0.0.0        240.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
                224.0.0.0        240.0.0.0    192.168.1.136  281  192.168.1.136 (Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC)
          255.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          255.255.255.255  255.255.255.255    192.168.1.136  281  192.168.1.136 (Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC)


--------[ IE Cookie ]---------------------------------------------------------------------------------------------------

    2014-08-12 23:09:08  black_sokol@adshost2.com/
    2014-08-14 21:38:03  black_sokol@horyzon-media.com/
    2014-08-15 17:04:01  black_sokol@server.cpmstar.com/
    2014-08-16 11:49:16  black_sokol@dailymotion.com/
    2014-08-16 11:49:16  black_sokol@www.dailymotion.com/
    2014-08-16 11:49:18  black_sokol@uslugi.tatar.ru/
    2014-08-16 11:49:19  black_sokol@www.gosuslugi.ru/
    2014-08-16 12:25:11  black_sokol@yadro.ru/
    2014-08-16 12:25:14  black_sokol@an.yandex.ru/
    2014-08-16 12:25:38  black_sokol@adnxs.com/
    2014-08-16 12:25:39  black_sokol@crwdcntrl.net/
    2014-08-16 12:27:48  black_sokol@sourceforge.net/
    2014-08-16 12:27:49  black_sokol@ml314.com/
    2014-08-16 12:27:50  black_sokol@twitter.com/
    2014-08-16 12:30:18  black_sokol@rambler.ru/
    2014-08-16 12:30:56  black_sokol@quantserve.com/
    2014-08-16 12:30:56  black_sokol@raptr.com/
    2014-08-16 12:30:56  black_sokol@scorecardresearch.com/
    2014-08-17 17:38:40  black_sokol@topdownloads.ru/
    2014-08-17 17:39:22  black_sokol@ru.wifiprotector.com/
    2014-08-17 17:39:22  black_sokol@www.fms.gov.ru/
    2014-08-17 17:39:22  black_sokol@www.wifiprotector.com/
    2014-08-17 17:39:26  black_sokol@google.com/
    2014-08-17 17:39:29  black_sokol@systemexplorer.net/
    2014-08-17 17:39:33  black_sokol@userecho.com/
    2014-08-17 17:46:21  black_sokol@systemsecurityguard.com/
    2014-08-17 18:55:56  black_sokol@mail.yandex.ru/
    2014-08-17 18:55:56  black_sokol@vk.com/
    2014-08-17 18:55:57  black_sokol@yandex.ru/
    2014-08-17 18:56:02  black_sokol@youtube.com/
    2014-08-17 19:00:54  black_sokol@gamatrix.com/
    2014-08-17 20:18:24  black_sokol@client.vuze.com/
    2014-08-17 20:18:28  black_sokol@doubleclick.net/
    2014-08-17 20:18:28  black_sokol@vuze.com/
    2014-08-17 22:48:49  black_sokol@ru.iobit.com/
    2014-08-17 23:06:51  black_sokol@virustotal.com/
    2014-08-17 23:08:19  black_sokol@www.virustotal.com/


--------[   ]--------------------------------------------------------------------------------------------

    2014-08-16 10:46:11  Black_SOKOL@http://ads.bittorrent.com/blank.html
    2014-08-16 10:53:50  Black_SOKOL@file:///E:/Яндекс%20диск/Документы/Gfhjkb.txt
    2014-08-16 11:46:57  Black_SOKOL@http://www.iobit.com/sd-ac-register.php
    2014-08-16 11:46:59  Black_SOKOL@http://ru.iobit.com/?ref=sd-ac-register
    2014-08-16 11:47:17  Black_SOKOL@http://ru.iobit.com/iobitsmartdefrag/
    2014-08-16 11:48:22  Black_SOKOL@http://ru.iobit.com/about/
    2014-08-16 11:48:39  Black_SOKOL@http://ru.iobit.com/vakansii/
    2014-08-16 11:48:57  Black_SOKOL@http://ru.iobit.com/partners/
    2014-08-16 11:48:58  Black_SOKOL@http://ru.iobit.com/programma-dlya-ochistki-reestra-uskoreniya-komp-yutera-i-optimizatsii-windows/
    2014-08-16 11:54:38  Black_SOKOL@http://ascstats.iobit.com/install.php?operate=1&user=1&app=av7&ver=7.1.0.625&pr=iobit&system=63&type=1
    2014-08-16 12:12:26  Black_SOKOL@file:///C:/Users/Black_SOKOL/Downloads/Программы/pcsecuritytest.zip
    2014-08-16 12:25:09  Black_SOKOL@http://topdownloads.ru/news/?country=RUS
    2014-08-16 12:25:33  Black_SOKOL@http://sourceforge.net/projects/azureus/files/vuze/Vuze_5400/Vuze_5400_Installer64.exe/download
    2014-08-16 12:25:37  Black_SOKOL@http://downloads.sourceforge.net/project/azureus/vuze/Vuze_5400/Vuze_5400_Installer64.exe?r=http%3A%2F%2Ftopdownloads.ru%2Fnews%2F%3Fcountry%3DRUS&ts=1408177533&use_mirror=cznic
    2014-08-16 12:26:16  Black_SOKOL@http://cznic.dl.sourceforge.net/project/azureus/vuze/Vuze_5400/Vuze_5400_Installer64.exe
    2014-08-16 12:27:44  Black_SOKOL@https://accounts.google.com/o/oauth2/postmessageRelay?parent=http%3A%2F%2Fsourceforge.net
    2014-08-16 12:27:48  Black_SOKOL@http://platform.twitter.com/widgets/tweet_button.1407888064.html
    2014-08-16 12:27:50  Black_SOKOL@http://platform.twitter.com/widgets/hub.html
    2014-08-16 12:27:50  Black_SOKOL@https://platform.twitter.com/widgets/hub.html
    2014-08-16 12:30:21  Black_SOKOL@http://client.vuze.com/ftux/index.php?iid=y1y71408177647112mjv2917&azid=4Q6DFPR2W3ZBROOHSHZA2PBKOCHW2QBS&azv=5.4.0.0&locale=ru_RU&os.name=Windows%208&vzemb=1
    2014-08-16 12:30:58  Black_SOKOL@http://raptr.com/store/vuze.html
    2014-08-16 12:31:06  Black_SOKOL@http://client.vuze.com/plus-ftux.start?sourceRef=user-%2Fplus%2Fftux&mode=free&remaining=0&azid=4Q6DFPR2W3ZBROOHSHZA2PBKOCHW2QBS&azv=5.4.0.0&locale=ru_RU&os.name=Windows%208&vzemb=1
    2014-08-16 12:36:29  Black_SOKOL@file:///C:/Users/Black_SOKOL/Downloads/[NNM-Club.me]_Autodesk.AutoCAD.2015.SP1.ru-en.x86-x64.torrent
    2014-08-16 12:37:16  Black_SOKOL@file:///C:/Users/Black_SOKOL/Downloads/[rutracker.org].t2061694.torrent
    2014-08-16 12:37:22  Black_SOKOL@file:///C:/Users/Black_SOKOL/Downloads/[rutracker.org].t3105245.torrent
    2014-08-16 12:37:28  Black_SOKOL@file:///C:/Users/Black_SOKOL/Downloads/[rutracker.org].t4460632.torrent
    2014-08-16 12:37:36  Black_SOKOL@file:///C:/Users/Black_SOKOL/Downloads/[rutracker.org].t4732388.torrent
    2014-08-16 21:24:13  Black_SOKOL@mshelp://windows/?id=0add4344-7b1d-4e23-94cf-5334dbd8dee2
    2014-08-16 21:40:24  Black_SOKOL@file:///D:/Новый%20текстовый%20документ.txt
    2014-08-16 23:10:22  Black_SOKOL@file:///E:/Яндекс%20диск/Документы/заказЛатыпова.xlsx
    2014-08-17 01:00:19  Black_SOKOL@http://client.vuze.com/devices/turnon.start?azid=4Q6DFPR2W3ZBROOHSHZA2PBKOCHW2QBS&azv=5.4.0.0&locale=ru_RU&os.name=Windows%208&vzemb=1
    2014-08-17 01:38:43  Black_SOKOL@file:///E:/Autodesk_Inventor_2015/Autodesk_Inventor_Professional_2015_EN_RU_x86_x64.iso
    2014-08-17 01:39:40  Black_SOKOL@file:///E:/Autodesk%20AutoCAD%20Architecture%202015%20Build%20J.51.0.0%20[Ru,En]/Crack/Иструкция%20по%20установке%20и%20активации.pdf
    2014-08-17 07:48:25  Black_SOKOL@file:///E:/ОСЬ/Win7%20Ultim%20Ru%20x86-x64%20Orig%20wBootMenu%20by%20OVGorskiy%2005.2014/Win7%20Ultim%20Ru%20x86-x64%20Orig%20wBootMenu%20by%20OVGorskiy%2005.2014.iso
    2014-08-17 08:27:00  Black_SOKOL@http://ascstats.iobit.com/install.php?operate=2&user=2&app=asc7&ver=7.3.0.456&pr=iobit&system=63&type=1
    2014-08-17 08:29:55  Black_SOKOL@http://ascstats.iobit.com/install.php?operate=1&user=2&app=asc7&ver=7.3.0.456&pr=iobit&system=63&type=1
    2014-08-17 09:11:02  Black_SOKOL@file:///E:/Яндекс%20диск/Документы/заказ%20Латыпова.xlsx
    2014-08-17 17:01:23  Black_SOKOL@file:///E:/Яндекс%20диск/Исследование/Новый%20текстовый%20документ.txt
    2014-08-17 17:31:15  Black_SOKOL@file:///C:/Users/Black_SOKOL/AppData/Local/Microsoft/Silverlight/OutOfBrowser/OptimalSoftwareLtd.WifiProtector/index.html
    2014-08-17 17:32:34  Black_SOKOL@http://www.wifiprotector.com/buy.aspx?forceComparisonTable=1&uniqueID=51CCFD86-8808-4C37-AD8E-D7D4F1A2B10B&requestID=&hl=ru&ip=178.204.54.154
    2014-08-17 17:33:13  Black_SOKOL@http://ru.iobit.com/advanced-systemcare-antivirus/
    2014-08-17 17:34:39  Black_SOKOL@http://ru.wifiprotector.com/buy7.aspx?forceComparisonTable=1&uniqueID=51CCFD86-8808-4C37-AD8E-D7D4F1A2B10B&requestID=9119a11971854cd8a52a7dc22c8241bb&hl=ru&ip=178.204.54.154
    2014-08-17 17:39:29  Black_SOKOL@res://ieframe.dll/dnserrordiagoff.htm
    2014-08-17 17:39:30  Black_SOKOL@https://accounts.google.com/o/oauth2/postmessageRelay?parent=http%3A%2F%2Fsystemexplorer.net
    2014-08-17 17:39:30  Black_SOKOL@javascript:false
    2014-08-17 17:39:32  Black_SOKOL@http://systemexplorer.userecho.com/widget/forum/18905-/?is_embedded=true&lang=en&referer=http://systemexplorer.net/uninstalldone.php
    2014-08-17 17:39:35  Black_SOKOL@http://systemexplorer.net/uninstalldone.php?v=5.9.2.5250
    2014-08-17 17:40:32  Black_SOKOL@http://www.systemsecurityguard.com/installdone2.php?uid=S0E471979044603A&lng=ru&ver=3.1.0.410
    2014-08-17 17:48:03  Black_SOKOL@http://systemsecurityguard.com/uninstalldonev2.php?uid=&ver=3.1.0.410&instDate=53F0E905
    2014-08-17 17:54:08  Black_SOKOL@file:///E:/Яндекс%20диск/Загрузки/rsload.net.Patch.My.PC.v2.5.zip
    2014-08-17 18:55:54  Black_SOKOL@http://www.yandex.ru/?win=134&clid=1969031
    2014-08-17 18:55:55  Black_SOKOL@http://www.yandex.ru/
    2014-08-17 18:56:02  Black_SOKOL@about:blank
    2014-08-17 18:56:03  Black_SOKOL@fd:TabsFrame
    2014-08-17 18:56:35  Black_SOKOL@http://rsload.net/soft/editor/8596-virtual-dj.html
    2014-08-17 18:56:40  Black_SOKOL@http://rsload.net/noload/files/054/rsload.net.Virtual.DJ.Pro.8.0.0.1897.zip
    2014-08-17 19:00:52  Black_SOKOL@http://www.gamatrix.com/client/index_v2
    2014-08-17 19:00:54  Black_SOKOL@http://www.gamatrix.com/client/news?ids=4147
    2014-08-17 19:05:46  Black_SOKOL@file:///E:/Яндекс%20диск/Исследование/rsload.net.Virtual.DJ.Pro.8.0.0.1897.zip
    2014-08-17 20:18:26  Black_SOKOL@http://client.vuze.com/browse.start?azid=4Q6DFPR2W3ZBROOHSHZA2PBKOCHW2QBS&azv=5.4.0.0&locale=ru_RU&os.name=Windows%208&vzemb=1
    2014-08-17 21:07:43  Black_SOKOL@file:///E:/Trainz%20Simulator%2012/TRAINZ2012.iso
    2014-08-17 21:08:30  Black_SOKOL@file:///E:/Trainz%20Simulator%2012/Serial_nombers.txt
    2014-08-17 22:04:35  Black_SOKOL@file:///H:/FreeAddons/Установка%20сторонних%20дополнений.txt
    2014-08-17 22:21:14  Black_SOKOL@file:///H:/FreeAddons/pack1.cdp
    2014-08-17 22:21:14  Black_SOKOL@file:///H:/FreeAddons/pack2.cdp
    2014-08-17 22:30:16  Black_SOKOL@http://ascstats.iobit.com/install.php?operate=2&user=1&app=ga&ver=1.2.1.466&pr=asc&system=63&type=1
    2014-08-17 22:32:08  Black_SOKOL@http://ascstats.iobit.com/install.php?operate=2&user=2&app=sd3&ver=3.2.0.340&pr=iobit&system=63&type=1
    2014-08-17 22:40:07  Black_SOKOL@res://C:\Windows\system32\mmcndmgr.dll/views.htm
    2014-08-17 22:49:57  Black_SOKOL@http://ascstats.iobit.com/install.php?operate=1&user=2&app=sd3&ver=3.2.0.340&pr=iobit&system=63&type=1
    2014-08-17 22:50:54  Black_SOKOL@file:///C:/Users/Black_SOKOL/AppData/Local/Temp/MATS-Temp/ResultReport/ResultReport.html
    2014-08-17 23:02:36  Black_SOKOL@file:///C:/Users/Black_SOKOL/OneDrive/Документы/1234566.txt
    2014-08-17 23:06:40  Black_SOKOL@http://www.virustotal.com/
    2014-08-17 23:06:40  Black_SOKOL@https://www.virustotal.com/
    2014-08-17 23:07:03  Black_SOKOL@javascript:""
    2014-08-17 23:14:32  Black_SOKOL@file:///E:/Яндекс%20диск/Загрузки/rsload.net.AIDA64.Extreme.Edition.v4.60.3100.Portable.Baltagy.zip
    2014-08-17 23:21:57  Black_SOKOL@file:///E:/Яндекс%20диск/Загрузки/rsload.net.AIDA64.Extreme.Edition.v4.60.3100.zip


--------[  DirectX ]-----------------------------------------------------------------------------------------------

    amstream.dll                              6.06.9600.16384   Final Retail                         65536  22.08.2013 7:53:29
    bdaplgin.ax                               6.03.9600.16384   Final Retail                         72704  22.08.2013 7:45:11
    d2d1.dll                                  6.03.9600.16473   Final Retail  Russian                     3936256  18.03.2014 14:29:36
    d3d10.dll                                 6.03.9600.16384   Final Retail  English                     1055744  22.08.2013 6:42:00
    d3d10_1.dll                               6.03.9600.16384   Final Retail  English                      151040  22.08.2013 6:44:44
    d3d10_1core.dll                           6.03.9600.16384   Final Retail  English                      318464  22.08.2013 6:46:18
    d3d10core.dll                             6.03.9600.16384   Final Retail  English                      285696  22.08.2013 6:46:10
    d3d10level9.dll                           6.03.9600.16421   Final Retail  English                      578952  18.03.2014 14:29:36
    d3d10warp.dll                             6.03.9600.17211   Final Retail  English                     2071552  12.08.2014 23:43:24
    d3d11.dll                                 6.03.9600.17041   Final Retail  English                     1779800  06.03.2014 15:13:14
    d3d8.dll                                  6.03.9600.16384   Final Retail                    1007104  22.08.2013 7:57:54
    d3d8thk.dll                               6.03.9600.17095   Final Retail                      11776  10.07.2014 20:12:34
    d3d9.dll                                  6.03.9600.17095   Final Retail                    1797896  10.07.2014 20:12:34
    d3dim.dll                                 6.03.9600.16384   Final Retail                     378368  22.08.2013 7:59:05
    d3dim700.dll                              6.03.9600.16384   Final Retail                     867328  22.08.2013 6:39:46
    d3dramp.dll                               6.03.9600.16384   Final Retail                     690176  22.08.2013 8:06:33
    d3dxof.dll                                6.03.9600.16384   Final Retail                      55808  22.08.2013 7:54:38
    ddraw.dll                                 6.03.9600.16384   Final Retail                        527872  22.08.2013 6:33:31
    ddrawex.dll                               6.03.9600.16384   Final Retail                      33280  22.08.2013 6:46:37
    devenum.dll                               6.06.9600.16384   Final Retail                         74856  22.08.2013 9:19:12
    dinput.dll                                6.03.9600.16384   Final Retail                        130048  22.08.2013 8:00:08
    dinput8.dll                               6.03.9600.16384   Final Retail                        162304  22.08.2013 8:00:49
    dmband.dll                                6.03.9600.16384   Final Retail                      31744  22.08.2013 7:55:01
    dmcompos.dll                              6.03.9600.16384   Final Retail                      66048  22.08.2013 7:54:34
    dmime.dll                                 6.03.9600.16384   Final Retail                     182272  22.08.2013 7:53:14
    dmloader.dll                              6.03.9600.16384   Final Retail                      36352  22.08.2013 7:55:19
    dmscript.dll                              6.03.9600.16384   Final Retail                      85504  22.08.2013 7:54:46
    dmstyle.dll                               6.03.9600.16384   Final Retail                     110080  22.08.2013 7:54:37
    dmsynth.dll                               6.03.9600.16384   Final Retail                     107008  22.08.2013 7:54:25
    dmusic.dll                                6.03.9600.16384   Final Retail                         97280  22.08.2013 7:50:48
    dplaysvr.exe                              6.03.9600.16384   Final Retail                       8192  22.08.2013 8:05:19
    dplayx.dll                                6.03.9600.16384   Final Retail                       8192  22.08.2013 8:05:19
    dpmodemx.dll                              6.03.9600.16384   Final Retail                       8192  22.08.2013 8:05:19
    dpnaddr.dll                               6.03.9600.16384   Final Retail                       8192  22.08.2013 8:05:19
    dpnathlp.dll                              6.03.9600.16384   Final Retail  English                        8192  22.08.2013 8:05:20
    dpnet.dll                                 6.03.9600.16384   Final Retail                       8192  22.08.2013 8:05:19
    dpnhpast.dll                              6.03.9600.16384   Final Retail                       8192  22.08.2013 8:05:19
    dpnhupnp.dll                              6.03.9600.16384   Final Retail                       8192  22.08.2013 8:05:19
    dpnlobby.dll                              6.03.9600.16384   Final Retail                       8192  22.08.2013 8:05:19
    dpnsvr.exe                                6.03.9600.16384   Final Retail                       8192  22.08.2013 8:05:19
    dpwsockx.dll                              6.03.9600.16384   Final Retail                       8192  22.08.2013 8:05:19
    dsdmo.dll                                 6.03.9600.16384   Final Retail                     173568  22.08.2013 7:54:38
    dsound.dll                                6.03.9600.16384   Final Retail                        485888  22.08.2013 7:50:39
    dswave.dll                                6.03.9600.16384   Final Retail                      22016  22.08.2013 7:55:00
    dwrite.dll                                6.03.9600.17111   Final Retail  Russian                     1509888  10.07.2014 20:13:28
    dxdiagn.dll                               6.03.9600.16384   Final Retail                        258560  22.08.2013 7:13:49
    dxgi.dll                                  6.03.9600.17201   Final Retail  English                      406400  12.08.2014 23:32:38
    dxmasf.dll                                12.00.9600.16384  Final Retail                       4608  22.08.2013 8:06:56
    dxtmsft.dll                               11.00.9600.17239  Final Retail  English                      367104  12.08.2014 23:16:40
    dxtrans.dll                               11.00.9600.17239  Final Retail  English                      239616  12.08.2014 23:16:40
    dxva2.dll                                 6.03.9600.16384   Final Retail  English                      103784  22.08.2013 9:24:58
    encapi.dll                                6.03.9600.16384   Final Retail                      19968  22.08.2013 6:46:50
    gcdef.dll                                 6.03.9600.16384   Final Retail                        121856  22.08.2013 7:50:05
    iac25_32.ax                               2.00.0005.0053    Final Retail                        197632  22.08.2013 5:43:11
    ir41_32.ax                                6.03.9600.16384   Final Retail                       9216  22.08.2013 8:06:35
    ir41_qc.dll                               6.03.9600.16384   Final Retail                       8704  22.08.2013 8:06:32
    ir41_qcx.dll                              6.03.9600.16384   Final Retail                       8704  22.08.2013 8:06:32
    ir50_32.dll                               6.03.9600.16384   Final Retail                       9216  22.08.2013 8:06:34
    ir50_qc.dll                               6.03.9600.16384   Final Retail                       8704  22.08.2013 8:06:33
    ir50_qcx.dll                              6.03.9600.16384   Final Retail                       9216  22.08.2013 8:06:34
    ivfsrc.ax                                 5.10.0002.0051    Final Retail                        146944  22.08.2013 5:43:11
    joy.cpl                                   6.03.9600.16384   Final Retail                        137216  22.08.2013 7:40:19
    ksproxy.ax                                6.03.9600.16384   Final Retail                        206848  22.08.2013 7:46:39
    kstvtune.ax                               6.03.9600.16384   Final Retail                         85504  22.08.2013 7:41:45
    ksuser.dll                                6.03.9600.16384   Final Retail                         18616  22.08.2013 9:19:12
    kswdmcap.ax                               6.03.9600.16384   Final Retail                        106496  22.08.2013 7:49:02
    ksxbar.ax                                 6.03.9600.16384   Final Retail                         48640  22.08.2013 7:47:40
    mciqtz32.dll                              6.06.9600.16384   Final Retail                         36864  22.08.2013 7:52:28
    mfc40.dll                                 4.01.0000.6140    Final Retail                        924944  22.08.2013 3:35:15
    mfc42.dll                                 6.06.8063.0000    Beta Retail                        1033728  22.08.2013 7:11:35
    Microsoft.DirectX.AudioVideoPlayback.dll  5.04.0000.2904    Final Retail                      53248  17.08.2014 21:50:37
    Microsoft.DirectX.Diagnostics.dll         5.04.0000.2904    Final Retail                      12800  17.08.2014 21:50:37
    Microsoft.DirectX.Direct3D.dll            9.05.0132.0000    Final Retail                     473600  17.08.2014 21:50:37
    Microsoft.DirectX.Direct3DX.dll           5.04.0000.3900    Final Retail                    2676224  17.08.2014 21:50:26
    Microsoft.DirectX.Direct3DX.dll           9.04.0091.0000    Final Retail                    2846720  17.08.2014 21:50:31
    Microsoft.DirectX.Direct3DX.dll           9.05.0132.0000    Final Retail                     563712  17.08.2014 21:50:32
    Microsoft.DirectX.Direct3DX.dll           9.06.0168.0000    Final Retail                     567296  17.08.2014 21:50:33
    Microsoft.DirectX.Direct3DX.dll           9.07.0239.0000    Final Retail                     576000  17.08.2014 21:50:33
    Microsoft.DirectX.Direct3DX.dll           9.08.0299.0000    Final Retail                     577024  17.08.2014 21:50:34
    Microsoft.DirectX.Direct3DX.dll           9.09.0376.0000    Final Retail                     577536  17.08.2014 21:50:34
    Microsoft.DirectX.Direct3DX.dll           9.10.0455.0000    Final Retail                     577536  17.08.2014 21:50:35
    Microsoft.DirectX.Direct3DX.dll           9.11.0519.0000    Final Retail                     578560  17.08.2014 21:50:35
    Microsoft.DirectX.Direct3DX.dll           9.12.0589.0000    Final Retail                     578560  17.08.2014 21:50:38
    Microsoft.DirectX.DirectDraw.dll          5.04.0000.2904    Final Retail                     145920  17.08.2014 21:50:38
    Microsoft.DirectX.DirectInput.dll         5.04.0000.2904    Final Retail                     159232  17.08.2014 21:50:38
    Microsoft.DirectX.DirectPlay.dll          5.04.0000.2904    Final Retail                     364544  17.08.2014 21:50:39
    Microsoft.DirectX.DirectSound.dll         5.04.0000.2904    Final Retail                     178176  17.08.2014 21:50:39
    Microsoft.DirectX.dll                     5.04.0000.2904    Final Retail                     223232  17.08.2014 21:50:37
    mpeg2data.ax                              6.06.9600.16384   Final Retail                         73216  22.08.2013 7:47:47
    mpg2splt.ax                               6.06.9600.16384   Final Retail                     197632  22.08.2013 7:52:58
    msdmo.dll                                 6.06.9600.16384   Final Retail                      39752  22.08.2013 9:19:22
    msdvbnp.ax                                6.06.9600.16384   Final Retail                         58880  22.08.2013 7:47:32
    msvidctl.dll                              6.05.9600.16384   Final Retail                       2284544  22.08.2013 7:16:37
    msyuv.dll                                 6.03.9600.16384   Final Retail                      23552  22.08.2013 8:03:48
    pid.dll                                   6.03.9600.16384   Final Retail                      37888  22.08.2013 8:00:41
    psisdecd.dll                              6.06.9600.16384   Final Retail                        457216  22.08.2013 7:29:48
    psisrndr.ax                               6.06.9600.16384   Final Retail                         77824  22.08.2013 7:29:39
    qasf.dll                                  12.00.9600.16384  Final Retail                     185856  22.08.2013 7:16:33
    qcap.dll                                  6.06.9600.16384   Final Retail                        179200  22.08.2013 7:50:04
    qdv.dll                                   6.06.9600.16384   Final Retail                        273408  22.08.2013 7:48:10
    qdvd.dll                                  6.06.9600.16384   Final Retail                        469504  22.08.2013 7:47:29
    qedit.dll                                 6.06.9600.17200   Final Retail                        488960  10.07.2014 20:14:58
    qedwipes.dll                              6.06.9600.16384   Final Retail                     733184  22.08.2013 8:16:59
    quartz.dll                                6.06.9600.16384   Final Retail                       1352192  22.08.2013 7:18:28
    vbisurf.ax                                6.03.9600.16384   Final Retail                      35328  22.08.2013 7:47:03
    vfwwdm32.dll                              6.03.9600.16384   Final Retail                         53760  22.08.2013 7:49:22
    wsock32.dll                               6.03.9600.16384   Final Retail                         15872  22.08.2013 8:05:51


--------[ DirectX -  ]---------------------------------------------------------------------------------------------

  [   ]

     DirectDraw:
        DirectDraw                           display
        DirectDraw                       
                                       aticfx32.dll (8.17.10.1247)
                                      AMD Radeon HD 6520G

     Direct3D:
                                16, 32
        Z-                          16, 24, 32
      Multisample Anti-Aliasing Modes                   MSAA 2x, MSAA 4x, MSAA 8x
                               1 x 1
                              16384 x 16384
                              5.0
        DirectX                      DirectX v11.0

     Direct3D:
      Additive Texture Blending                         
      AGP Texturing                                     
      Anisotropic Filtering                             
      Automatic Mipmap Generation                       
      Bilinear Filtering                                
      Compute Shader                                    
      Cubic Environment Mapping                         
      Cubic Filtering                                    
      Decal-Alpha Texture Blending                      
      Decal Texture Blending                            
      Directional Lights                                
      DirectX Texture Compression                       
      DirectX Volumetric Texture Compression             
      Dithering                                         
      Dot3 Texture Blending                             
      Double-Precision Floating-Point                    
      Driver Concurrent Creates                         
      Driver Command Lists                               
      Dynamic Textures                                  
      Edge Anti-Aliasing                                 
      Environmental Bump Mapping                        
      Environmental Bump Mapping + Luminance            
      Factor Alpha Blending                             
      Geometric Hidden-Surface Removal                   
      Geometry Shader                                   
      Guard Band                                        
      Hardware Scene Rasterization                      
      Hardware Transform & Lighting                     
      Legacy Depth Bias                                 
      Map On Default Buffers                             
      Mipmap LOD Bias Adjustments                       
      Mipmapped Cube Textures                           
      Mipmapped Volume Textures                         
      Modulate-Alpha Texture Blending                   
      Modulate Texture Blending                         
      Non-Square Textures                               
      N-Patches                                          
      Perspective Texture Correction                    
      Point Lights                                      
      Point Sampling                                    
      Projective Textures                               
      Quintic Bezier Curves & B-Splines                  
      Range-Based Fog                                   
      Rectangular & Triangular Patches                   
      Rendering In Windowed Mode                        
      Runtime Shader Linking                            
      Scissor Test                                      
      Slope-Scale Based Depth Bias                      
      Specular Flat Shading                             
      Specular Gouraud Shading                          
      Specular Phong Shading                             
      Spherical Mapping                                 
      Spot Lights                                       
      Stencil Buffers                                   
      Sub-Pixel Accuracy                                
      Subtractive Texture Blending                      
      Table Fog                                         
      Texture Alpha Blending                            
      Texture Clamping                                  
      Texture Mirroring                                 
      Texture Transparency                              
      Texture Wrapping                                  
      Tiled Resources                                    
      Triangle Culling                                   
      Trilinear Filtering                               
      Two-Sided Stencil Test                            
      Vertex Alpha Blending                             
      Vertex Fog                                        
      Vertex Tweening                                   
      Volume Textures                                   
      W-Based Fog                                       
      W-Buffering                                        
      Z-Based Fog                                       
      Z-Bias                                            
      Z-Test                                            

      FourCC:
      ATIC                                              
      AYUV                                              
      DXT1                                              
      DXT2                                              
      DXT3                                              
      DXT4                                              
      DXT5                                              
      FLGL                                              
      GET4                                              
      GINF                                              
      INST                                              
      M2IA                                              
      NULL                                              
      NV12                                              
      NV21                                              
      R2VB                                              
      RESZ                                              
      SYV2                                              
      TES1                                              
      TESS                                              
      UYVY                                              
      YUY2                                              
      YV12                                              

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates


--------[ DirectX -  ]----------------------------------------------------------------------------------------------

  [    ]

     DirectSound:
                                        
                                          
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [  (2-    High Definition Audio) ]

     DirectSound:
                                       (2-    High Definition Audio)
                                          {0.0.0.00000000}.{e9c6f0f7-3b51-4927-937c-ea7f00cb7ac1}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    


--------[ DirectX -  ]----------------------------------------------------------------------------------------------

  [  ]

     DirectInput:
                                      
                                           
                                        
                                                     3
      /                                    8

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      

  [  ]

     DirectInput:
                                      
                                           
                                        
      /                                    128

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      

  [ Toshiba Hotkey Driver ]

     DirectInput:
                                      Toshiba Hotkey Driver
                                           
                                        
      /                                    2

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      

  [ Toshiba Hotkey Driver ]

     DirectInput:
                                      Toshiba Hotkey Driver
                                           
                                        
      /                                    1

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      

  [ Toshiba Hotkey Driver ]

     DirectInput:
                                      Toshiba Hotkey Driver
                                           
                                        
      /                                    5

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      

  [ USB- ]

     DirectInput:
                                      USB-
                                           
                                        

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      


--------[  Windows ]------------------------------------------------------------------------------------------

  [  ]

    DVD-   -:
      DTSOFT Virtual CdRom Device                       6.3.9600.16384
      TSSTcorp CDDVDW TS-L633F                          6.3.9600.16384

    Unknown:
                                              

      :
       (2-    High Definition Audio)6.3.9600.16384
       (2-    High Definition Audio)6.3.9600.16384

    :
         ()             6.3.9600.16384
        ACPI-  ()6.3.9600.16384

    :
      AMD Radeon HD 6520G                               13.251.9001.1001
      AMD Radeon HD 7400M Series                        13.251.9001.1001

     :
      WDC WD5000BPKX-22HPJT0                            6.3.9600.16384

    ,   :
      AMD High Definition Audio Device                  9.0.0.9905
         High Definition Audio     6.3.9600.16384

    :
        PS/2                       6.3.9600.16384

    :
      ACPI    x64                        6.3.9600.16384

     IDE ATA/ATAPI:
      AMD SATA Controller                               1.3.1.220

     USB:
      Realtek USB 2.0 Card Reader                       6.3.9600.30175
       USB-                         6.3.9600.17238
       USB-                         6.3.9600.17238
       USB-                         6.3.9600.17238
       USB-                         6.3.9600.17238
       USB-                         6.3.9600.17238
       USB-                         6.3.9600.17238
       USB-                         6.3.9600.17238
       USB                           6.3.9600.17238
       USB                           6.3.9600.17238
       OpenHCD USB -           6.3.9600.17238
       OpenHCD USB -           6.3.9600.17238
       OpenHCD USB -           6.3.9600.17238
       OpenHCD USB -           6.3.9600.17238
        PCI - USB - 6.3.9600.17238
        PCI - USB - 6.3.9600.17238
        PCI - USB - 6.3.9600.17238

      :
         ()    6.3.9600.17238

    :
      LGE Virtual Modem                                 1.1.0.0

    :
        PnP                         6.3.9600.16384

        :
      HID-                               6.3.9600.16384
      Synaptics PS/2 Port Compatible TouchPad           18.0.7.0

     :
      Fax                                               6.3.9600.16384
      HP ePrint                                         6.3.9600.16384
      HP LaserJet Professional CP1020 Series            6.3.9600.16384
      Microsoft XPS Document Writer                     6.3.9600.16384
                                   6.3.9600.16384
        OneNote 2013                          6.3.9600.16384

     (COM  LPT):
      LGE Bluetooth TransPort (COM3)                    1.1.0.0

     :
      Microsoft Device Association Root Enumerator      6.3.9600.16384
        IPv4 IPv6 ()              6.3.9600.16384

    :
      AMD A6-3400M APU with Radeon(tm) HD Graphics      6.3.9600.16384
      AMD A6-3400M APU with Radeon(tm) HD Graphics      6.3.9600.16384
      AMD A6-3400M APU with Radeon(tm) HD Graphics      6.3.9600.16384
      AMD A6-3400M APU with Radeon(tm) HD Graphics      6.3.9600.16384

     :
      Qualcomm Atheros AR8152 PCI-E Fast Ethernet Controller (NDIS 6.30)2.1.0.21
      Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC  2012.14.417.2014
      Teredo Tunneling Pseudo-Interface                 6.3.9600.16384
       Microsoft ISATAP                          6.3.9600.16384
        Wi-Fi Direct ()     6.3.9600.16384
           ()      6.3.9600.16384

     :
      AMD SMBus                                         6.3.9600.17238
      CMOS                                         6.3.9600.17238
      DAEMON Tools Virtual Bus                          4.49.1.352
      Generic IO & Memory Access                        4.0.0.0
      LG Bluetooth Bus Enumerator                       1.1.0.0
      Microsoft ACPI-                 6.3.9600.17031
      Microsoft ACPI-    6.3.9600.17238
      PCI Express Root Complex                          6.3.9600.17238
      TOSHIBA x64 ACPI-Compliant Value Added Logical and General Purpose Device3.1.0.0
      UMBus                    6.3.9600.16384
                               6.3.9600.17238
        ()                 6.3.9600.16384
         ()            6.3.9600.17031
                                       6.3.9600.17238
                               6.3.9600.17238
                                          6.3.9600.16384
       Microsoft System Management BIOS          6.3.9600.16384
         ACPI Microsoft Windows   6.3.9600.16384
        ACPI                               6.3.9600.17238
                          6.3.9600.17238
       High Definition Audio (Microsoft)      6.3.9600.17238
       High Definition Audio (Microsoft)      6.3.9600.17238
                         6.3.9600.17238
       ACPI                                       6.3.9600.17238
         ()     6.3.9600.16384
          NDIS  6.3.9600.16384
                            6.3.9600.16384
         Plug and Play 6.3.9600.16384
                     6.3.9600.17238
                                   6.3.9600.17238
                                   6.3.9600.17238
                                          6.3.9600.17238
                                         6.3.9600.17238
        PCI  - CPU                       6.3.9600.17238
        PCI  - CPU                       6.3.9600.17238
        PCI  - CPU                       6.3.9600.17238
        PCI  - CPU                       6.3.9600.17238
        PCI  - CPU                       6.3.9600.17238
        PCI  - CPU                       6.3.9600.17238
        PCI  - CPU                       6.3.9600.17238
        PCI  - CPU                       6.3.9600.17238
        PCI  - CPU                       6.3.9600.17238
        PCI - ISA                        6.3.9600.17238
        PCI - PCI                        6.3.9600.17238
        PCI - PCI                        6.3.9600.17238
        PCI - PCI                        6.3.9600.17238
        PCI - PCI                        6.3.9600.17238
        ACPI                              6.3.9600.17238
         ACPI          6.3.9600.17238
           6.3.9600.16384

        :
                           6.3.9600.16384
                           6.3.9600.16384
                           6.3.9600.16384
                           6.3.9600.16384
                           6.3.9600.16384
                           6.3.9600.16384
                           6.3.9600.16384

      :
                                        6.3.9600.17215
                                        6.3.9600.17215
                                        6.3.9600.17215

     HID (Human Interface Devices):
      HID-               6.3.9600.16384
      HID-               6.3.9600.16384
      HID- ,  6.3.9600.17041
      Toshiba Hotkey Driver                             9.0.0.5
      USB-                               6.3.9600.17041
      USB-                               6.3.9600.17041
            HID6.3.9600.17041

      :
      TOSHIBA Web Camera - MP                           6.3.9600.16384

     :
      [TV]42LM620T-ZE                                   6.3.9600.16384

  [ DVD-   - / DTSOFT Virtual CdRom Device ]

     :
                                        DTSOFT Virtual CdRom Device
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          cdrom.inf
       ID                                     DTSOFTBUS&Rev1\DTCDROM&Rev1
                                     00

     :
                                     http://www.aida64.com/driver-updates

  [ DVD-   - / TSSTcorp CDDVDW TS-L633F ]

     :
                                        TSSTcorp CDDVDW TS-L633F
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          cdrom.inf
       ID                                     SCSI\CdRomTSSTcorpCDDVDW_TS-L633F_TF01
                                     Bus Number 1, Target Id 0, LUN 0

     :
                                                   Toshiba Samsung Storage Technology
                                     http://www.tsstorage.com/tsst/index_e.html
                                        http://www.samsungodd.com/eng/LiveUpdate/LiveUpdate.asp
                                     http://www.aida64.com/driver-updates

  [ Unknown / Unknown ]

     :
                                        Unknown

  [    /  (2-    High Definition Audio) ]

     :
                                         (2-    High Definition Audio)
                                            22.08.2013
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          AudioEndpoint.inf
       ID                                     MMDEVAPI\AudioEndpoints

  [    /  (2-    High Definition Audio) ]

     :
                                         (2-    High Definition Audio)
                                            22.08.2013
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          AudioEndpoint.inf
       ID                                     MMDEVAPI\AudioEndpoints

  [  /    () ]

     :
                                           ()
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          cmbatt.inf
       ID                                     ACPI\VEN_ACPI&DEV_0003

     :
                                     http://www.aida64.com/driver-updates

  [  /   ACPI-  () ]

     :
                                          ACPI-  ()
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          cmbatt.inf
       ID                                     ACPI\VEN_PNP&DEV_0C0A

     :
                                     http://www.aida64.com/driver-updates

  [  / AMD Radeon HD 6520G ]

     :
                                        AMD Radeon HD 6520G
                                            04.07.2014
                                          13.251.9001.1001
                                       Advanced Micro Devices, Inc.
      INF-                                          oem1.inf
       ID                                     PCI\VEN_1002&DEV_9647&SUBSYS_FC511179&REV_00
                                     PCI- 0,  1,  0
      PCI-                                    AMD Radeon HD 6520G (Sumo) Video Adapter

     :
      IRQ                                               65536
                                                  000A0000-000BFFFF
                                                  D0000000-DFFFFFFF
                                                  F0300000-F033FFFF
                                                    03B0-03BB
                                                    03C0-03DF
                                                    5000-50FF

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates

  [  / AMD Radeon HD 7400M Series ]

     :
                                        AMD Radeon HD 7400M Series
                                            04.07.2014
                                          13.251.9001.1001
                                       Advanced Micro Devices, Inc.
      INF-                                          oem1.inf
       ID                                     PCI\VEN_1002&DEV_6760&SUBSYS_FC511179&REV_00
                                     PCI- 1,  0,  0
      PCI-                                    AMD Radeon HD 6450M/6470M/6490M (Seymour) Video Adapter

     :
      IRQ                                               65536
                                                  E0000000-EFFFFFFF
                                                  F02E0000-F02FFFFF
                                                    4F00-4FFF

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates

  [   / WDC WD5000BPKX-22HPJT0 ]

     :
                                        WDC WD5000BPKX-22HPJT0
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          disk.inf
       ID                                     SCSI\DiskWDC_____WD5000BPKX-22HPJ01.0
                                     Bus Number 0, Target Id 0, LUN 0

     :
                                                   Western Digital Corporation
                                     http://www.wdc.com/en
                                     http://www.aida64.com/driver-updates

  [ ,    / AMD High Definition Audio Device ]

     :
                                        AMD High Definition Audio Device
                                            21.02.2014
                                          9.0.0.9905
                                       Advanced Micro Devices
      INF-                                          oem10.inf
       ID                                     HDAUDIO\FUNC_01&VEN_1002&DEV_AA01&SUBSYS_00AA0100&REV_1002
                                     Internal High Definition Audio Bus

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/chipsets
                                       http://support.amd.com
                                     http://www.aida64.com/driver-updates

  [ ,    /    High Definition Audio ]

     :
                                           High Definition Audio
                                            22.08.2013
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          hdaudio.inf
       ID                                     HDAUDIO\FUNC_01&VEN_14F1&DEV_5069&SUBSYS_1179FC50&REV_1003
                                     Internal High Definition Audio Bus

     :
                                     http://www.aida64.com/driver-updates

  [  /   PS/2 ]

     :
                                          PS/2
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          keyboard.inf
       ID                                     ACPI\VEN_TOS&DEV_1102

     :
      IRQ                                               01
                                                    0060-0060
                                                    0064-0064

     :
                                     http://www.aida64.com/driver-updates

  [  / ACPI    x64 ]

     :
                                        ACPI    x64
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          hal.inf
       ID                                     acpiapic

  [  IDE ATA/ATAPI / AMD SATA Controller ]

     :
                                        AMD SATA Controller
                                            20.03.2014
                                          1.3.1.220
                                       AMD
      INF-                                          oem9.inf
       ID                                     PCI\VEN_1022&DEV_7801&SUBSYS_FC501179&REV_00
                                     PCI- 0,  17,  0
      PCI-                                    AMD Hudson-2 FCH - SATA AHCI Controller

     :
      IRQ                                               19
                                                  F034F000-F034F7FF
                                                    5100-510F
                                                    5110-5117
                                                    5118-511F
                                                    5120-5123
                                                    5124-5127

  [  USB / Realtek USB 2.0 Card Reader ]

     :
                                        Realtek USB 2.0 Card Reader
                                            27.02.2014
                                          6.3.9600.30175
                                       Realtek
      INF-                                          oem7.inf
       ID                                     USB\VID_0BDA&PID_0138&REV_3882
                                     Port_#0001.Hub_#0004

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB20&VID1022&PID7808&REV0011

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB20&VID1022&PID7808&REV0011

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB20&VID1022&PID7808&REV0011

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB&VID1022&PID7807&REV0011

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB&VID1022&PID7807&REV0011

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB&VID1022&PID7809&REV0011

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB&VID1022&PID7807&REV0011

  [  USB /  USB  ]

     :
                                         USB 
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          usb.inf
       ID                                     USB\VID_04F2&PID_B289&REV_4718
                                     Port_#0002.Hub_#0004

  [  USB /  USB  ]

     :
                                         USB 
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          usb.inf
       ID                                     USB\VID_04B4&PID_0060&REV_0001
                                     Port_#0004.Hub_#0001

  [  USB /  OpenHCD USB - ]

     :
                                         OpenHCD USB -
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_1022&DEV_7807&SUBSYS_FC501179&REV_11
                                     PCI- 0,  18,  0
      PCI-                                    AMD Hudson-2 FCH - USB OHCI Controller

     :
      IRQ                                               18
                                                  F034E000-F034EFFF

  [  USB /  OpenHCD USB - ]

     :
                                         OpenHCD USB -
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_1022&DEV_7807&SUBSYS_FC501179&REV_11
                                     PCI- 0,  19,  0
      PCI-                                    AMD Hudson-2 FCH - USB OHCI Controller

     :
      IRQ                                               18
                                                  F034C000-F034CFFF

  [  USB /  OpenHCD USB - ]

     :
                                         OpenHCD USB -
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_1022&DEV_7809&SUBSYS_FC501179&REV_11
                                     PCI- 0,  20,  5
      PCI-                                    AMD Hudson-2 FCH - USB OHCI Controller

     :
      IRQ                                               18
                                                  F034A000-F034AFFF

  [  USB /  OpenHCD USB - ]

     :
                                         OpenHCD USB -
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_1022&DEV_7807&SUBSYS_FC501179&REV_11
                                     PCI- 0,  22,  0
      PCI-                                    AMD Hudson-2 FCH - USB OHCI Controller

     :
      IRQ                                               18
                                                  F0349000-F0349FFF

  [  USB /   PCI - USB - ]

     :
                                          PCI - USB -
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_1022&DEV_7808&SUBSYS_FC501179&REV_11
                                     PCI- 0,  18,  2
      PCI-                                    AMD Hudson-2 FCH - USB 2.0 EHCI Controller

     :
      IRQ                                               17
                                                  F034D000-F034D0FF

  [  USB /   PCI - USB - ]

     :
                                          PCI - USB -
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_1022&DEV_7808&SUBSYS_FC501179&REV_11
                                     PCI- 0,  19,  2
      PCI-                                    AMD Hudson-2 FCH - USB 2.0 EHCI Controller

     :
      IRQ                                               17
                                                  F034B000-F034B0FF

  [  USB /   PCI - USB - ]

     :
                                          PCI - USB -
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_1022&DEV_7808&SUBSYS_FC501179&REV_11
                                     PCI- 0,  22,  2
      PCI-                                    AMD Hudson-2 FCH - USB 2.0 EHCI Controller

     :
      IRQ                                               17
                                                  F0348000-F03480FF

  [    /    () ]

     :
                                           ()
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          spaceport.inf
       ID                                     Root\Spaceport

     :
                                     http://www.aida64.com/driver-updates

  [  / LGE Virtual Modem ]

     :
                                        LGE Virtual Modem
                                            21.08.2009
                                          1.1.0.0
                                       LG Electronics Inc
      INF-                                          oem24.inf
       ID                                     LGBT\LGBT_modem

     :
                                     http://www.aida64.com/driver-updates

  [  /   PnP ]

     :
                                          PnP
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          monitor.inf
       ID                                     MONITOR\LGD02DC

     :
                                     http://www.aida64.com/driver-updates

  [      / HID-  ]

     :
                                        HID- 
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          msmouse.inf
       ID                                     HID\VID_04B4&PID_0060&REV_0001&MI_00

     :
                                     http://www.aida64.com/driver-updates

  [      / Synaptics PS/2 Port Compatible TouchPad ]

     :
                                        Synaptics PS/2 Port Compatible TouchPad
                                            09.01.2014
                                          18.0.7.0
                                       Synaptics
      INF-                                          oem11.inf
       ID                                     ACPI\VEN_TOS&DEV_0200

     :
      IRQ                                               12

     :
                                     http://www.aida64.com/driver-updates

  [   / Fax ]

     :
                                        Fax
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          PrintQueue.inf
       ID                                     PRINTENUM\microsoftmicrosoft_s7d14

  [   / HP ePrint ]

     :
                                        HP ePrint
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          PrintQueue.inf
       ID                                     PRINTENUM\LocalPrintQueue

  [   / HP LaserJet Professional CP1020 Series ]

     :
                                        HP LaserJet Professional CP1020 Series
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          PrintQueue.inf
       ID                                     PRINTENUM\hewlett-packardhp_la0384

  [   / Microsoft XPS Document Writer ]

     :
                                        Microsoft XPS Document Writer
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          PrintQueue.inf
       ID                                     PRINTENUM\{0f4130dd-19c7-7ab6-99a1-980f03b2ee4e}

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          PrintQueue.inf
       ID                                     PRINTENUM\LocalPrintQueue

  [   /   OneNote 2013 ]

     :
                                          OneNote 2013
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          PrintQueue.inf
       ID                                     PRINTENUM\{3ee39114-30b4-45a4-a109-19d4a40fcc22}

  [  (COM  LPT) / LGE Bluetooth TransPort (COM3) ]

     :
                                        LGE Bluetooth TransPort (COM3)
                                            21.08.2009
                                          1.1.0.0
                                       LG Electronics Inc.
      INF-                                          oem25.inf
       ID                                     LGBT\LGBT_transport

  [   / Microsoft Device Association Root Enumerator ]

     :
                                        Microsoft Device Association Root Enumerator
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          c_swdevice.inf

  [   /   IPv4 IPv6 () ]

     :
                                          IPv4 IPv6 ()
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          c_swdevice.inf

  [  / AMD A6-3400M APU with Radeon(tm) HD Graphics ]

     :
                                        AMD A6-3400M APU with Radeon(tm) HD Graphics
                                            21.04.2009
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          cpu.inf
       ID                                     ACPI\AuthenticAMD_-_AMD64_Family_18_Model_1

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/processors
                                     http://www.aida64.com/driver-updates

  [  / AMD A6-3400M APU with Radeon(tm) HD Graphics ]

     :
                                        AMD A6-3400M APU with Radeon(tm) HD Graphics
                                            21.04.2009
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          cpu.inf
       ID                                     ACPI\AuthenticAMD_-_AMD64_Family_18_Model_1

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/processors
                                     http://www.aida64.com/driver-updates

  [  / AMD A6-3400M APU with Radeon(tm) HD Graphics ]

     :
                                        AMD A6-3400M APU with Radeon(tm) HD Graphics
                                            21.04.2009
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          cpu.inf
       ID                                     ACPI\AuthenticAMD_-_AMD64_Family_18_Model_1

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/processors
                                     http://www.aida64.com/driver-updates

  [  / AMD A6-3400M APU with Radeon(tm) HD Graphics ]

     :
                                        AMD A6-3400M APU with Radeon(tm) HD Graphics
                                            21.04.2009
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          cpu.inf
       ID                                     ACPI\AuthenticAMD_-_AMD64_Family_18_Model_1

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/processors
                                     http://www.aida64.com/driver-updates

  [   / Qualcomm Atheros AR8152 PCI-E Fast Ethernet Controller (NDIS 6.30) ]

     :
                                        Qualcomm Atheros AR8152 PCI-E Fast Ethernet Controller (NDIS 6.30)
                                            16.07.2013
                                          2.1.0.21
                                       Qualcomm Atheros
      INF-                                          oem8.inf
       ID                                     PCI\VEN_1969&DEV_2062&SUBSYS_FC501179&REV_C1
                                     PCI- 2,  0,  0
      PCI-                                    Atheros AR8152/8158 PCI-E Fast Ethernet Controller

     :
      IRQ                                               16
                                                  F0100000-F013FFFF
                                                    3000-307F

      :
                                                   Atheros Communications, Inc.
                                     http://www.atheros.com/networking
                                       http://www.atheros.com
                                     http://www.aida64.com/driver-updates

  [   / Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC ]

     :
                                        Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC
                                            30.04.2014
                                          2012.14.417.2014
                                       Realtek Semiconductor Corp.
      INF-                                          oem13.inf
       ID                                     PCI\VEN_10EC&DEV_8176&SUBSYS_818110EC&REV_01
                                     PCI- 3,  0,  0
      PCI-                                    Realtek RTL8188CE Wireless LAN 802.11n PCI-E Network Adapter

     :
      IRQ                                               17
                                                  F0000000-F0003FFF
                                                    2000-20FF

      :
                                                   Realtek Semiconductor Corp.
                                     http://www.realtek.com.tw/products/productsView.aspx?Langid=1&PNid=7&PFid=10&Level=3&Conn=2
                                       http://www.realtek.com.tw/downloads
                                     http://www.aida64.com/driver-updates

  [   / Teredo Tunneling Pseudo-Interface ]

     :
                                        Teredo Tunneling Pseudo-Interface
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          nettun.inf
       ID                                     *TEREDO

     :
                                     http://www.aida64.com/driver-updates

  [   /  Microsoft ISATAP ]

     :
                                         Microsoft ISATAP
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          nettun.inf
       ID                                     *ISATAP

     :
                                     http://www.aida64.com/driver-updates

  [   /   Wi-Fi Direct () ]

     :
                                          Wi-Fi Direct ()
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          netvwifimp.inf
       ID                                     {5d624f94-8850-40c3-a3fa-a4fd2080baf3}\vwifimp_wfd
                                     VWiFi Bus 0

     :
                                     http://www.aida64.com/driver-updates

  [   /      () ]

     :
                                             ()
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          kdnic.inf
       ID                                     root\kdnic

     :
                                     http://www.aida64.com/driver-updates

  [   / AMD SMBus ]

     :
                                        AMD SMBus
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_780B&SUBSYS_FC501179&REV_13
                                     PCI- 0,  20,  0
      PCI-                                    AMD Hudson-2 FCH - SMBus and ACPI Controller

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/chipsets
                                       http://support.amd.com
       BIOS                                 http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [   / CMOS   ]

     :
                                        CMOS  
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\VEN_PNP&DEV_0B00

     :
                                                    0070-0071

  [   / DAEMON Tools Virtual Bus ]

     :
                                        DAEMON Tools Virtual Bus
                                            21.02.2014
                                          4.49.1.352
                                       DT Soft Ltd
      INF-                                          oem6.inf
       ID                                     root\DTSoftBus01

  [   / Generic IO & Memory Access ]

     :
                                        Generic IO & Memory Access
                                            06.08.2013
                                          4.0.0.0
                                       TOSHIBA
      INF-                                          oem3.inf
       ID                                     ACPI\VEN_QCI&DEV_0701

  [   / LG Bluetooth Bus Enumerator ]

     :
                                        LG Bluetooth Bus Enumerator
                                            21.08.2009
                                          1.1.0.0
                                       LG Electronics Inc.
      INF-                                          oem23.inf
       ID                                     root\lgbtbus

  [   / Microsoft ACPI-  ]

     :
                                        Microsoft ACPI- 
                                            21.06.2006
                                          6.3.9600.17031
                                       Microsoft
      INF-                                          acpi.inf
       ID                                     ACPI_HAL\PNP0C08
      PnP-                                    ACPI Driver/BIOS

     :
      IRQ                                               100
      IRQ                                               101
      IRQ                                               102
      IRQ                                               103
      IRQ                                               104
      IRQ                                               105
      IRQ                                               106
      IRQ                                               107
      IRQ                                               108
      IRQ                                               109
      IRQ                                               110
      IRQ                                               111
      IRQ                                               112
      IRQ                                               113
      IRQ                                               114
      IRQ                                               115
      IRQ                                               116
      IRQ                                               117
      IRQ                                               118
      IRQ                                               119
      IRQ                                               120
      IRQ                                               121
      IRQ                                               122
      IRQ                                               123
      IRQ                                               124
      IRQ                                               125
      IRQ                                               126
      IRQ                                               127
      IRQ                                               128
      IRQ                                               129
      IRQ                                               130
      IRQ                                               131
      IRQ                                               132
      IRQ                                               133
      IRQ                                               134
      IRQ                                               135
      IRQ                                               136
      IRQ                                               137
      IRQ                                               138
      IRQ                                               139
      IRQ                                               140
      IRQ                                               141
      IRQ                                               142
      IRQ                                               143
      IRQ                                               144
      IRQ                                               145
      IRQ                                               146
      IRQ                                               147
      IRQ                                               148
      IRQ                                               149
      IRQ                                               150
      IRQ                                               151
      IRQ                                               152
      IRQ                                               153
      IRQ                                               154
      IRQ                                               155
      IRQ                                               156
      IRQ                                               157
      IRQ                                               158
      IRQ                                               159
      IRQ                                               160
      IRQ                                               161
      IRQ                                               162
      IRQ                                               163
      IRQ                                               164
      IRQ                                               165
      IRQ                                               166
      IRQ                                               167
      IRQ                                               168
      IRQ                                               169
      IRQ                                               170
      IRQ                                               171
      IRQ                                               172
      IRQ                                               173
      IRQ                                               174
      IRQ                                               175
      IRQ                                               176
      IRQ                                               177
      IRQ                                               178
      IRQ                                               179
      IRQ                                               180
      IRQ                                               181
      IRQ                                               182
      IRQ                                               183
      IRQ                                               184
      IRQ                                               185
      IRQ                                               186
      IRQ                                               187
      IRQ                                               188
      IRQ                                               189
      IRQ                                               190
      IRQ                                               191
      IRQ                                               256
      IRQ                                               257
      IRQ                                               258
      IRQ                                               259
      IRQ                                               260
      IRQ                                               261
      IRQ                                               262
      IRQ                                               263
      IRQ                                               264
      IRQ                                               265
      IRQ                                               266
      IRQ                                               267
      IRQ                                               268
      IRQ                                               269
      IRQ                                               270
      IRQ                                               271
      IRQ                                               272
      IRQ                                               273
      IRQ                                               274
      IRQ                                               275
      IRQ                                               276
      IRQ                                               277
      IRQ                                               278
      IRQ                                               279
      IRQ                                               280
      IRQ                                               281
      IRQ                                               282
      IRQ                                               283
      IRQ                                               284
      IRQ                                               285
      IRQ                                               286
      IRQ                                               287
      IRQ                                               288
      IRQ                                               289
      IRQ                                               290
      IRQ                                               291
      IRQ                                               292
      IRQ                                               293
      IRQ                                               294
      IRQ                                               295
      IRQ                                               296
      IRQ                                               297
      IRQ                                               298
      IRQ                                               299
      IRQ                                               300
      IRQ                                               301
      IRQ                                               302
      IRQ                                               303
      IRQ                                               304
      IRQ                                               305
      IRQ                                               306
      IRQ                                               307
      IRQ                                               308
      IRQ                                               309
      IRQ                                               310
      IRQ                                               311
      IRQ                                               312
      IRQ                                               313
      IRQ                                               314
      IRQ                                               315
      IRQ                                               316
      IRQ                                               317
      IRQ                                               318
      IRQ                                               319
      IRQ                                               320
      IRQ                                               321
      IRQ                                               322
      IRQ                                               323
      IRQ                                               324
      IRQ                                               325
      IRQ                                               326
      IRQ                                               327
      IRQ                                               328
      IRQ                                               329
      IRQ                                               330
      IRQ                                               331
      IRQ                                               332
      IRQ                                               333
      IRQ                                               334
      IRQ                                               335
      IRQ                                               336
      IRQ                                               337
      IRQ                                               338
      IRQ                                               339
      IRQ                                               340
      IRQ                                               341
      IRQ                                               342
      IRQ                                               343
      IRQ                                               344
      IRQ                                               345
      IRQ                                               346
      IRQ                                               347
      IRQ                                               348
      IRQ                                               349
      IRQ                                               350
      IRQ                                               351
      IRQ                                               352
      IRQ                                               353
      IRQ                                               354
      IRQ                                               355
      IRQ                                               356
      IRQ                                               357
      IRQ                                               358
      IRQ                                               359
      IRQ                                               360
      IRQ                                               361
      IRQ                                               362
      IRQ                                               363
      IRQ                                               364
      IRQ                                               365
      IRQ                                               366
      IRQ                                               367
      IRQ                                               368
      IRQ                                               369
      IRQ                                               370
      IRQ                                               371
      IRQ                                               372
      IRQ                                               373
      IRQ                                               374
      IRQ                                               375
      IRQ                                               376
      IRQ                                               377
      IRQ                                               378
      IRQ                                               379
      IRQ                                               380
      IRQ                                               381
      IRQ                                               382
      IRQ                                               383
      IRQ                                               384
      IRQ                                               385
      IRQ                                               386
      IRQ                                               387
      IRQ                                               388
      IRQ                                               389
      IRQ                                               390
      IRQ                                               391
      IRQ                                               392
      IRQ                                               393
      IRQ                                               394
      IRQ                                               395
      IRQ                                               396
      IRQ                                               397
      IRQ                                               398
      IRQ                                               399
      IRQ                                               400
      IRQ                                               401
      IRQ                                               402
      IRQ                                               403
      IRQ                                               404
      IRQ                                               405
      IRQ                                               406
      IRQ                                               407
      IRQ                                               408
      IRQ                                               409
      IRQ                                               410
      IRQ                                               411
      IRQ                                               412
      IRQ                                               413
      IRQ                                               414
      IRQ                                               415
      IRQ                                               416
      IRQ                                               417
      IRQ                                               418
      IRQ                                               419
      IRQ                                               420
      IRQ                                               421
      IRQ                                               422
      IRQ                                               423
      IRQ                                               424
      IRQ                                               425
      IRQ                                               426
      IRQ                                               427
      IRQ                                               428
      IRQ                                               429
      IRQ                                               430
      IRQ                                               431
      IRQ                                               432
      IRQ                                               433
      IRQ                                               434
      IRQ                                               435
      IRQ                                               436
      IRQ                                               437
      IRQ                                               438
      IRQ                                               439
      IRQ                                               440
      IRQ                                               441
      IRQ                                               442
      IRQ                                               443
      IRQ                                               444
      IRQ                                               445
      IRQ                                               446
      IRQ                                               447
      IRQ                                               448
      IRQ                                               449
      IRQ                                               450
      IRQ                                               451
      IRQ                                               452
      IRQ                                               453
      IRQ                                               454
      IRQ                                               455
      IRQ                                               456
      IRQ                                               457
      IRQ                                               458
      IRQ                                               459
      IRQ                                               460
      IRQ                                               461
      IRQ                                               462
      IRQ                                               463
      IRQ                                               464
      IRQ                                               465
      IRQ                                               466
      IRQ                                               467
      IRQ                                               468
      IRQ                                               469
      IRQ                                               470
      IRQ                                               471
      IRQ                                               472
      IRQ                                               473
      IRQ                                               474
      IRQ                                               475
      IRQ                                               476
      IRQ                                               477
      IRQ                                               478
      IRQ                                               479
      IRQ                                               480
      IRQ                                               481
      IRQ                                               482
      IRQ                                               483
      IRQ                                               484
      IRQ                                               485
      IRQ                                               486
      IRQ                                               487
      IRQ                                               488
      IRQ                                               489
      IRQ                                               490
      IRQ                                               491
      IRQ                                               492
      IRQ                                               493
      IRQ                                               494
      IRQ                                               495
      IRQ                                               496
      IRQ                                               497
      IRQ                                               498
      IRQ                                               499
      IRQ                                               500
      IRQ                                               501
      IRQ                                               502
      IRQ                                               503
      IRQ                                               504
      IRQ                                               505
      IRQ                                               506
      IRQ                                               507
      IRQ                                               508
      IRQ                                               509
      IRQ                                               510
      IRQ                                               511
      IRQ                                               81
      IRQ                                               82
      IRQ                                               83
      IRQ                                               84
      IRQ                                               85
      IRQ                                               86
      IRQ                                               87
      IRQ                                               88
      IRQ                                               89
      IRQ                                               90
      IRQ                                               91
      IRQ                                               92
      IRQ                                               93
      IRQ                                               94
      IRQ                                               95
      IRQ                                               96
      IRQ                                               97
      IRQ                                               98
      IRQ                                               99

  [   / Microsoft ACPI-   ]

     :
                                        Microsoft ACPI-  
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\VEN_PNP&DEV_0C09

     :
                                                    0062-0062
                                                    0066-0066

  [   / PCI Express Root Complex ]

     :
                                        PCI Express Root Complex
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\VEN_PNP&DEV_0A08

     :
                                                  000A0000-000BFFFF
                                                  000C0000-000C3FFF
                                                  000C4000-000C7FFF
                                                  000C8000-000CBFFF
                                                  000CC000-000CFFFF
                                                  000D0000-000D3FFF
                                                  000D4000-000D7FFF
                                                  000D8000-000DBFFF
                                                  000DC000-000DFFFF
                                                  000E0000-000E3FFF
                                                  000E4000-000E7FFF
                                                  000E8000-000EBFFF
                                                  000EC000-000EFFFF
                                                  D0000000-F7FFFFFF
                                                  FC000000-FFFFFFFF
                                                    0000-0CF7
                                                    0D00-FFFF

  [   / TOSHIBA x64 ACPI-Compliant Value Added Logical and General Purpose Device ]

     :
                                        TOSHIBA x64 ACPI-Compliant Value Added Logical and General Purpose Device
                                            09.08.2013
                                          3.1.0.0
                                       TOSHIBA
      INF-                                          oem2.inf
       ID                                     ACPI\VEN_TOS&DEV_1900

  [   / UMBus    ]

     :
                                        UMBus   
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          umbus.inf
       ID                                     root\umbus

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\VEN_PNP&DEV_0C04

  [   /   () ]

     :
                                          ()
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          basicdisplay.inf
       ID                                     ROOT\BasicDisplay

  [   /    () ]

     :
                                           ()
                                            21.06.2006
                                          6.3.9600.17031
                                       Microsoft
      INF-                                          basicrender.inf
       ID                                     ROOT\BasicRender

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\VEN_PNP&DEV_0800

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\VEN_PNP&DEV_0103

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          volmgr.inf
       ID                                     ROOT\VOLMGR

  [   /  Microsoft System Management BIOS ]

     :
                                         Microsoft System Management BIOS
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          mssmbios.inf
       ID                                     ROOT\mssmbios

  [   /    ACPI Microsoft Windows ]

     :
                                           ACPI Microsoft Windows
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          wmiacpi.inf
       ID                                     ACPI\VEN_PNP&DEV_0C14

  [   /   ACPI ]

     :
                                          ACPI
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\VEN_PNP&DEV_0C0C

  [   /     ]

     :
                                           
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\VEN_PNP&DEV_0C32

  [   /  High Definition Audio (Microsoft) ]

     :
                                         High Definition Audio (Microsoft)
                                            23.07.2014
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          hdaudbus.inf
       ID                                     PCI\VEN_1002&DEV_1714&SUBSYS_17141002&REV_00
                                     PCI- 0,  1,  1
      PCI-                                    AMD K12 - High Definition Audio Controller

     :
      IRQ                                               19
                                                  F0344000-F0347FFF

  [   /  High Definition Audio (Microsoft) ]

     :
                                         High Definition Audio (Microsoft)
                                            23.07.2014
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          hdaudbus.inf
       ID                                     PCI\VEN_1022&DEV_780D&SUBSYS_FC501179&REV_01
                                     PCI- 0,  20,  2
      PCI-                                    AMD Hudson-2 FCH - High Definition Audio Controller

     :
      IRQ                                               16
                                                  F0340000-F0343FFF

  [   /      ]

     :
                                            
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\VEN_PNP&DEV_0200

  [   /  ACPI ]

     :
                                         ACPI
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\VEN_PNP&DEV_0C0D

  [   /    () ]

     :
                                           ()
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          vdrvroot.inf
       ID                                     ROOT\vdrvroot

  [   /     NDIS ]

     :
                                            NDIS
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          ndisvirtualbus.inf
       ID                                     ROOT\NdisVirtualBus

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          CompositeBus.inf
       ID                                     ROOT\CompositeBus

  [   /    Plug and Play ]

     :
                                           Plug and Play
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          swenum.inf
       ID                                     ROOT\SWENUM

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\VEN_PNP&DEV_0000

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\VEN_PNP&DEV_0C02

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\VEN_PNP&DEV_0C02

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\VEN_PNP&DEV_0C01

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\VEN_PNP&DEV_0100

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1705&SUBSYS_17051022&REV_00
                                     PCI- 0,  0,  0
      PCI-                                    AMD K12 - Root Complex

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1700&SUBSYS_00000000&REV_43
                                     PCI- 0,  24,  0
      PCI-                                    AMD K12 - Link Control

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1701&SUBSYS_00000000&REV_00
                                     PCI- 0,  24,  1
      PCI-                                    AMD K12 - Address Map

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1702&SUBSYS_00000000&REV_00
                                     PCI- 0,  24,  2
      PCI-                                    AMD K12 - DRAM Controller

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1703&SUBSYS_00000000&REV_00
                                     PCI- 0,  24,  3
      PCI-                                    AMD K12 - Miscellaneous Control

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1704&SUBSYS_00000000&REV_00
                                     PCI- 0,  24,  4
      PCI-                                    AMD K12 - Extended Miscellaneous Control

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1718&SUBSYS_00000000&REV_00
                                     PCI- 0,  24,  5
      PCI-                                    AMD K12 - Miscellaneous Control

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1716&SUBSYS_00000000&REV_00
                                     PCI- 0,  24,  6
      PCI-                                    AMD K12 - Miscellaneous Control

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1719&SUBSYS_00000000&REV_00
                                     PCI- 0,  24,  7
      PCI-                                    AMD K12 - Miscellaneous Control

  [   /   PCI - ISA ]

     :
                                          PCI - ISA
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_780E&SUBSYS_FC501179&REV_11
                                     PCI- 0,  20,  3
      PCI-                                    AMD Hudson-2 FCH - LPC Bridge

  [   /   PCI - PCI ]

     :
                                          PCI - PCI
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1707&SUBSYS_12341022&REV_00
                                     PCI- 0,  2,  0
      PCI-                                    AMD K12 - PCI Express Root Port

     :
      IRQ                                               18
                                                  E0000000-EFFFFFFF
                                                  F0200000-F02FFFFF
                                                    4000-4FFF

  [   /   PCI - PCI ]

     :
                                          PCI - PCI
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1709&SUBSYS_12341022&REV_00
                                     PCI- 0,  4,  0
      PCI-                                    AMD K12 - PCI Express Root Port

     :
      IRQ                                               18
                                                  F0100000-F01FFFFF
                                                    3000-3FFF

  [   /   PCI - PCI ]

     :
                                          PCI - PCI
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_170A&SUBSYS_12341022&REV_00
                                     PCI- 0,  5,  0
      PCI-                                    AMD K12 - PCI Express Root Port

     :
      IRQ                                               17
                                                  F0000000-F00FFFFF
                                                    2000-2FFF

  [   /   PCI - PCI ]

     :
                                          PCI - PCI
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_780F&SUBSYS_00000000&REV_40
                                     PCI- 0,  20,  4
      PCI-                                    AMD Hudson-2 FCH - PCI-PCI Host Bridge

  [   /   ACPI ]

     :
                                          ACPI
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\ThermalZone

  [   /    ACPI ]

     :
                                           ACPI
                                            21.06.2006
                                          6.3.9600.17238
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\FixedButton

  [   /       ]

     :
                                             
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          rdpbus.inf
       ID                                     ROOT\RDPBUS

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.3.9600.17215
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.3.9600.17215
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.3.9600.17215
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume

  [  HID (Human Interface Devices) / HID-   ]

     :
                                        HID-  
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          hidserv.inf
       ID                                     HID\tossyshid&Col01

     :
                                     http://www.aida64.com/driver-updates

  [  HID (Human Interface Devices) / HID-   ]

     :
                                        HID-  
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          hidserv.inf
       ID                                     HID\tossyshid&Col03

     :
                                     http://www.aida64.com/driver-updates

  [  HID (Human Interface Devices) / HID- ,   ]

     :
                                        HID- ,  
                                            21.06.2006
                                          6.3.9600.17041
                                       Microsoft
      INF-                                          input.inf
       ID                                     HID\VID_04B4&PID_0060&REV_0001&MI_01

     :
                                     http://www.aida64.com/driver-updates

  [  HID (Human Interface Devices) / Toshiba Hotkey Driver ]

     :
                                        Toshiba Hotkey Driver
                                            24.03.2014
                                          9.0.0.5
                                       Toshiba
      INF-                                          oem12.inf
       ID                                     TVALZ\tossyshid

     :
                                     http://www.aida64.com/driver-updates

  [  HID (Human Interface Devices) / USB-  ]

     :
                                        USB- 
                                            21.06.2006
                                          6.3.9600.17041
                                       Microsoft
      INF-                                          input.inf
       ID                                     USB\VID_04B4&PID_0060&REV_0001&MI_00
                                     0000.0012.0000.004.000.000.000.000.000

     :
                                     http://www.aida64.com/driver-updates

  [  HID (Human Interface Devices) / USB-  ]

     :
                                        USB- 
                                            21.06.2006
                                          6.3.9600.17041
                                       Microsoft
      INF-                                          input.inf
       ID                                     USB\VID_04B4&PID_0060&REV_0001&MI_01
                                     0000.0012.0000.004.000.000.000.000.000

     :
                                     http://www.aida64.com/driver-updates

  [  HID (Human Interface Devices) /       HID ]

     :
                                              HID
                                            21.06.2006
                                          6.3.9600.17041
                                       Microsoft
      INF-                                          input.inf
       ID                                     HID\tossyshid&Col02

     :
                                     http://www.aida64.com/driver-updates

  [    / TOSHIBA Web Camera - MP ]

     :
                                        TOSHIBA Web Camera - MP
                                            21.06.2006
                                          6.3.9600.16384
                                       
      INF-                                          usbvideo.inf
       ID                                     USB\VID_04F2&PID_B289&REV_4718&MI_00
                                     0000.0013.0002.002.000.000.000.000.000

     :
                                     http://www.aida64.com/driver-updates

  [   / [TV]42LM620T-ZE ]

     :
                                        [TV]42LM620T-ZE
                                            21.06.2006
                                          6.3.9600.16384
                                       Microsoft
      INF-                                          digitalmediadevice.inf
       ID                                     UMB\VEN_0104&DEV_0001&REV_01
                                     http://192.168.1.139:37904/MediaRenderer1.xml


--------[   ]---------------------------------------------------------------------------------------

     PCI:
       0,  20,  2                  AMD Hudson-2 FCH - High Definition Audio Controller
       0,  20,  3                  AMD Hudson-2 FCH - LPC Bridge
       0,  20,  4                  AMD Hudson-2 FCH - PCI-PCI Host Bridge
       0,  17,  0                  AMD Hudson-2 FCH - SATA AHCI Controller
       0,  20,  0                  AMD Hudson-2 FCH - SMBus and ACPI Controller
       0,  18,  2                  AMD Hudson-2 FCH - USB 2.0 EHCI Controller
       0,  19,  2                  AMD Hudson-2 FCH - USB 2.0 EHCI Controller
       0,  22,  2                  AMD Hudson-2 FCH - USB 2.0 EHCI Controller
       0,  18,  0                  AMD Hudson-2 FCH - USB OHCI Controller
       0,  19,  0                  AMD Hudson-2 FCH - USB OHCI Controller
       0,  20,  5                  AMD Hudson-2 FCH - USB OHCI Controller
       0,  22,  0                  AMD Hudson-2 FCH - USB OHCI Controller
       0,  24,  1                  AMD K12 - Address Map
       0,  24,  2                  AMD K12 - DRAM Controller
       0,  24,  4                  AMD K12 - Extended Miscellaneous Control
       0,  1,  1                   AMD K12 - High Definition Audio Controller
       0,  24,  0                  AMD K12 - Link Control
       0,  24,  3                  AMD K12 - Miscellaneous Control
       0,  24,  5                  AMD K12 - Miscellaneous Control
       0,  24,  6                  AMD K12 - Miscellaneous Control
       0,  24,  7                  AMD K12 - Miscellaneous Control
       0,  2,  0                   AMD K12 - PCI Express Root Port
       0,  4,  0                   AMD K12 - PCI Express Root Port
       0,  5,  0                   AMD K12 - PCI Express Root Port
       0,  0,  0                   AMD K12 - Root Complex
       1,  0,  0                   AMD Radeon HD 6450M/6470M/6490M (Seymour) Video Adapter
       0,  1,  0                   AMD Radeon HD 6520G (Sumo) Video Adapter
       2,  0,  0                   Atheros AR8152/8158 PCI-E Fast Ethernet Controller
       3,  0,  0                   Realtek RTL8188CE Wireless LAN 802.11n PCI-E Network Adapter

     PnP:
      PNP0C08                                           ACPI Driver/BIOS
      PNP0C14                                           ACPI Management Interface
      PNP0A08                                           ACPI Three-wire Device Bus
      AUTHENTICAMD_-_AMD64_FAMILY_18_MODEL_1_-_AMD_A6-3400M_APU_WITH_RADEON(TM)_HD_GRAPHICSAMD A6-3400M APU with Radeon(tm) HD Graphics
      AUTHENTICAMD_-_AMD64_FAMILY_18_MODEL_1_-_AMD_A6-3400M_APU_WITH_RADEON(TM)_HD_GRAPHICSAMD A6-3400M APU with Radeon(tm) HD Graphics
      AUTHENTICAMD_-_AMD64_FAMILY_18_MODEL_1_-_AMD_A6-3400M_APU_WITH_RADEON(TM)_HD_GRAPHICSAMD A6-3400M APU with Radeon(tm) HD Graphics
      AUTHENTICAMD_-_AMD64_FAMILY_18_MODEL_1_-_AMD_A6-3400M_APU_WITH_RADEON(TM)_HD_GRAPHICSAMD A6-3400M APU with Radeon(tm) HD Graphics
      PNP0C0A                                           Control Method Battery
      PNP0C32                                           Direct Application Launch Button
      PNP0200                                           DMA Controller
      PNP0C09                                           Embedded Controller Device
      QCI0701                                           Generic IO & Memory Access
      PNP0103                                           High Precision Event Timer
      PNP0C0D                                           Lid
      ACPI0003                                          Microsoft AC Adapter
      PNP0C04                                           Numeric Data Processor
      PNP0800                                           PC Speaker
      PNP0C0C                                           Power Button
      PNP0000                                           Programmable Interrupt Controller
      PNP0B00                                           Real-Time Clock
      TOS0200                                           Synaptics PS/2 Port TouchPad
      PNP0C01                                           System Board Extension
      PNP0100                                           System Timer
      PNP0C02                                           Thermal Monitoring ACPI Device
      PNP0C02                                           Thermal Monitoring ACPI Device
      TOS1900                                           Toshiba ACPI-Compliant Value Added Logical and General Purpose Device
      TOS1102                                           Toshiba PS/2 Keyboard
      THERMALZONE                                         ACPI
      FIXEDBUTTON                                          ACPI

     USB:
      0BDA 0138                                         Realtek USB 2.0 Card Reader
      04F2 B289                                         TOSHIBA Web Camera - MP
      04B4 0060                                         USB- 
      04B4 0060                                         USB- 
      04B4 0060                                          USB 
      04F2 B289                                          USB 

    :
      COM3                                              LGE Bluetooth TransPort (COM3)


--------[  PCI ]----------------------------------------------------------------------------------------------

  [ AMD Hudson-2 FCH - High Definition Audio Controller ]

     :
                                      AMD Hudson-2 FCH - High Definition Audio Controller
                                                 PCI
       /  /                        0 / 20 / 2
      ID                                      1022-780D
                               1179-FC50
                                         0403 (High Definition Audio)
                                                  01
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD Hudson-2 FCH - LPC Bridge ]

     :
                                      AMD Hudson-2 FCH - LPC Bridge
                                                 PCI
       /  /                        0 / 20 / 3
      ID                                      1022-780E
                               1179-FC50
                                         0601 (PCI/ISA Bridge)
                                                  11
      Fast Back-to-Back Transactions                     

     :
      66-                                    
      Bus Mastering                                     

  [ AMD Hudson-2 FCH - PCI-PCI Host Bridge ]

     :
                                      AMD Hudson-2 FCH - PCI-PCI Host Bridge
                                                 PCI
       /  /                        0 / 20 / 4
      ID                                      1022-780F
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  40
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ AMD Hudson-2 FCH - SATA AHCI Controller ]

     :
                                      AMD Hudson-2 FCH - SATA AHCI Controller
                                                 PCI
       /  /                        0 / 17 / 0
      ID                                      1022-7801
                               1179-FC50
                                         0106 (SATA Controller)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                    
      Bus Mastering                                     

  [ AMD Hudson-2 FCH - SMBus and ACPI Controller ]

     :
                                      AMD Hudson-2 FCH - SMBus and ACPI Controller
                                                 PCI
       /  /                        0 / 20 / 0
      ID                                      1022-780B
                               1179-FC50
                                         0C05 (SMBus Controller)
                                                  13
      Fast Back-to-Back Transactions                     

     :
      66-                                    
      Bus Mastering                                     

  [ AMD Hudson-2 FCH - USB 2.0 EHCI Controller ]

     :
                                      AMD Hudson-2 FCH - USB 2.0 EHCI Controller
                                                 PCI
       /  /                        0 / 18 / 2
      ID                                      1022-7808
                               1179-FC50
                                         0C03 (USB Controller)
                                                  11
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ AMD Hudson-2 FCH - USB 2.0 EHCI Controller ]

     :
                                      AMD Hudson-2 FCH - USB 2.0 EHCI Controller
                                                 PCI
       /  /                        0 / 19 / 2
      ID                                      1022-7808
                               1179-FC50
                                         0C03 (USB Controller)
                                                  11
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ AMD Hudson-2 FCH - USB 2.0 EHCI Controller ]

     :
                                      AMD Hudson-2 FCH - USB 2.0 EHCI Controller
                                                 PCI
       /  /                        0 / 22 / 2
      ID                                      1022-7808
                               1179-FC50
                                         0C03 (USB Controller)
                                                  11
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ AMD Hudson-2 FCH - USB OHCI Controller ]

     :
                                      AMD Hudson-2 FCH - USB OHCI Controller
                                                 PCI
       /  /                        0 / 18 / 0
      ID                                      1022-7807
                               1179-FC50
                                         0C03 (USB Controller)
                                                  11
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ AMD Hudson-2 FCH - USB OHCI Controller ]

     :
                                      AMD Hudson-2 FCH - USB OHCI Controller
                                                 PCI
       /  /                        0 / 19 / 0
      ID                                      1022-7807
                               1179-FC50
                                         0C03 (USB Controller)
                                                  11
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ AMD Hudson-2 FCH - USB OHCI Controller ]

     :
                                      AMD Hudson-2 FCH - USB OHCI Controller
                                                 PCI
       /  /                        0 / 20 / 5
      ID                                      1022-7809
                               1179-FC50
                                         0C03 (USB Controller)
                                                  11
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ AMD Hudson-2 FCH - USB OHCI Controller ]

     :
                                      AMD Hudson-2 FCH - USB OHCI Controller
                                                 PCI
       /  /                        0 / 22 / 0
      ID                                      1022-7807
                               1179-FC50
                                         0C03 (USB Controller)
                                                  11
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ AMD K12 - Address Map ]

     :
                                      AMD K12 - Address Map
                                                 PCI
       /  /                        0 / 24 / 1
      ID                                      1022-1701
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K12 - DRAM Controller ]

     :
                                      AMD K12 - DRAM Controller
                                                 PCI
       /  /                        0 / 24 / 2
      ID                                      1022-1702
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K12 - Extended Miscellaneous Control ]

     :
                                      AMD K12 - Extended Miscellaneous Control
                                                 PCI
       /  /                        0 / 24 / 4
      ID                                      1022-1704
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K12 - High Definition Audio Controller ]

     :
                                      AMD K12 - High Definition Audio Controller
                                                 PCI Express 2.0
       /  /                        0 / 1 / 1
      ID                                      1002-1714
                               1002-1714
                                         0403 (High Definition Audio)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K12 - Link Control ]

     :
                                      AMD K12 - Link Control
                                                 PCI
       /  /                        0 / 24 / 0
      ID                                      1022-1700
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  43
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K12 - Miscellaneous Control ]

     :
                                      AMD K12 - Miscellaneous Control
                                                 PCI
       /  /                        0 / 24 / 3
      ID                                      1022-1703
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K12 - Miscellaneous Control ]

     :
                                      AMD K12 - Miscellaneous Control
                                                 PCI
       /  /                        0 / 24 / 5
      ID                                      1022-1718
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K12 - Miscellaneous Control ]

     :
                                      AMD K12 - Miscellaneous Control
                                                 PCI
       /  /                        0 / 24 / 6
      ID                                      1022-1716
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K12 - Miscellaneous Control ]

     :
                                      AMD K12 - Miscellaneous Control
                                                 PCI
       /  /                        0 / 24 / 7
      ID                                      1022-1719
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K12 - PCI Express Root Port ]

     :
                                      AMD K12 - PCI Express Root Port
                                                 PCI
       /  /                        0 / 2 / 0
      ID                                      1022-1707
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K12 - PCI Express Root Port ]

     :
                                      AMD K12 - PCI Express Root Port
                                                 PCI
       /  /                        0 / 4 / 0
      ID                                      1022-1709
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K12 - PCI Express Root Port ]

     :
                                      AMD K12 - PCI Express Root Port
                                                 PCI
       /  /                        0 / 5 / 0
      ID                                      1022-170A
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K12 - Root Complex ]

     :
                                      AMD K12 - Root Complex
                                                 PCI
       /  /                        0 / 0 / 0
      ID                                      1022-1705
                               1022-1705
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                    
      Bus Mastering                                     

  [ AMD Radeon HD 6450M/6470M/6490M (Seymour) Video Adapter ]

     :
                                      AMD Radeon HD 6450M/6470M/6490M (Seymour) Video Adapter
                                                 PCI Express 2.0 x16
       /  /                        1 / 0 / 0
      ID                                      1002-6760
                               1179-FC51
                                         0300 (VGA Display Controller)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates

  [ AMD Radeon HD 6520G (Sumo) Video Adapter ]

     :
                                      AMD Radeon HD 6520G (Sumo) Video Adapter
                                                 PCI Express 2.0
       /  /                        0 / 1 / 0
      ID                                      1002-9647
                               1179-FC51
                                         0300 (VGA Display Controller)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates

  [ Atheros AR8152/8158 PCI-E Fast Ethernet Controller ]

     :
                                      Atheros AR8152/8158 PCI-E Fast Ethernet Controller
                                                 PCI Express 1.0 x1
       /  /                        2 / 0 / 0
      ID                                      1969-2062
                               1179-FC50
                                         0200 (Ethernet Controller)
                                                  C1
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

      :
                                                   Atheros Communications, Inc.
                                     http://www.atheros.com/networking
                                       http://www.atheros.com
                                     http://www.aida64.com/driver-updates

  [ Realtek RTL8188CE Wireless LAN 802.11n PCI-E Network Adapter ]

     :
                                      Realtek RTL8188CE Wireless LAN 802.11n PCI-E Network Adapter
                                                 PCI Express 2.0 x1
       /  /                        3 / 0 / 0
      ID                                      10EC-8176
                               10EC-8181
                                         0280 (Network Controller)
                                                  01
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     


--------[  USB ]----------------------------------------------------------------------------------------------

  [  USB  (USB Device) ]

     :
                                       USB 
      ID                                      04B4-0060
                                         03 / 01 (Human Interface Device)
                                      02
                                           Areson
                                                 USB-
        USB                         1.10
                                         Low  (USB 1.1)

  [ Realtek USB 2.0 Card Reader (USB2.0-CRW) ]

     :
                                      Realtek USB 2.0 Card Reader
      ID                                      0BDA-0138
                                         08 / 06 (Mass Storage)
                                      50
                                           Generic
                                                 USB2.0-CRW
                                           20090516388200000
        USB                         2.00
                                         High  (USB 2.0)

  [  USB  ]

     :
                                       USB 
      ID                                      04F2-B289
                                         EF / 02 (Interface Association Descriptor)
                                      01
        USB                         2.00
                                         High  (USB 2.0)


--------[   ]-------------------------------------------------------------------------------------------

    IRQ 01                                 PS/2
    IRQ 100                              Microsoft ACPI- 
    IRQ 101                              Microsoft ACPI- 
    IRQ 102                              Microsoft ACPI- 
    IRQ 103                              Microsoft ACPI- 
    IRQ 104                              Microsoft ACPI- 
    IRQ 105                              Microsoft ACPI- 
    IRQ 106                              Microsoft ACPI- 
    IRQ 107                              Microsoft ACPI- 
    IRQ 108                              Microsoft ACPI- 
    IRQ 109                              Microsoft ACPI- 
    IRQ 110                              Microsoft ACPI- 
    IRQ 111                              Microsoft ACPI- 
    IRQ 112                              Microsoft ACPI- 
    IRQ 113                              Microsoft ACPI- 
    IRQ 114                              Microsoft ACPI- 
    IRQ 115                              Microsoft ACPI- 
    IRQ 116                              Microsoft ACPI- 
    IRQ 117                              Microsoft ACPI- 
    IRQ 118                              Microsoft ACPI- 
    IRQ 119                              Microsoft ACPI- 
    IRQ 12                               Synaptics PS/2 Port Compatible TouchPad
    IRQ 120                              Microsoft ACPI- 
    IRQ 121                              Microsoft ACPI- 
    IRQ 122                              Microsoft ACPI- 
    IRQ 123                              Microsoft ACPI- 
    IRQ 124                              Microsoft ACPI- 
    IRQ 125                              Microsoft ACPI- 
    IRQ 126                              Microsoft ACPI- 
    IRQ 127                              Microsoft ACPI- 
    IRQ 128                              Microsoft ACPI- 
    IRQ 129                              Microsoft ACPI- 
    IRQ 130                              Microsoft ACPI- 
    IRQ 131                              Microsoft ACPI- 
    IRQ 132                              Microsoft ACPI- 
    IRQ 133                              Microsoft ACPI- 
    IRQ 134                              Microsoft ACPI- 
    IRQ 135                              Microsoft ACPI- 
    IRQ 136                              Microsoft ACPI- 
    IRQ 137                              Microsoft ACPI- 
    IRQ 138                              Microsoft ACPI- 
    IRQ 139                              Microsoft ACPI- 
    IRQ 140                              Microsoft ACPI- 
    IRQ 141                              Microsoft ACPI- 
    IRQ 142                              Microsoft ACPI- 
    IRQ 143                              Microsoft ACPI- 
    IRQ 144                              Microsoft ACPI- 
    IRQ 145                              Microsoft ACPI- 
    IRQ 146                              Microsoft ACPI- 
    IRQ 147                              Microsoft ACPI- 
    IRQ 148                              Microsoft ACPI- 
    IRQ 149                              Microsoft ACPI- 
    IRQ 150                              Microsoft ACPI- 
    IRQ 151                              Microsoft ACPI- 
    IRQ 152                              Microsoft ACPI- 
    IRQ 153                              Microsoft ACPI- 
    IRQ 154                              Microsoft ACPI- 
    IRQ 155                              Microsoft ACPI- 
    IRQ 156                              Microsoft ACPI- 
    IRQ 157                              Microsoft ACPI- 
    IRQ 158                              Microsoft ACPI- 
    IRQ 159                              Microsoft ACPI- 
    IRQ 16                                        Qualcomm Atheros AR8152 PCI-E Fast Ethernet Controller (NDIS 6.30)
    IRQ 16                                         High Definition Audio (Microsoft)
    IRQ 160                              Microsoft ACPI- 
    IRQ 161                              Microsoft ACPI- 
    IRQ 162                              Microsoft ACPI- 
    IRQ 163                              Microsoft ACPI- 
    IRQ 164                              Microsoft ACPI- 
    IRQ 165                              Microsoft ACPI- 
    IRQ 166                              Microsoft ACPI- 
    IRQ 167                              Microsoft ACPI- 
    IRQ 168                              Microsoft ACPI- 
    IRQ 169                              Microsoft ACPI- 
    IRQ 17                                        Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC
    IRQ 17                                          PCI - USB -
    IRQ 17                                          PCI - USB -
    IRQ 17                                          PCI - USB -
    IRQ 17                                          PCI - PCI
    IRQ 170                              Microsoft ACPI- 
    IRQ 171                              Microsoft ACPI- 
    IRQ 172                              Microsoft ACPI- 
    IRQ 173                              Microsoft ACPI- 
    IRQ 174                              Microsoft ACPI- 
    IRQ 175                              Microsoft ACPI- 
    IRQ 176                              Microsoft ACPI- 
    IRQ 177                              Microsoft ACPI- 
    IRQ 178                              Microsoft ACPI- 
    IRQ 179                              Microsoft ACPI- 
    IRQ 18                                         OpenHCD USB -
    IRQ 18                                         OpenHCD USB -
    IRQ 18                                         OpenHCD USB -
    IRQ 18                                         OpenHCD USB -
    IRQ 18                                          PCI - PCI
    IRQ 18                                          PCI - PCI
    IRQ 180                              Microsoft ACPI- 
    IRQ 181                              Microsoft ACPI- 
    IRQ 182                              Microsoft ACPI- 
    IRQ 183                              Microsoft ACPI- 
    IRQ 184                              Microsoft ACPI- 
    IRQ 185                              Microsoft ACPI- 
    IRQ 186                              Microsoft ACPI- 
    IRQ 187                              Microsoft ACPI- 
    IRQ 188                              Microsoft ACPI- 
    IRQ 189                              Microsoft ACPI- 
    IRQ 19                                         High Definition Audio (Microsoft)
    IRQ 19                                        AMD SATA Controller
    IRQ 190                              Microsoft ACPI- 
    IRQ 191                              Microsoft ACPI- 
    IRQ 256                              Microsoft ACPI- 
    IRQ 257                              Microsoft ACPI- 
    IRQ 258                              Microsoft ACPI- 
    IRQ 259                              Microsoft ACPI- 
    IRQ 260                              Microsoft ACPI- 
    IRQ 261                              Microsoft ACPI- 
    IRQ 262                              Microsoft ACPI- 
    IRQ 263                              Microsoft ACPI- 
    IRQ 264                              Microsoft ACPI- 
    IRQ 265                              Microsoft ACPI- 
    IRQ 266                              Microsoft ACPI- 
    IRQ 267                              Microsoft ACPI- 
    IRQ 268                              Microsoft ACPI- 
    IRQ 269                              Microsoft ACPI- 
    IRQ 270                              Microsoft ACPI- 
    IRQ 271                              Microsoft ACPI- 
    IRQ 272                              Microsoft ACPI- 
    IRQ 273                              Microsoft ACPI- 
    IRQ 274                              Microsoft ACPI- 
    IRQ 275                              Microsoft ACPI- 
    IRQ 276                              Microsoft ACPI- 
    IRQ 277                              Microsoft ACPI- 
    IRQ 278                              Microsoft ACPI- 
    IRQ 279                              Microsoft ACPI- 
    IRQ 280                              Microsoft ACPI- 
    IRQ 281                              Microsoft ACPI- 
    IRQ 282                              Microsoft ACPI- 
    IRQ 283                              Microsoft ACPI- 
    IRQ 284                              Microsoft ACPI- 
    IRQ 285                              Microsoft ACPI- 
    IRQ 286                              Microsoft ACPI- 
    IRQ 287                              Microsoft ACPI- 
    IRQ 288                              Microsoft ACPI- 
    IRQ 289                              Microsoft ACPI- 
    IRQ 290                              Microsoft ACPI- 
    IRQ 291                              Microsoft ACPI- 
    IRQ 292                              Microsoft ACPI- 
    IRQ 293                              Microsoft ACPI- 
    IRQ 294                              Microsoft ACPI- 
    IRQ 295                              Microsoft ACPI- 
    IRQ 296                              Microsoft ACPI- 
    IRQ 297                              Microsoft ACPI- 
    IRQ 298                              Microsoft ACPI- 
    IRQ 299                              Microsoft ACPI- 
    IRQ 300                              Microsoft ACPI- 
    IRQ 301                              Microsoft ACPI- 
    IRQ 302                              Microsoft ACPI- 
    IRQ 303                              Microsoft ACPI- 
    IRQ 304                              Microsoft ACPI- 
    IRQ 305                              Microsoft ACPI- 
    IRQ 306                              Microsoft ACPI- 
    IRQ 307                              Microsoft ACPI- 
    IRQ 308                              Microsoft ACPI- 
    IRQ 309                              Microsoft ACPI- 
    IRQ 310                              Microsoft ACPI- 
    IRQ 311                              Microsoft ACPI- 
    IRQ 312                              Microsoft ACPI- 
    IRQ 313                              Microsoft ACPI- 
    IRQ 314                              Microsoft ACPI- 
    IRQ 315                              Microsoft ACPI- 
    IRQ 316                              Microsoft ACPI- 
    IRQ 317                              Microsoft ACPI- 
    IRQ 318                              Microsoft ACPI- 
    IRQ 319                              Microsoft ACPI- 
    IRQ 320                              Microsoft ACPI- 
    IRQ 321                              Microsoft ACPI- 
    IRQ 322                              Microsoft ACPI- 
    IRQ 323                              Microsoft ACPI- 
    IRQ 324                              Microsoft ACPI- 
    IRQ 325                              Microsoft ACPI- 
    IRQ 326                              Microsoft ACPI- 
    IRQ 327                              Microsoft ACPI- 
    IRQ 328                              Microsoft ACPI- 
    IRQ 329                              Microsoft ACPI- 
    IRQ 330                              Microsoft ACPI- 
    IRQ 331                              Microsoft ACPI- 
    IRQ 332                              Microsoft ACPI- 
    IRQ 333                              Microsoft ACPI- 
    IRQ 334                              Microsoft ACPI- 
    IRQ 335                              Microsoft ACPI- 
    IRQ 336                              Microsoft ACPI- 
    IRQ 337                              Microsoft ACPI- 
    IRQ 338                              Microsoft ACPI- 
    IRQ 339                              Microsoft ACPI- 
    IRQ 340                              Microsoft ACPI- 
    IRQ 341                              Microsoft ACPI- 
    IRQ 342                              Microsoft ACPI- 
    IRQ 343                              Microsoft ACPI- 
    IRQ 344                              Microsoft ACPI- 
    IRQ 345                              Microsoft ACPI- 
    IRQ 346                              Microsoft ACPI- 
    IRQ 347                              Microsoft ACPI- 
    IRQ 348                              Microsoft ACPI- 
    IRQ 349                              Microsoft ACPI- 
    IRQ 350                              Microsoft ACPI- 
    IRQ 351                              Microsoft ACPI- 
    IRQ 352                              Microsoft ACPI- 
    IRQ 353                              Microsoft ACPI- 
    IRQ 354                              Microsoft ACPI- 
    IRQ 355                              Microsoft ACPI- 
    IRQ 356                              Microsoft ACPI- 
    IRQ 357                              Microsoft ACPI- 
    IRQ 358                              Microsoft ACPI- 
    IRQ 359                              Microsoft ACPI- 
    IRQ 360                              Microsoft ACPI- 
    IRQ 361                              Microsoft ACPI- 
    IRQ 362                              Microsoft ACPI- 
    IRQ 363                              Microsoft ACPI- 
    IRQ 364                              Microsoft ACPI- 
    IRQ 365                              Microsoft ACPI- 
    IRQ 366                              Microsoft ACPI- 
    IRQ 367                              Microsoft ACPI- 
    IRQ 368                              Microsoft ACPI- 
    IRQ 369                              Microsoft ACPI- 
    IRQ 370                              Microsoft ACPI- 
    IRQ 371                              Microsoft ACPI- 
    IRQ 372                              Microsoft ACPI- 
    IRQ 373                              Microsoft ACPI- 
    IRQ 374                              Microsoft ACPI- 
    IRQ 375                              Microsoft ACPI- 
    IRQ 376                              Microsoft ACPI- 
    IRQ 377                              Microsoft ACPI- 
    IRQ 378                              Microsoft ACPI- 
    IRQ 379                              Microsoft ACPI- 
    IRQ 380                              Microsoft ACPI- 
    IRQ 381                              Microsoft ACPI- 
    IRQ 382                              Microsoft ACPI- 
    IRQ 383                              Microsoft ACPI- 
    IRQ 384                              Microsoft ACPI- 
    IRQ 385                              Microsoft ACPI- 
    IRQ 386                              Microsoft ACPI- 
    IRQ 387                              Microsoft ACPI- 
    IRQ 388                              Microsoft ACPI- 
    IRQ 389                              Microsoft ACPI- 
    IRQ 390                              Microsoft ACPI- 
    IRQ 391                              Microsoft ACPI- 
    IRQ 392                              Microsoft ACPI- 
    IRQ 393                              Microsoft ACPI- 
    IRQ 394                              Microsoft ACPI- 
    IRQ 395                              Microsoft ACPI- 
    IRQ 396                              Microsoft ACPI- 
    IRQ 397                              Microsoft ACPI- 
    IRQ 398                              Microsoft ACPI- 
    IRQ 399                              Microsoft ACPI- 
    IRQ 400                              Microsoft ACPI- 
    IRQ 401                              Microsoft ACPI- 
    IRQ 402                              Microsoft ACPI- 
    IRQ 403                              Microsoft ACPI- 
    IRQ 404                              Microsoft ACPI- 
    IRQ 405                              Microsoft ACPI- 
    IRQ 406                              Microsoft ACPI- 
    IRQ 407                              Microsoft ACPI- 
    IRQ 408                              Microsoft ACPI- 
    IRQ 409                              Microsoft ACPI- 
    IRQ 410                              Microsoft ACPI- 
    IRQ 411                              Microsoft ACPI- 
    IRQ 412                              Microsoft ACPI- 
    IRQ 413                              Microsoft ACPI- 
    IRQ 414                              Microsoft ACPI- 
    IRQ 415                              Microsoft ACPI- 
    IRQ 416                              Microsoft ACPI- 
    IRQ 417                              Microsoft ACPI- 
    IRQ 418                              Microsoft ACPI- 
    IRQ 419                              Microsoft ACPI- 
    IRQ 420                              Microsoft ACPI- 
    IRQ 421                              Microsoft ACPI- 
    IRQ 422                              Microsoft ACPI- 
    IRQ 423                              Microsoft ACPI- 
    IRQ 424                              Microsoft ACPI- 
    IRQ 425                              Microsoft ACPI- 
    IRQ 426                              Microsoft ACPI- 
    IRQ 427                              Microsoft ACPI- 
    IRQ 428                              Microsoft ACPI- 
    IRQ 429                              Microsoft ACPI- 
    IRQ 430                              Microsoft ACPI- 
    IRQ 431                              Microsoft ACPI- 
    IRQ 432                              Microsoft ACPI- 
    IRQ 433                              Microsoft ACPI- 
    IRQ 434                              Microsoft ACPI- 
    IRQ 435                              Microsoft ACPI- 
    IRQ 436                              Microsoft ACPI- 
    IRQ 437                              Microsoft ACPI- 
    IRQ 438                              Microsoft ACPI- 
    IRQ 439                              Microsoft ACPI- 
    IRQ 440                              Microsoft ACPI- 
    IRQ 441                              Microsoft ACPI- 
    IRQ 442                              Microsoft ACPI- 
    IRQ 443                              Microsoft ACPI- 
    IRQ 444                              Microsoft ACPI- 
    IRQ 445                              Microsoft ACPI- 
    IRQ 446                              Microsoft ACPI- 
    IRQ 447                              Microsoft ACPI- 
    IRQ 448                              Microsoft ACPI- 
    IRQ 449                              Microsoft ACPI- 
    IRQ 450                              Microsoft ACPI- 
    IRQ 451                              Microsoft ACPI- 
    IRQ 452                              Microsoft ACPI- 
    IRQ 453                              Microsoft ACPI- 
    IRQ 454                              Microsoft ACPI- 
    IRQ 455                              Microsoft ACPI- 
    IRQ 456                              Microsoft ACPI- 
    IRQ 457                              Microsoft ACPI- 
    IRQ 458                              Microsoft ACPI- 
    IRQ 459                              Microsoft ACPI- 
    IRQ 460                              Microsoft ACPI- 
    IRQ 461                              Microsoft ACPI- 
    IRQ 462                              Microsoft ACPI- 
    IRQ 463                              Microsoft ACPI- 
    IRQ 464                              Microsoft ACPI- 
    IRQ 465                              Microsoft ACPI- 
    IRQ 466                              Microsoft ACPI- 
    IRQ 467                              Microsoft ACPI- 
    IRQ 468                              Microsoft ACPI- 
    IRQ 469                              Microsoft ACPI- 
    IRQ 470                              Microsoft ACPI- 
    IRQ 471                              Microsoft ACPI- 
    IRQ 472                              Microsoft ACPI- 
    IRQ 473                              Microsoft ACPI- 
    IRQ 474                              Microsoft ACPI- 
    IRQ 475                              Microsoft ACPI- 
    IRQ 476                              Microsoft ACPI- 
    IRQ 477                              Microsoft ACPI- 
    IRQ 478                              Microsoft ACPI- 
    IRQ 479                              Microsoft ACPI- 
    IRQ 480                              Microsoft ACPI- 
    IRQ 481                              Microsoft ACPI- 
    IRQ 482                              Microsoft ACPI- 
    IRQ 483                              Microsoft ACPI- 
    IRQ 484                              Microsoft ACPI- 
    IRQ 485                              Microsoft ACPI- 
    IRQ 486                              Microsoft ACPI- 
    IRQ 487                              Microsoft ACPI- 
    IRQ 488                              Microsoft ACPI- 
    IRQ 489                              Microsoft ACPI- 
    IRQ 490                              Microsoft ACPI- 
    IRQ 491                              Microsoft ACPI- 
    IRQ 492                              Microsoft ACPI- 
    IRQ 493                              Microsoft ACPI- 
    IRQ 494                              Microsoft ACPI- 
    IRQ 495                              Microsoft ACPI- 
    IRQ 496                              Microsoft ACPI- 
    IRQ 497                              Microsoft ACPI- 
    IRQ 498                              Microsoft ACPI- 
    IRQ 499                              Microsoft ACPI- 
    IRQ 500                              Microsoft ACPI- 
    IRQ 501                              Microsoft ACPI- 
    IRQ 502                              Microsoft ACPI- 
    IRQ 503                              Microsoft ACPI- 
    IRQ 504                              Microsoft ACPI- 
    IRQ 505                              Microsoft ACPI- 
    IRQ 506                              Microsoft ACPI- 
    IRQ 507                              Microsoft ACPI- 
    IRQ 508                              Microsoft ACPI- 
    IRQ 509                              Microsoft ACPI- 
    IRQ 510                              Microsoft ACPI- 
    IRQ 511                              Microsoft ACPI- 
    IRQ 65536                            AMD Radeon HD 6520G
    IRQ 65536                            AMD Radeon HD 7400M Series
    IRQ 81                               Microsoft ACPI- 
    IRQ 82                               Microsoft ACPI- 
    IRQ 83                               Microsoft ACPI- 
    IRQ 84                               Microsoft ACPI- 
    IRQ 85                               Microsoft ACPI- 
    IRQ 86                               Microsoft ACPI- 
    IRQ 87                               Microsoft ACPI- 
    IRQ 88                               Microsoft ACPI- 
    IRQ 89                               Microsoft ACPI- 
    IRQ 90                               Microsoft ACPI- 
    IRQ 91                               Microsoft ACPI- 
    IRQ 92                               Microsoft ACPI- 
    IRQ 93                               Microsoft ACPI- 
    IRQ 94                               Microsoft ACPI- 
    IRQ 95                               Microsoft ACPI- 
    IRQ 96                               Microsoft ACPI- 
    IRQ 97                               Microsoft ACPI- 
    IRQ 98                               Microsoft ACPI- 
    IRQ 99                               Microsoft ACPI- 
     000A0000-000BFFFF                      AMD Radeon HD 6520G
     000A0000-000BFFFF                      PCI Express Root Complex
     000C0000-000C3FFF                      PCI Express Root Complex
     000C4000-000C7FFF                      PCI Express Root Complex
     000C8000-000CBFFF                      PCI Express Root Complex
     000CC000-000CFFFF                      PCI Express Root Complex
     000D0000-000D3FFF                      PCI Express Root Complex
     000D4000-000D7FFF                      PCI Express Root Complex
     000D8000-000DBFFF                      PCI Express Root Complex
     000DC000-000DFFFF                      PCI Express Root Complex
     000E0000-000E3FFF                      PCI Express Root Complex
     000E4000-000E7FFF                      PCI Express Root Complex
     000E8000-000EBFFF                      PCI Express Root Complex
     000EC000-000EFFFF                      PCI Express Root Complex
     D0000000-DFFFFFFF             AMD Radeon HD 6520G
     D0000000-F7FFFFFF                      PCI Express Root Complex
     E0000000-EFFFFFFF             AMD Radeon HD 7400M Series
     E0000000-EFFFFFFF               PCI - PCI
     F0000000-F0003FFF             Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC
     F0000000-F00FFFFF               PCI - PCI
     F0100000-F013FFFF             Qualcomm Atheros AR8152 PCI-E Fast Ethernet Controller (NDIS 6.30)
     F0100000-F01FFFFF               PCI - PCI
     F0200000-F02FFFFF               PCI - PCI
     F02E0000-F02FFFFF             AMD Radeon HD 7400M Series
     F0300000-F033FFFF             AMD Radeon HD 6520G
     F0340000-F0343FFF              High Definition Audio (Microsoft)
     F0344000-F0347FFF              High Definition Audio (Microsoft)
     F0348000-F03480FF               PCI - USB -
     F0349000-F0349FFF              OpenHCD USB -
     F034A000-F034AFFF              OpenHCD USB -
     F034B000-F034B0FF               PCI - USB -
     F034C000-F034CFFF              OpenHCD USB -
     F034D000-F034D0FF               PCI - USB -
     F034E000-F034EFFF              OpenHCD USB -
     F034F000-F034F7FF             AMD SATA Controller
     FC000000-FFFFFFFF                      PCI Express Root Complex
     0000-0CF7                                PCI Express Root Complex
     0060-0060                         PS/2
     0062-0062                       Microsoft ACPI-  
     0064-0064                         PS/2
     0066-0066                       Microsoft ACPI-  
     0070-0071                       CMOS  
     03B0-03BB                                AMD Radeon HD 6520G
     03C0-03DF                                AMD Radeon HD 6520G
     0D00-FFFF                                PCI Express Root Complex
     2000-20FF                       Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC
     2000-2FFF                         PCI - PCI
     3000-307F                       Qualcomm Atheros AR8152 PCI-E Fast Ethernet Controller (NDIS 6.30)
     3000-3FFF                         PCI - PCI
     4000-4FFF                         PCI - PCI
     4F00-4FFF                       AMD Radeon HD 7400M Series
     5000-50FF                       AMD Radeon HD 6520G
     5100-510F                       AMD SATA Controller
     5110-5117                       AMD SATA Controller
     5118-511F                       AMD SATA Controller
     5120-5123                       AMD SATA Controller
     5124-5127                       AMD SATA Controller


--------[  ]--------------------------------------------------------------------------------------------------------

  [   PS/2 ]

     :
                                        PS/2
                                           Japanese keyboard
                                     US
        ANSI                             1251 -  (Windows)
        OEM                              866 -  (DOS)
                                         1
                                         31

  [ HID-  ]

     :
                                            HID- 
                                         8
                                              
                                         1
                                     500 msec
       X / Y                                       6 / 10
                                 3

     :
                               
      ''                                
                
                                            
                   
                                              
      Sonar                                             


--------[  ]----------------------------------------------------------------------------------------------------

  [ Fax ]

     :
                                             Fax
                                      
                                  
                                            SHRFAX:
                                         Microsoft Shared Fax Driver (v4.00)
                                           Fax
                                         winprint
                                     
                                             5:00 - 5:00
                                               1
                                 0
                                                  

     :
                                            Letter, 8.5 x 11 in
                                              
                                          200 x 200 dpi Mono

  [ HP ePrint ( ) ]

     :
                                             HP ePrint
                                      
                                  
                                            LPT1:
                                         HP ePrint (v1.04)
                                           HP ePrint
                                         winprint
                                     
                                             
                                               1
                                 0
                                                  

     :
                                            A4, 210 x 297 mm
                                              
                                          Low Color

     :
                                                   Hewlett-Packard Company
                                     http://www.hp.com/united-states/consumer/gateway/printing_multifunction.html
                                     http://www.aida64.com/driver-updates

  [ HP LaserJet Professional CP1020 Series ]

     :
                                             HP LaserJet Professional CP1020 Series
                                      
                                  
                                            HPTCPIP_192.168.1.103
                                         HP LaserJet Professional CP1020 Series (v0.03)
                                           HP LaserJet Professional CP1020
                                             Network Printer
                                         HPCP1020PP
                                     
                                             
                                               1
                                 0
                                                  

     :
                                            A4, 210 x 297 mm
                                              
                                          600 dpi Color

     :
                                                   Hewlett-Packard Company
                                     http://www.hp.com/united-states/consumer/gateway/printing_multifunction.html
                                     http://www.aida64.com/driver-updates

  [ Microsoft XPS Document Writer ]

     :
                                             Microsoft XPS Document Writer
                                      
                                  
                                            PORTPROMPT:
                                         Microsoft XPS Document Writer v4 (v6.03)
                                           Microsoft XPS Document Writer
                                         winprint
                                     
                                             5:00 - 5:00
                                               1
                                 0
                                                  

     :
                                            A4, 210 x 297 mm
                                              
                                          600 x 600 dpi Color

  [ NPIA72351 (HP LaserJet CP1025nw) ]

     :
                                             NPIA72351 (HP LaserJet CP1025nw)
                                      
                                  
                                            WSD-47238b24-08f3-42c9-9d47-63a34ba5def7.0069
                                         HP LaserJet PCLmS Class Driver (v6.03)
                                           NPIA72351 (HP LaserJet CP1025nw
                                         winprint
                                     
                                             
                                               1
                                 0
                                                  Offline

     :
                                            A4, 210 x 297 mm
                                              
                                          600 x 600 dpi Color

     :
                                                   Hewlett-Packard Company
                                     http://www.hp.com/united-states/consumer/gateway/printing_multifunction.html
                                     http://www.aida64.com/driver-updates

  [   OneNote 2013 ]

     :
                                               OneNote 2013
                                      
                                  
                                            nul:
                                         Send to Microsoft OneNote 15 Driver (v6.03)
                                             OneNote 2013
                                         winprint
                                     
                                             
                                               1
                                 0
                                                  

     :
                                            A4, 210 x 297 mm
                                              
                                          600 x 600 dpi Color


--------[  ]------------------------------------------------------------------------------------------------

    ADSKAppManager                     Registry\Common\Run      C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe -showminimized -checkautorun
    Advanced SystemCare 7              Registry\User\Run        C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe /Auto
    Application Restart #0             Registry\User\RunOnce    C:\Users\Black_SOKOL\AppData\Local\Yandex\YandexBrowser\Application\browser.exe --flag-switches-begin --flag-switches-end --disable-ssl-false-start --disable-webkit-media-source --disable-direct-npapi-requests --disable-client-side-phishing-detection --disable-breadcrumbs-api --google-profile-info --disable-sync-search-engines --disable-sync-tabs --disable-sync-favicons --disable-sync-themes --sync-try-ssltcp-first-for-xmpp --restore-last-session
    Autodesk Sync                      Registry\User\Run        C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe 
    AvastUI.exe                        Registry\Common\Run      C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui
    Azureus                            Registry\User\Run        C:\Program Files\Vuze\Azureus.exe 
    Browser Manager                    Registry\User\Run        C:\Users\Black_SOKOL\AppData\Local\Yandex\Updater2\BrowserManager.exe 
    DAEMON Tools Lite                  Registry\User\Run        C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun
    Download Master                    Registry\Common\Run      C:\Program Files (x86)\Download Master\dmaster.exe -autorun
    Game Assistant                     StartMenu\User           C:\Program Files (x86)\IObit\Game Assistant\GameAssistant.exe /autorun
    GameCenterMailRu                   Registry\User\Run        C:\Users\Black_SOKOL\AppData\Local\Mail.Ru\GameCenter\GameCenter@Mail.Ru.exe -autostart
    Hee-SoftPack                       Registry\User\Run        E:\ \Hee-SoftPackv3\hsp.exe /autorun
    Smart Defrag 3                     StartMenu\User           C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe 
    StartCCC                           Registry\Common\Run      C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe MSRun
    SunJavaUpdateSched                 Registry\Common\Run      C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe 
    SyncManPath                        Registry\User\Run        C:\Users\Black_SOKOL\AppData\Roaming\Yandex\YandexDisk\YandexDisk.exe -autostart
    SynTPEnh                           Registry\Common\Run      %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe 
    USB Safely Remove                  Registry\User\Run        C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe /startup
    YandexElements                     Registry\User\Run        C:\Users\Black_SOKOL\AppData\Local\Yandex\Elements\elements.exe \8.4.0.9140\elements64.exe" /auto


--------[  ]---------------------------------------------------------------------------------------------

  [ AutoPico Daily Restart ]

     :
                                               AutoPico Daily Restart
                                                  
                                           "C:\Program Files\KMSpico\AutoPico.exe"
                                     /silent
                                            
                                             
                                        
                                               Black_SOKOL
                                         17.08.2014 17:28:59
                                         18.08.2014 11:59:00

     :
      Daily                                             At 11:59:00 every day - After triggered, repeat every 330 minutes for a duration of 12 hours

  [ HPLJCustParticipation ]

     :
                                               HPLJCustParticipation
                                                  
                                           "C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe"
                                     
                                            
                                             
                                        BLACK_SOKOL\Black_SOKOL
                                               Black_SOKOL
                                         17.08.2014 22:34:01
                                         17.08.2014 23:34:00

     :
      One time                                          At 10:34:00 on 27.07.2014 - After triggered, repeat every 1 hour indefinitely

  [ Optimize Start Menu Cache Files-S-1-5-21-2392427619-4168570856-2050312051-1001 ]

     :
                                               Optimize Start Menu Cache Files-S-1-5-21-2392427619-4168570856-2050312051-1001
                                                  
                                           
                                     
                                            
                                                   ,     "".         .
                                        Black_SOKOL
                                               Microsoft Corporation
                                         17.08.2014 18:14:38
                                         

     :
      On idle                                           When computer is idle


--------[   ]-------------------------------------------------------------------------------------

    7-Zip 9.22 (x64 edition)                                                                 9.22.00.0    {23170F69-40C1-2702-0922-000001000000}        Igor Pavlov                     2014-07-26
    8GadgetPack                                                                                 11.0.0    {32A7C3B0-E5C3-4913-B1F2-49FE860FAA5E}        Helmut Buhler                   2014-07-26
    Advanced SystemCare 7                                                                        7.3.0    Advanced SystemCare 7_is1                     IObit                           2014-08-17
    AIDA64 Extreme v4.60                                                                          4.60    AIDA64 Extreme_is1                            FinalWire Ltd.                  2014-08-17
    AIMP3                                                                             v3.55.1355, 14.07.2014    AIMP3                                         AIMP DevTeam                    2014-07-26
    AMD Catalyst Control Center                                                       2014.0704.2133.36938    {5D2B5E19-C333-4519-3D32-AAB8EEE9ACA4}        Advanced Micro Devices, Inc.    2014-07-26
    AMD Fuel                                                                          2014.0704.2133.36938    {E7ACB435-E0B4-4770-77DE-ED38887CD133}        Advanced Micro Devices, Inc.    2014-07-26
    AutoCAD 2015   (Russian) [ ()]                                      20.0.51.0    {5783F2D7-E001-0419-2102-0060B0CE6BBA}        Autodesk                        2014-07-27
    AutoCAD 2015   (Russian)                                                        20.0.104.0    {5783F2D7-E001-0000-0102-0060B0CE6BBA}        Autodesk                        2014-07-27
    AutoCAD 2015 Help   (Russian) [ ()]                                 20.0.51.0    {5783F2D7-E034-0419-0100-0060B0CE6BBA}        Autodesk                        2014-07-27
    AutoCAD 2015 Language Pack   (Russian) [ ()]                        20.0.51.0    {5783F2D7-E001-0419-1102-0060B0CE6BBA}        Autodesk                        2014-07-27
    AutoCAD 2015 VBA Enabler                                                                 20.0.51.0    {FD0595A7-C560-4967-0133-ADCE7EE7644D}        Autodesk                        2014-07-27
    AutoCAD Architecture 2015   (Russian) [ ()]                          7.7.49.0    {5783F2D7-E004-0419-2102-0060B0CE6BBA}        Autodesk                        2014-08-06
    AutoCAD Architecture 2015   (Russian) SP 1                                               1    AutoCAD Architecture 2015   (Russian) SP 1  Autodesk                                  
    AutoCAD Architecture 2015   (Russian)                                            7.7.104.0    {5783F2D7-E004-0000-0102-0060B0CE6BBA}        Autodesk                        2014-08-07
    AutoCAD Architecture 2015 Help -  (Russian) [ ()]                     7.7.49.0    {5783F2D7-E036-0419-0100-0060B0CE6BBA}        Autodesk                        2014-08-06
    AutoCAD Architecture 2015 Language Pack   (Russian) [ ()]            7.7.49.0    {5783F2D7-E004-0419-1102-0060B0CE6BBA}        Autodesk                        2014-08-06
    Autodesk 360 [ ()]                                                         5.1.4.1000    {556966D9-F7F6-421B-9707-D07901604DDF}        Autodesk                        2014-07-27
    Autodesk App Manager [ ()]                                                      1.2.0    {C8125548-F2D5-4059-823F-1F3C5BBD9F19}        Autodesk                        2014-07-27
    Autodesk Application Manager                                                             3.0.155.0    Autodesk Application Manager                  Autodesk                                  
    Autodesk AutoCAD 2015   (Russian) SP1                                                    1    AutoCAD 2015   (Russian) SP1          Autodesk                                  
    Autodesk AutoCAD 2015   (Russian)                                                20.0.51.0    AutoCAD 2015   (Russian)              Autodesk                        27.07.2014
    Autodesk AutoCAD 2015 Help   (Russian)                                           20.0.51.0    AutoCAD 2015 Help   (Russian)         Autodesk                                  
    Autodesk AutoCAD 2015 VBA Enabler                                                        20.0.51.0    AutoCAD 2015 VBA Enabler                      Autodesk                        27.07.2014
    Autodesk AutoCAD Architecture 2015   (Russian)                                    7.7.49.0    AutoCAD Architecture 2015   (Russian)  Autodesk                        06.08.2014
    Autodesk AutoCAD Architecture 2015 Help -  (Russian)                               7.7.49.0    AutoCAD Architecture 2015 Help -  (Russian)  Autodesk                                  
    Autodesk AutoCAD Performance Feedback Tool Version 1.2.2                                   1.2.2.0    {85735431-6CD3-4B16-BEC8-95332034E53B}        Autodesk                        2014-07-27
    Autodesk BIM 360 Glue AutoCAD 2015 Add-in 64 bit                                         4.33.6482    {78E2A54B-5F13-4286-9148-DAD8B823D485}        Autodesk                        2014-08-07
    Autodesk Content Service Language Pack [ ()]                                  3.2.0.0    {A37CDB58-AAE8-0001-8C13-E0F7BACB0D5F}        Autodesk                        2014-07-27
    Autodesk Content Service                                                                   3.2.0.0    Autodesk Content Service                      Autodesk                        27.07.2014
    Autodesk Design Review 2013                                                              13.0.0.82    Autodesk Design Review 2013                   Autodesk, Inc.                            
    Autodesk DWG TrueView 2015 - English                                                     20.0.51.0    DWG TrueView 2015 - English                   Autodesk                        16.08.2014
    Autodesk Inventor Content Center Libraries 2015 (Desktop Content)                  19.0.15900.0000    {B46DECD1-1964-4EF1-0000-22D71E81877C}        Autodesk                        2014-08-17
    Autodesk Inventor Professional 2015 -  (Russian)                            19.0.15900.0000    Autodesk Inventor Professional 2015           Autodesk                                  
    Autodesk Inventor Professional 2015 Language Pack -  (Russian) [ ()]   19.0.15900.0000    {7F4DD591-1964-0001-1049-7107D70F3DB4}        Autodesk                        2014-08-17
    Autodesk Inventor Professional 2015                                                19.0.15900.0000    {7F4DD591-1964-0001-0000-7107D70F3DB4}        Autodesk                        2014-08-17
    Autodesk Material Library 2015                                                           5.2.9.100    {427F733F-4D6C-45BC-9324-EB743104C321}        Autodesk                        2014-07-27
    Autodesk Material Library Base Resolution Image Library 2015                             5.2.9.100    {ABE2F70B-8D94-44E9-AA04-F0DB35063D62}        Autodesk                        2014-07-27
    Autodesk Material Library Low Resolution Image Library 2015                              5.2.9.100    {4FBC9635-AC56-4378-8FDE-C4D3ED072681}        Autodesk                        2014-08-16
    Autodesk ReCap                                                                             1.3.5.1    Autodesk ReCap                                Autodesk                        07.08.2014
    Autodesk Revit Interoperability for Inventor 2015                                       15.0.107.0    {0BB716E0-1500-0210-0000-097DC2F354DF}        Autodesk                        2014-08-17
    Autodesk Vault Basic 2015 (Client)                                                       19.0.49.0    {CF526A26-1964-0000-0000-02E95019B628}        Autodesk                        2014-08-17
    avast! Internet Security                                                                  9.0.2021    Avast                                         AVAST Software                            
    Bonjour [ ()]                                                                3.0.0.10    {6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}        Apple Inc.                      2014-07-27
    Catalyst Control Center - Branding                                                       1.00.0000    {25A3B953-1423-3F15-640E-B620DD0F419A}        Advanced Micro Devices, Inc.    2014-07-26
    Catalyst Control Center InstallProxy                                              2014.0704.2133.36938    {80680785-2EE1-053F-9CD3-4B2C904596EE}        Advanced Micro Devices, Inc.    2014-07-26
    Catalyst Control Center Localization All                                          2014.0704.2133.36938    {B12BE177-DC00-5746-3AB9-91CD090AF555}        Advanced Micro Devices, Inc.    2014-07-26
    Catalyst Control Center                                                                  1.00.0000    WUCCCApp                                      AMD                                       
    CCC Help Chinese Standard                                                         2014.0704.2132.36938    {BF5509A0-250A-25EA-0C19-61505E9EBA13}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Chinese Traditional                                                      2014.0704.2132.36938    {104DE091-6C4F-C5A9-F619-5D6C965A0296}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Czech                                                                    2014.0704.2132.36938    {EDA5BB56-AAF4-6889-AD8E-E25A17BD140B}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Danish                                                                   2014.0704.2132.36938    {EEF14371-2D24-5A2D-0EF2-22010DB4CFA6}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Dutch                                                                    2014.0704.2132.36938    {95B8F519-8C35-9010-A63C-51B3E0EE8D4E}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help English                                                                  2014.0704.2132.36938    {FDF2FE33-426D-45C2-4E70-76C162F1B790}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Finnish                                                                  2014.0704.2132.36938    {A3806AB7-AB46-7672-A825-F9AE0DE6910A}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help French                                                                   2014.0704.2132.36938    {7C5B13DA-6A68-86C7-ED29-610CA0F49555}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help German                                                                   2014.0704.2132.36938    {C69EA753-0D3F-E48B-8C98-7F6310DC29B8}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Greek                                                                    2014.0704.2132.36938    {B079957C-3276-4B9F-DB08-D1CA8C090D9E}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Hungarian                                                                2014.0704.2132.36938    {285C9F30-3BF8-697B-BD1D-353435E94B78}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Italian                                                                  2014.0704.2132.36938    {29967A7C-6E18-91CD-BBE4-9C09F401E950}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Japanese                                                                 2014.0704.2132.36938    {5C757800-27E8-2AE3-889A-8B959AE689F8}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Korean                                                                   2014.0704.2132.36938    {EB766D4A-C56C-946D-F74D-43C78FE4521E}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Norwegian                                                                2014.0704.2132.36938    {61B90A4D-8CC9-2FED-2495-AC8C9467C984}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Polish                                                                   2014.0704.2132.36938    {ED0D7699-1943-0C29-7465-6530F8DE2DA2}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Portuguese                                                               2014.0704.2132.36938    {FDD69799-37B2-9ACE-F70C-ABD1F96FD04C}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Russian                                                                  2014.0704.2132.36938    {54D05374-2428-7BE0-58CD-CE8031163DE6}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Spanish                                                                  2014.0704.2132.36938    {5D3EC645-B957-36A1-068A-FE8450963669}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Swedish                                                                  2014.0704.2132.36938    {5C6AFE98-08BF-086A-300D-18F77D284966}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Thai                                                                     2014.0704.2132.36938    {C4EE2BA3-EEA5-9650-86E0-0405ECA5C22C}        Advanced Micro Devices, Inc.    2014-07-26
    CCC Help Turkish                                                                  2014.0704.2132.36938    {070232F8-068B-1FF6-B5C4-F8F38E09C7E1}        Advanced Micro Devices, Inc.    2014-07-26
    ccc-utility64                                                                     2014.0704.2133.36938    {4B3EF5E6-9A2C-0A1B-C61C-B1FD444B84BC}        Advanced Micro Devices, Inc.    2014-07-26
    Configurator 360 addin                                                             19.0.11300.9000    {8FE324B0-B934-4D68-BAB5-DE2136036237}        Autodesk, Inc.                  2014-08-17
    DAEMON Tools Lite                                                                      4.49.1.0356    DAEMON Tools Lite                             Disc Soft Ltd                             
    Definition Update for Microsoft Office 2013 (KB2760587) 32-Bit Edition                                {90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{0B79C91F-978F-4C2E-9FE4-D4B567808858}  Microsoft                                 
    Download Master version 5.21.1.1405                                                    5.21.1.1405    Download Master_is1                           WestByte                        2014-07-26
    Driver Booster                                                                                 1.4    Driver Booster_is1                            IObit                           2014-07-26
    DWG TrueView 2015 - English                                                              20.0.51.0    {5783F2D7-E028-0409-0100-0060B0CE6BBA}        Autodesk                        2014-08-16
    Eco Materials Adviser for Autodesk Inventor 2015 (64-bit)                                  5.1.2.0    {2F7441CB-A646-41F1-B1CB-518AB311138B}        Granta Design Limited           2014-08-17
    FARO LS 1.1.502.0 (64bit)                                                              5.2.0.35213    {66D83FE0-D798-4B38-86FE-FB48151E5AEF}        FARO Scanner Production         2014-08-07
    HP ePrint                                                                          14.0.14176.1823    {2794875B-6CCF-48B8-84A5-5B10DB98BEE6}        Hewlett-Packard                           
    HP LaserJet Professional CP1020 Series                                                                HP LaserJet Professional CP1020 Series                                                  
    HP Unified IO                                                                            2.0.0.434    {F1390872-2500-4408-A46C-CD16C960C661}        HP                              2014-07-27
    HPLJUT                                                                                   1.00.0012    {229D6185-BD7E-494B-A73B-C5215BE0690E}        HP                              2014-07-27
    hppcp1025LaserJetService                                                                 1.00.0000    {F31BF057-0D5E-485E-ADFD-560314A27912}        Hewlett-Packard                 2014-07-27
    hppLaserJetService                                                                   007.015.00635    {5093AE98-D510-4BEB-BAC1-7FC8ECE35B98}        Hewlett-Packard                 2014-07-27
    IObit Uninstaller                                                                       3.3.8.2663    IObitUninstall                                IObit                           2014-07-27
    Java 7 Update 67                                                                           7.0.670    {26A24AE4-039D-4CA4-87B4-2F03217067FF}        Oracle                          2014-08-11
    Java Auto Updater                                                                         2.1.67.1    {4A03706F-666A-4037-7777-5F2748764D10}        Oracle, Inc.                    2014-08-11
    Jove's Mod Pack 0.9.2,  13.1  29.07.2014                                  13.1  29.07.2014    {B0F4B9B2-D252-44B6-B6C4-464809AA675B}_is1                                    2014-07-30
    K-Lite Codec Pack 10.6.5 Full                                                               10.6.5    KLiteCodecPack_is1                                                            2014-08-08
    KMSpico v9.3                                                                                   9.3    KMSpico_is1                                                                   2014-07-26
    LG Bluetooth Drivers                                                                           1.1    {AC7EE5F1-0DE4-4256-8E43-92B73C8E6019}        LG Electronics                  2014-07-27
    LG PC Suite                                                                        5.3.18.20140626    LG PC Suite                                   LG Electronics                            
    LG United Mobile Drivers                                                                  3.12.1.0    {15A5D29A-F209-49FD-BA47-5E4C882FF496}        LG Electronics                  2014-07-28
    Microsoft Access MUI (Russian) 2013 [ ()]                              15.0.4569.1506    {90150000-0015-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-07-26
    Microsoft DCF MUI (Russian) 2013 [ ()]                                 15.0.4569.1506    {90150000-0090-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-07-26
    Microsoft Excel MUI (Russian) 2013 [ ()]                               15.0.4569.1506    {90150000-0016-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-08-14
    Microsoft Games for Windows - LIVE Redistributable                                       2.0.673.0    {FD052FB9-FE90-4438-B355-15EDC89D8FB1}        Microsoft Corporation           2014-07-27
    Microsoft Games for Windows - LIVE                                                       2.0.675.0    {4AA3D64E-9EC3-4B0F-AB91-5885AC55641F}        Microsoft Corporation           2014-07-27
    Microsoft Groove MUI (Russian) 2013 [ ()]                              15.0.4569.1506    {90150000-00BA-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-08-14
    Microsoft InfoPath MUI (Russian) 2013 [ ()]                            15.0.4569.1506    {90150000-0044-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-07-26
    Microsoft Lync MUI (Russian) 2013 [ ()]                                15.0.4569.1506    {90150000-012B-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-08-14
    Microsoft Office 64-bit Components 2013                                             15.0.4569.1506    {90150000-002A-0000-1000-0000000FF1CE}        Microsoft Corporation           2014-08-14
    Microsoft Office Korrekturhilfen 2013 - Deutsch [ ()]               15.0.4569.1506    {90150000-001F-0407-0000-0000000FF1CE}        Microsoft Corporation           2014-08-14
    Microsoft Office OSM MUI (Russian) 2013 [ ()]                          15.0.4569.1506    {90150000-00E1-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-07-26
    Microsoft Office OSM UX MUI (Russian) 2013 [ ()]                       15.0.4569.1506    {90150000-00E2-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-07-26
    Microsoft Office Professional Plus 2013                                             15.0.4569.1506    {90150000-0011-0000-0000-0000000FF1CE}        Microsoft Corporation           2014-08-14
    Microsoft Office Proofing (Russian) 2013 [ ()]                         15.0.4569.1506    {90150000-002C-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-07-26
    Microsoft Office Proofing Tools 2013 - English                                      15.0.4569.1506    {90150000-001F-0409-0000-0000000FF1CE}        Microsoft Corporation           2014-08-14
    Microsoft Office Shared 64-bit MUI (Russian) 2013 [ ()]                15.0.4569.1506    {90150000-002A-0419-1000-0000000FF1CE}        Microsoft Corporation           2014-08-14
    Microsoft Office Shared MUI (Russian) 2013 [ ()]                       15.0.4569.1506    {90150000-006E-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-08-14
    Microsoft Office   2013                                         15.0.4569.1506    Office15.PROPLUS                              Microsoft Corporation                     
    Microsoft OneNote MUI (Russian) 2013 [ ()]                             15.0.4569.1506    {90150000-00A1-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-07-27
    Microsoft Outlook MUI (Russian) 2013 [ ()]                             15.0.4569.1506    {90150000-001A-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-07-27
    Microsoft PowerPoint MUI (Russian) 2013 [ ()]                          15.0.4569.1506    {90150000-0018-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-08-14
    Microsoft Publisher MUI (Russian) 2013 [ ()]                           15.0.4569.1506    {90150000-0019-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-07-27
    Microsoft Silverlight                                                                  5.1.30514.0    {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}        Microsoft Corporation           2014-07-27
    Microsoft Visual Basic for Applications 7.1 (x64) English                                  7.1.0.0    {90F60409-7000-11D3-8CFE-0150048383C9}        Microsoft Corporation           2014-07-27
    Microsoft Visual Basic for Applications 7.1 (x64)                                        7.1.00.00    {90120064-0070-0000-0000-4000000FF1CE}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2005 Redistributable (x64)                                          8.0.59192    {6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}        Microsoft Corporation           2014-08-16
    Microsoft Visual C++ 2005 Redistributable (x64)                                          8.0.61000    {ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2005 Redistributable                                                8.0.59193    {837b34e3-7c30-493c-8f6a-2b0f04e2912c}        Microsoft Corporation           2014-08-16
    Microsoft Visual C++ 2005 Redistributable                                                8.0.61001    {710f4c1c-cc18-4c49-8cbf-51240c89a1a2}        Microsoft Corporation           2014-07-28
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 False [ ()]         9.0.21022    {D04659D1-EB2D-3DE5-A833-837A623CCCF7}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022.0 False                        9.0.21022    {350AA351-21FA-3270-8B7A-835434E766AD}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022.218 False                  9.0.21022.218    {BBBE35B2-9349-3C48-BD3D-F574B17C7924}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30411 False                          9.0.30411    {D93AC9C8-B6CF-391E-BD2F-48AF4727476C}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 False [ ()]         9.0.30729    {2DFD8316-9EF1-3210-908C-4CB61961C1AC}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 False                       9.0.30729    {8220EEFE-38CD-377E-8595-13398D740ACE}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4048 False                9.0.30729.4048    {91415F19-4C22-3609-A105-92ED3522D83C}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 False                9.0.30729.4148    {4B6C7001-C7D6-3710-913E-5BC23FCE91E6}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.5570 False                9.0.30729.5570    {8338783A-0968-3B85-AFC7-BAAE0A63DC50}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161                      9.0.30729.6161    {5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 False [ ()]         9.0.21022    {DCB46B42-723F-350E-B18A-449BC6C21636}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.0 False                        9.0.21022    {FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 False                  9.0.21022.218    {E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 False                          9.0.30411    {5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 False [ ()]         9.0.30729    {527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 False                       9.0.30729    {9A25302D-30C0-39D9-BD6F-21E6EC160475}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4048 False                9.0.30729.4048    {5B1F2843-B379-3FF2-B0D3-64DD143ED53A}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 False                9.0.30729.4148    {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.5570 False                9.0.30729.5570    {86CE85E6-DBAC-3FFD-B977-E4B79F83C909}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161                      9.0.30729.6161    {9BE518E6-ECC6-35A9-88E4-87755C07200F}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2008 x64 ATL Runtime 9.0.30729                                      9.0.30729    {C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}        Microsoft Corporation           2014-08-17
    Microsoft Visual C++ 2008 x64 CRT Runtime 9.0.30729                                      9.0.30729    {F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}        Microsoft Corporation           2014-08-17
    Microsoft Visual C++ 2008 x64 MFC Runtime 9.0.30729                                      9.0.30729    {6DA2B636-698A-3294-BF4A-B5E11B238CDD}        Microsoft Corporation           2014-08-17
    Microsoft Visual C++ 2008 x64 OpenMP Runtime 9.0.30729                                   9.0.30729    {8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}        Microsoft Corporation           2014-08-17
    Microsoft Visual C++ 2008 x86 ATL Runtime 9.0.30729                                      9.0.30729    {04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}        Microsoft Corporation           2014-08-17
    Microsoft Visual C++ 2008 x86 CRT Runtime 9.0.30729                                      9.0.30729    {14866AAD-1F23-39AC-A62B-7091ED1ADE64}        Microsoft Corporation           2014-08-17
    Microsoft Visual C++ 2008 x86 MFC Runtime 9.0.30729                                      9.0.30729    {B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}        Microsoft Corporation           2014-08-17
    Microsoft Visual C++ 2008 x86 OpenMP Runtime 9.0.30729                                   9.0.30729    {4B90093A-5D9C-3956-8ABB-95848BE6EFAD}        Microsoft Corporation           2014-08-17
    Microsoft Visual C++ 2010 Redistributable - x64 10.0.30319 False                        10.0.30319    {DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219                              10.0.40219    {1D8E6291-B0D5-35EC-8441-6616F567A0F7}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2010 Redistributable - x86 10.0.30319 False                        10.0.30319    {196BB40D-1578-3D01-B289-BEFC77A11A1E}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219                              10.0.40219    {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030                          11.0.61030.0    {ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}        Microsoft Corporation                     
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030                          11.0.61030.0    {f0080ca2-80ae-4958-b6eb-e8fa916d744a}                              
    Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 False                     11.0.50727    {AC53FC8B-EE18-3F9C-9B59-60937D0B182C}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 False                     11.0.51106    {3C28BFD4-90C7-3138-87EF-418DC16E9598}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 False                     11.0.60610    {764384C5-BCA9-307C-9AAC-FD443662686A}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030                           11.0.61030    {37B8F9C7-03FB-3253-8781-2517C99D7C00}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 False                        11.0.50727    {A2CB1ACB-94A2-32BA-A15E-7D80319F7589}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 False                        11.0.51106    {5AF4E09F-5C9B-3AAF-B731-544D3DC821DD}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 False                        11.0.60610    {2EDC2FA3-1F34-34E5-9085-588C9EFD1CC6}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030                              11.0.61030    {CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 False                     11.0.50727    {FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 False                     11.0.51106    {6C772996-BFF3-3C8C-860B-B3D48FF05D65}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 False                     11.0.60610    {3D6AD258-61EA-35F5-812C-B7A02152996E}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030                           11.0.61030    {B175520C-86A2-35A7-8619-86DC379688B9}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 False                        11.0.50727    {2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 False                        11.0.51106    {E824E81C-80A4-3DFF-B5F9-4842A9FF5F7F}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 False                        11.0.60610    {E7D4E834-93EB-351F-B8FB-82CDAE623003}        Microsoft Corporation           2014-07-27
    Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030                              11.0.61030    {BD95A8CD-1D9F-35AD-981A-3E7925026EBB}        Microsoft Corporation           2014-07-27
    Microsoft Word MUI (Russian) 2013 [ ()]                                15.0.4569.1506    {90150000-001B-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-08-14
    Microsoft WSE 3.0 Runtime                                                               3.0.5305.0    {E3E71D07-CD27-46CB-8448-16D4FB29AA13}        Microsoft Corp.                 2014-08-17
    Mockup 360 Addin 2015                                                                        1.1.0    {E4D4242C-FC14-4B4F-B1D9-6760D8C241D5}        Autodesk                        2014-08-17
    MSXML 4.0 SP2 Parser and SDK                                                           4.20.9818.0    {716E0306-8318-4364-8B8F-0CC4E9376BAC}        Microsoft Corporation           2014-07-27
    Security Update for Microsoft Office 2013 (KB2880502) 32-Bit Edition                                  {90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{90E7A66B-723D-4790-824A-6E4EEC0C2CBA}  Microsoft                                 
    Smart Defrag 3                                                                                 3.2    Smart Defrag 3_is1                            IObit                           2014-08-17
    Start Menu 8                                                                               1.5.0.0    IObit_StartMenu8_is1                          IObit                           2014-08-12
    Steam                                                                                                 Steam                                         Valve Corporation                         
    Surfing Protection                                                                             1.0    IObit Surfing Protection_is1                  IObit                           2014-08-17
    Synaptics Pointing Device Driver                                                          18.0.7.0    SynTPDeinstKey                                Synaptics Incorporated                    
    UltraUXThemePatcher                                                                        2.3.0.0    UltraUXThemePatcher                           Manuel Hoefs (Zottel)                     
    Update for Microsoft Excel 2013 (KB2883061) 32-Bit Edition                                            {90150000-006E-0419-0000-0000000FF1CE}_Office15.PROPLUS_{4CFCE804-3034-4F3A-84E2-3C97665F80EC}  Microsoft                                 
    Update for Microsoft Lync 2013 (KB2881070) 32-Bit Edition                                             {90150000-012B-0419-0000-0000000FF1CE}_Office15.PROPLUS_{35E5FACD-A5AA-46AD-93C7-F6D7969044E7}  Microsoft                                 
    Update for Microsoft Lync 2013 (KB2881083) 32-Bit Edition                                             {90150000-012B-0419-0000-0000000FF1CE}_Office15.PROPLUS_{10845A75-2CE3-49D1-8E8D-3AB4962717AF}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2760249) 32-Bit Edition                                           {90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{8C07AD38-38EB-4332-BCB3-F55A77C927DF}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2760344) 32-Bit Edition                                           {90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{A7610F07-E844-4444-8E1D-D5BC8AD0B4C5}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2760544) 32-Bit Edition                                           {90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{45B7D395-EB9B-414F-9E46-5849B42326E2}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2768012) 32-Bit Edition                                           {90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{66421820-D3CA-450A-898C-78D7E40108E6}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2817302) 32-Bit Edition                                           {90150000-0016-0419-0000-0000000FF1CE}_Office15.PROPLUS_{1644D7F6-90EE-4252-8884-18E4E330529D}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2826040) 32-Bit Edition                                           {90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{B7EA8070-C37F-4617-82F4-52CF3304595A}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2837644) 32-Bit Edition                                           {90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{9BC5FF1D-9626-44D7-BC7F-EB44BD8BDB9F}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2863843) 32-Bit Edition                                           {90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{AD7045B8-1D75-4B4C-8120-12F045D206C7}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2880457) 32-Bit Edition                                           {90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{D27F6360-AE1E-4C8C-8ECD-C0375E20B923}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2880462) 32-Bit Edition                                           {90150000-006E-0419-0000-0000000FF1CE}_Office15.PROPLUS_{5D6439FF-D651-4B13-B52E-2508AB9DE19D}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2880478) 32-Bit Edition                                           {90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7C5CEE0F-6823-4BB7-A28F-76FEC14EB6AC}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2880987) 32-Bit Edition                                           {90150000-006E-0419-0000-0000000FF1CE}_Office15.PROPLUS_{07017577-FBD6-45E2-A796-659E8F428057}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2881009) 32-Bit Edition                                           {90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7A3EF4FF-A9C8-4F7E-8020-A45F7D319387}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2881035) 32-Bit Edition                                           {90150000-0016-0419-0000-0000000FF1CE}_Office15.PROPLUS_{01B80B63-C638-4004-9148-75B8C8518B1E}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2883036) 32-Bit Edition                                           {90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{B8E73381-09B1-4895-ACD0-34385B0F526D}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2883049) 32-Bit Edition                                           {90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{1C6260FD-A280-49FE-89D0-CCEC647FBD8E}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2883060) 32-Bit Edition                                           {90150000-001F-0422-0000-0000000FF1CE}_Office15.PROPLUS_{9F206933-EB7F-45DD-9391-BAF33E6769E1}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2883062) 32-Bit Edition                                           {90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{EE35EB6C-7768-433F-B9A0-73C97699A08C}  Microsoft                                 
    Update for Microsoft OneDrive for Business (KB2883066) 32-Bit Edition                                 {90150000-00BA-0419-0000-0000000FF1CE}_Office15.PROPLUS_{90EEAEDF-CD51-4E8C-B781-7A071EC53C36}  Microsoft                                 
    Update for Microsoft OneNote 2013 (KB2881082) 32-Bit Edition                                          {90150000-00A1-0419-0000-0000000FF1CE}_Office15.PROPLUS_{CA0F0611-10FB-47D4-A642-E3BABCC73393}  Microsoft                                 
    Update for Microsoft Outlook 2013 (KB2880470) 32-Bit Edition                                          {90150000-001A-0419-0000-0000000FF1CE}_Office15.PROPLUS_{1BCA67A6-5329-48D0-A088-C097AC7A14BD}  Microsoft                                 
    Update for Microsoft PowerPoint 2013 (KB2883051) 32-Bit Edition                                       {90150000-0018-0419-0000-0000000FF1CE}_Office15.PROPLUS_{01923A0F-BA34-4A75-8D43-97F536E44D95}  Microsoft                                 
    Update for Microsoft Publisher 2013 (KB2880999) 32-Bit Edition                                        {90150000-0019-0419-0000-0000000FF1CE}_Office15.PROPLUS_{7500AD77-83C6-400B-8B2F-F8E401A7B697}  Microsoft                                 
    Update for Microsoft Visio Viewer 2013 (KB2817301) 32-Bit Edition                                     {90150000-006E-0419-0000-0000000FF1CE}_Office15.PROPLUS_{25C61889-2E44-4BE1-9E96-9364BFDCF501}  Microsoft                                 
    Update for Microsoft Word 2013 (KB2878319) 32-Bit Edition                                             {90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{A7CD05CC-CA85-428C-91FD-74A908D126E1}  Microsoft                                 
    Update for Microsoft Word 2013 (KB2881080) 32-Bit Edition                                             {90150000-012B-0419-0000-0000000FF1CE}_Office15.PROPLUS_{2C43B8B8-09A1-4D09-B4B9-B247A7348D75}  Microsoft                                 
    USB Safely Remove 5.2                                                                                 USB Safely Remove_is1                         SafelyRemove.com                2014-07-26
    VirtualDJ 8                                                                                  8.0.0    {9ADBBA93-4625-4898-BB0D-BCE7EA9F8B4A}        Atomix Productions              2014-08-17
    VirusScanner 1.2.0.0                                                              VirusScanner 1.2.0.0    {C568B389-3EE3-40D1-BA0E-5C49E145F139}}_is1   iTVA, LLC.                      2014-08-02
    Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177                                    9.0.30729.177    {F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}.KB958357  Microsoft Corporation                     
    Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177                                    9.0.30729.177    {B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}.KB958357  Microsoft Corporation                     
    VKMusic 4                                                                                     4.61    VKMusic 4_is1                                                                 2014-07-26
    Vuze                                                                                       5.4.0.0    8461-7759-5462-8226                           Azureus Software, Inc.                    
    Warface [ ()]                                                                    1.78    Warface                                       Mail.Ru                                   
    Windows 7 USB/DVD Download Tool                                                             1.0.30    {CCF298AF-9CE1-4B26-B251-486E98A34789}        Microsoft Corporation           2014-08-17
    World of Tanks                                                                                        {1EAC1D02-C6AC-4FA6-9A44-96258C37C812RU}_is1  Wargaming.net                   2014-07-26
    Xilisoft Video Converter Ultimate                                                   7.8.2.20140711    Xilisoft Video Converter Ultimate             Xilisoft                                  
    Yandex                                                                             34.0.1847.18825    YandexBrowser                                  ѻ                    2014-07-26
       Microsoft Office 2013    [ ()]    15.0.4569.1506    {90150000-001F-0422-0000-0000000FF1CE}        Microsoft Corporation           2014-08-14
                                                                                     2.407    GameCenterMailRu                               ". "                       
     SketchUp [ ()]                                                           1.2.0    {C403E867-FCF1-432B-BCC1-8FFD40A10A6E}        Autodesk                        2014-07-27
                                                                            1.3.1.502    {9D1EE65A-AE6F-4B0E-B6B7-A84AA882290C}                                  2014-07-26
      Autodesk Vault Basic 2015 (Client)   [ ()]         19.0.49.0    {266597A9-1964-0000-1049-DCBF2B69166B}        Autodesk                        2014-08-17
      Autodesk [ ()]                                       1.2.0    {EDDEE94B-214D-4B07-9727-A3E46F3E379A}        Autodesk                        2014-07-27
       Microsoft Office 2013   [ ()]    15.0.4569.1506    {90150000-001F-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-08-14
      8.4  Internet Explorer                                              8.4.0.9140    {B9C3392F-76A5-4130-B60B-4D9C0B03E6C8}                                  2014-07-28
    .                                                                             1.2.6.4589    YandexDisk                                                                        




--------[   ]-------------------------------------------------------------------------------------------------

    386               Virtual Device Driver                                            
    3G2               3GPP2 Audio/Video                                                video/3gpp2
    3GP               3GPP Audio/Video                                                 video/3gpp
    3GP2              3GP2 File                                                        video/3gpp2
    3GPP              3GPP Audio/Video                                                 video/3gpp
    AAC               ADTS Audio                                                       audio/vnd.dlna.adts
    ACCDA             Microsoft Access Add-in                                          application/msaccess.addin
    ACCDB             Microsoft Access                                       application/msaccess
    ACCDC             Microsoft Access Signed Package                                  application/msaccess.cab
    ACCDE             Microsoft Access ACCDE Database                                  application/msaccess.exec
    ACCDR             Microsoft Access Runtime Application                             application/msaccess.runtime
    ACCDT             Microsoft Access Template                                        application/msaccess.template
    ACCDU             Microsoft Access Add-in Data                                     
    ACCDW             Microsoft Access Web Application                                 application/msaccess.webapplication
    ACCFT             Microsoft Access Template                                        application/msaccess.ftemplate
    ACCOUNTPICTURE-MS  Account Picture File                                             application/windows-accountpicture
    ACL               AutoCorrect List File                                            
    ACR               ACR File                                                         
    ADE               Microsoft Access Project Extension                               application/msaccess
    ADN               Microsoft Access Blank Project Template                          
    ADP               Microsoft Access Project                                         application/msaccess
    ADSK                Autodesk                                             
    ADT               ADTS Audio                                                       audio/vnd.dlna.adts
    ADTS              ADTS Audio                                                       audio/vnd.dlna.adts
    AIF               AIFF Format Sound                                                audio/aiff
    AIFC              AIFF Format Sound                                                audio/aiff
    AIFF              AIFF Format Sound                                                audio/aiff
    AMV               AMV Video File                                                   
    ANI               Animated Cursor                                                  
    APE               APE File                                                         
    APJ               Autodesk Project Information                                     
    APPCONTENT-MS     Application Content                                              application/windows-appcontent+xml
    APPLICATION       Application Manifest                                             application/x-ms-application
    APPREF-MS         Application Reference                                            
    ASA               ASA File                                                         
    ASF               ASF File                                                         video/x-ms-asf
    ASP               ASP File                                                         
    ASX               Windows Media Audio/Video playlist                               video/x-ms-asf
    AU                AU Format Sound                                                  audio/basic
    AVASTCONFIG       avast! config file                                               application/avast-config
    AVASTLIC          avast! license file                                              application/avast-license
    AVASTSOUNDS       avast! soundpack file                                            application/avast-sounds
    AVASTTHEME        avast! theme file                                                application/avast-theme
    AVASTVPN          avast! secureline file                                           application/avast-avastvpn
    AVI               Video Clip                                                       video/avi
    AW                Answer Wizard File                                               
    B5T               B5T File                                                         
    B6T               B6T File                                                         
    BAT               Windows Batch File                                               
    BDMV              Blu-ray File                                                     
    BLG               Performance Monitor File                                         
    BMP               Bitmap Image                                                     image/bmp
    BWT               BWT File                                                         
    CAB               Cabinet File                                                     
    CAMP              WCS Viewing Condition Profile                                    
    CAT               Security Catalog                                                 application/vnd.ms-pki.seccat
    CBL               Autodesk Content Browser Library                                 
    CCD               CCD File                                                         
    CDA               CD Audio Track                                                   
    CDI               CDI File                                                         
    CDMP              WCS Device Profile                                               
    CDX               CDX File                                                         
    CDXML             CDXML File                                                       
    CER               Security Certificate                                             application/x-x509-ca-cert
    CHK               Recovered File Fragments                                         
    CHM               Compiled HTML Help file                                          
    CMD               Windows Command Script                                           
    COM               MS-DOS Application                                               
    COMPOSITEFONT     Composite Font File                                              
    CONTACT           Contact File                                                     text/x-ms-contact
    CPL               Control Panel Item                                               
    CRC               MoldDesignFileHandler.Document                                   
    CRL               Certificate Revocation List                                      application/pkix-crl
    CRT               Security Certificate                                             application/x-x509-ca-cert
    CRTX               Microsoft Office Chart                                    
    CSS               Cascading Style Sheet Document                                   text/css
    CSV                Microsoft Excel,  ,    application/vnd.ms-excel
    CUE               CUE File                                                         
    CUR               Cursor                                                           
    DB                Data Base File                                                   
    DCTX              Open Extended Dictionary                                         
    DCTXC             Open Extended Dictionary                                         
    DDS               DDS Image                                                        image/vnd.ms-dds
    DER               Security Certificate                                             application/x-x509-ca-cert
    DESKLINK          Desktop Shortcut                                                 
    DESKTHEMEPACK     Windows Desktop Theme Pack                                       
    DIAGCAB           Diagnostic Cabinet                                               
    DIAGCFG           Diagnostic Configuration                                         
    DIAGPKG           Diagnostic Document                                              
    DIB               Bitmap Image                                                     image/bmp
    DIC               Text Document                                                    
    DIE               MoldDesignFileHandler.Document                                   
    DLL               Application Extension                                            application/x-msdownload
    DMF               DMF File                                                         
    DOC                Microsoft Word 972003                                  application/msword
    DOCHTML            Microsoft Word   HTML                           
    DOCM               Microsoft Word                       application/vnd.ms-word.document.macroEnabled.12
    DOCMHTML          DOCMHTML File                                                    
    DOCX               Microsoft Word                                          application/vnd.openxmlformats-officedocument.wordprocessingml.document
    DOCXML             Microsoft Word   XML                            
    DOT                Microsoft Word 972003                                    application/msword
    DOTHTML            Microsoft Word   HTML                             
    DOTM               Microsoft Word                         application/vnd.ms-word.template.macroEnabled.12
    DOTX               Microsoft Word                                            application/vnd.openxmlformats-officedocument.wordprocessingml.template
    DQY                 ODBC  Microsoft Excel                            
    DRV               Device Driver                                                    
    DSH               Vault Data Sheet File                                            
    DSN               Microsoft OLE DB Provider for ODBC Drivers                       
    DSS               Sheet Set Data File                                              
    DSU               Vault Data Subset File                                           
    DV                Digital Video File                                               
    DWF               Autodesk DWF Document                                            model/vnd.dwf
    DWFX              Autodesk DWFx Document                                           model/vnd.dwfx+xps
    EASMX             XPS Document                                                     model/vnd.easmx+xps
    EDRWX             XPS Document                                                     model/vnd.edrwx+xps
    ELM               Microsoft Office Themes File                                     
    EMF               EMF File                                                         image/x-emf
    EML               EML File                                                         
    EPRTX             XPS Document                                                     model/vnd.eprtx+xps
    EVO               EVO Video File                                                   
    EVT               EVT File                                                         
    EVTX              EVTX File                                                        
    EXC               Text Document                                                    
    EXE               Application                                                      application/x-msdownload
    F4V               Flash Video File                                                 
    FLAC              FLAC File                                                        
    FON               Font file                                                        
    FPO               MoldDesignFileHandler.Document                                   
    GADGET            Windows Gadget                                                   
    GCSX                 Microsoft Office SmartArt                  
    GIF               GIF Image                                                        image/gif
    GLOX                Microsoft Office SmartArt                          
    GMMP              WCS Gamut Mapping Profile                                        
    GQSX              -  Microsoft Office SmartArt                 
    GRA                Microsoft Graph                                        
    GRFX              GraphStudioNext Filter Graph File                                
    GROUP             Contact Group File                                               text/x-ms-group
    GRP               Microsoft Program Group                                          
    HDMOV             HDMOV Video File                                                 
    HLP               Help File                                                        
    HTA               HTML Application                                                 application/hta
    HTM               HTML Document                                                    text/html
    HTML              HTML Document                                                    text/html
    HXA               Microsoft Help Attribute Definition File                         application/xml
    HXC               Microsoft Help Collection Definition File                        application/xml
    HXD               Microsoft Help Validator File                                    application/octet-stream
    HXE               Microsoft Help Samples Definition File                           application/xml
    HXF               Microsoft Help Include File                                      application/xml
    HXH               Microsoft Help Merged Hierarchy File                             application/octet-stream
    HXI               Microsoft Help Compiled Index File                               application/octet-stream
    HXK               Microsoft Help Index File                                        application/xml
    HXQ               Microsoft Help Merged Query Index File                           application/octet-stream
    HXR               Microsoft Help Merged Attribute Index File                       application/octet-stream
    HXS               Microsoft Help Compiled Storage File                             application/octet-stream
    HXT               Microsoft Help Table of Contents File                            application/xml
    HXV               Microsoft Help Virtual Topic Definition File                     application/xml
    HXW               Microsoft Help Attribute Definition File                         application/octet-stream
    ICC               ICC Profile                                                      
    ICL               Icon Library                                                     
    ICM               ICC Profile                                                      
    ICO               Icon                                                             image/x-icon
    IFC               IAI Industry Foundation Classes File                             
    IFO               DVD IFO File                                                     
    IMESX             IME Search provider definition                                   
    IMG               Disc Image File                                                  
    INF               Setup Information                                                
    INFOPATHXML        Microsoft InfoPath                                         application/ms-infopath.xml
    INI               Configuration Settings                                           
    IQY                -  Microsoft Excel                             text/x-ms-iqy
    ISO               ISO File                                                         
    ISZ               ISZ File                                                         
    JAR               Executable Jar File                                              
    JFIF              JPEG Image                                                       image/jpeg
    JNLP              JNLP File                                                        application/x-java-jnlp-file
    JNT               Journal Document                                                 
    JOB               Task Scheduler Task Object                                       
    JOD               Microsoft.Jet.OLEDB.4.0                                          
    JPE               JPEG Image                                                       image/jpeg
    JPEG              JPEG Image                                                       image/jpeg
    JPG               JPEG Image                                                       image/jpeg
    JS                JavaScript File                                                  
    JSE               JScript Encoded File                                             
    JTP               Journal Template                                                 
    JTX               XPS Document                                                     application/x-jtx+xps
    JXR               Windows Media Photo                                              image/vnd.ms-photo
    LABEL             Property List                                                    
    LACCDB            Microsoft Access Record-Locking Information                      
    LDB               Microsoft Access Record-Locking Information                      
    LEX               Dictionary File                                                  
    LIBRARY-MS        Library Folder                                                   application/windows-library+xml
    LNK               Shortcut                                                         
    LOG               Text Document                                                    
    M1V               MPEG Video File                                                  video/mpeg
    M2P               MPEG Video File                                                  
    M2T               AVCHD Video                                                      video/vnd.dlna.mpeg-tts
    M2TS              AVCHD Video                                                      video/vnd.dlna.mpeg-tts
    M2V               MPEG Video File                                                  video/mpeg
    M3U               M3U file                                                         audio/x-mpegurl
    M4A               MPEG-4 Audio                                                     audio/mp4
    M4V               MP4 Video                                                        video/mp4
    MAD               Microsoft Access Module Shortcut                                 
    MAF               Microsoft Access Form Shortcut                                   
    MAG               Microsoft Access Diagram Shortcut                                
    MAM               Microsoft Access Macro Shortcut                                  
    MAPIMAIL          Mail Service                                                     
    MAQ               Microsoft Access Query Shortcut                                  
    MAR               Microsoft Access Report Shortcut                                 
    MAS               Microsoft Access Stored Procedure Shortcut                       
    MAT               Microsoft Access Table Shortcut                                  
    MAU               MAU File                                                         
    MAV               Microsoft Access View Shortcut                                   
    MAW               Microsoft Access Data Access Page Shortcut                       
    MDA               Microsoft Access Add-in                                          application/msaccess
    MDB               Microsoft Access Database                                        application/msaccess
    MDBHTML           Microsoft Access HTML Document                                   
    MDE               Microsoft Access MDE Database                                    application/msaccess
    MDF               MDF File                                                         
    MDN               Microsoft Access Blank Database Template                         
    MDS               MDS File                                                         
    MDT               Microsoft Access Add-in Data                                     
    MDW               Microsoft Access Workgroup Information                           
    MDX               MDX File                                                         
    MFP               Macromedia Flash Paper                                           application/x-shockwave-flash
    MHT               MHTML Document                                                   message/rfc822
    MHTML             MHTML Document                                                   message/rfc822
    MID               MIDI Sequence                                                    audio/mid
    MIDI              MIDI Sequence                                                    audio/mid
    MIG               Migration Store                                                  
    MIT               MoldDesignFileHandler.Document                                   
    MKV               Matroska Video File                                              
    MLC               Language Pack File_                                              
    MOD               Movie Clip                                                       video/mpeg
    MOV               QuickTime Movie                                                  video/quicktime
    MP2               MP3 Format Sound                                                 audio/mpeg
    MP2V              MPEG Video File                                                  video/mpeg
    MP3               MP3 Format Sound                                                 audio/mpeg
    MP4               MP4 Video                                                        video/mp4
    MP4V              MP4 Video                                                        video/mp4
    MPA               Movie Clip                                                       audio/mpeg
    MPE               Movie Clip                                                       video/mpeg
    MPEG              Movie Clip                                                       video/mpeg
    MPG               Movie Clip                                                       video/mpeg
    MPLS              Blu-ray Playlist File                                            
    MPV2              Movie Clip                                                       video/mpeg
    MPV4              MPV4 Video File                                                  
    MSC               Microsoft Common Console Document                                
    MSI               Windows Installer Package                                        
    MS-ONE-STUB        Microsoft OneNote                                       
    MSP               Windows Installer Patch                                          
    MSRCINCIDENT      Windows Remote Assistance Invitation                             
    MSSTYLES          Windows Visual Style File                                        
    MSU               Microsoft Update Standalone Package                              
    MTS               AVCHD Video                                                      video/vnd.dlna.mpeg-tts
    MXF               Material Exchange Format                                         
    MYDOCS            MyDocs Drop Target                                               
    NFO               MSInfo Configuration File                                        
    NRG               NRG File                                                         
    OCX               ActiveX control                                                  
    ODC               Microsoft Office Data Connection                                 text/x-ms-odc
    ODCCUBEFILE       ODCCUBEFILE File                                                 
    ODCDATABASEFILE   ODCDATABASEFILE File                                             
    ODCNEWFILE        ODCNEWFILE File                                                  
    ODCTABLECOLLECTIONFILE  ODCTABLECOLLECTIONFILE File                                      
    ODCTABLEFILE      ODCTABLEFILE File                                                
    ODP                OpenDocument                                         application/vnd.oasis.opendocument.presentation
    ODS                 OpenDocument                                 application/vnd.oasis.opendocument.spreadsheet
    ODT                OpenDocument                                               application/vnd.oasis.opendocument.text
    OF1               MoldDesignFileHandler.Document                                   
    OF2               MoldDesignFileHandler.Document                                   
    OGM               Ogg Video File                                                   
    OGV               Ogg Video File                                                   
    OLS                  Office                                          application/vnd.ms-publisher
    ONE                Microsoft OneNote                                         application/msonenote
    ONEPKG             Microsoft OneNote,                   application/msonenote
    ONETOC             Microsoft OneNote 2003                                
    ONETOC2            Microsoft OneNote                                     
    OO1               MoldDesignFileHandler.Document                                   
    OO2               MoldDesignFileHandler.Document                                   
    OP2               MoldDesignFileHandler.Document                                   
    OPC               Microsoft Clean-up Wizard File                                   
    OQY                 OLAP  Microsoft Excel                            
    OSDX              OpenSearch Description File                                      application/opensearchdescription+xml
    OT1               MoldDesignFileHandler.Document                                   
    OT2               MoldDesignFileHandler.Document                                   
    OTF               OpenType Font file                                               
    OUT               MoldDesignFileHandler.Document                                   
    OXPS              XPS Document                                                     
    P10               Certificate Request                                              application/pkcs10
    P12               Personal Information Exchange                                    application/x-pkcs12
    P7B               PKCS #7 Certificates                                             application/x-pkcs7-certificates
    P7C               Digital ID File                                                  application/pkcs7-mime
    P7M               PKCS #7 MIME Message                                             application/pkcs7-mime
    P7R               Certificate Request Response                                     application/x-pkcs7-certreqresp
    P7S               PKCS #7 Signature                                                application/pkcs7-signature
    PANO              PANO File                                                        application/vnd.ms-pano
    PARTIAL           Partial Download                                                 
    PBK               Dial-Up Phonebook                                                
    PCB               PCB File                                                         
    PERFMONCFG        Performance Monitor Configuration                                
    PFM               Type 1 Font file                                                 
    PFX               Personal Information Exchange                                    application/x-pkcs12
    PIF               Shortcut to MS-DOS Program                                       
    PKO               Public Key Security Object                                       application/vnd.ms-pki.pko
    PNF               Precompiled Setup Information                                    
    PNG               PNG Image                                                        image/png
    POT                Microsoft PowerPoint 972003                              application/vnd.ms-powerpoint
    POTHTML           HTML- Microsoft PowerPoint                                 
    POTM                Microsoft PowerPoint        application/vnd.ms-powerpoint.template.macroEnabled.12
    POTX               Microsoft PowerPoint                                      application/vnd.openxmlformats-officedocument.presentationml.template
    PPA                Microsoft PowerPoint 972003                          application/vnd.ms-powerpoint
    PPAM               Microsoft PowerPoint                                  application/vnd.ms-powerpoint.addin.macroEnabled.12
    PPC               MoldDesignFileHandler.Document                                   
    PPL               Autodesk Publish Properties List                                 
    PPS                 Microsoft PowerPoint 972003                       application/vnd.ms-powerpoint
    PPSM                Microsoft PowerPoint            application/vnd.ms-powerpoint.slideshow.macroEnabled.12
    PPSX                Microsoft PowerPoint                               application/vnd.openxmlformats-officedocument.presentationml.slideshow
    PPT                Microsoft PowerPoint 972003                         application/vnd.ms-powerpoint
    PPTHTML           HTML- Microsoft PowerPoint                               
    PPTM               Microsoft PowerPoint              application/vnd.ms-powerpoint.presentation.macroEnabled.12
    PPTMHTML          PPTMHTML File                                                    
    PPTX               Microsoft PowerPoint                                 application/vnd.openxmlformats-officedocument.presentationml.presentation
    PPTXML            XML- Microsoft PowerPoint                             
    PRF               PICS Rules File                                                  application/pics-rules
    PRINTEREXPORT     Printer Migration File                                           
    PS1               PS1 File                                                         
    PS1XML            PS1XML File                                                      
    PSC1              PSC1 File                                                        application/PowerShell
    PSD1              PSD1 File                                                        
    PSM1              PSM1 File                                                        
    PSSC              PSSC File                                                        
    PUB                Microsoft Publisher                                     application/vnd.ms-publisher
    PUBHTML           PUBHTML File                                                     
    PUBMHTML          PUBMHTML File                                                    
    PWZ                Microsoft PowerPoint                                      application/vnd.ms-powerpoint
    QDS               Directory Query                                                  
    RAM               RealMedia File                                                   
    RAT               Rating System File                                               application/rat-file
    RCP               Autodesk ReCap Project file                                      application/rcp
    RCS               Autodesk ReCap Scan                                              application/rcs
    RDP               Remote Desktop Connection                                        
    REC               MPEG-TS Video File                                               
    REG               Registration Entries                                             
    RELS              XML Document                                                     
    RESMONCFG         Resource Monitor Configuration                                   
    RFN               MoldDesignFileHandler.Document                                   
    RLE               RLE File                                                         
    RLL               Application Extension                                            
    RM                RealMedia Video File                                             
    RMI               MIDI Sequence                                                    audio/mid
    RMVB              RealMedia Video File                                             
    RQY                 OLE DB  Microsoft Excel                          text/x-ms-rqy
    RTF                RTF                                                       application/msword
    SCF               File Explorer Command                                            
    SCP               Text Document                                                    
    SCR               Screen saver                                                     
    SCT               Windows Script Component                                         text/scriptlet
    SDY               MoldDesignFileHandler.Document                                   
    SEARCHCONNECTOR-MS  Search Connector Folder                                          application/windows-search-connector+xml
    SEARCH-MS         Saved Search                                                     
    SETTINGCONTENT-MS  Setting Content                                                  
    SFCACHE           ReadyBoost Cache File                                            
    SLDM               Microsoft PowerPoint                    application/vnd.ms-powerpoint.slide.macroEnabled.12
    SLDX               Microsoft PowerPoint                                       application/vnd.openxmlformats-officedocument.presentationml.slide
    SLK                  Microsoft Excel SLK                        application/vnd.ms-excel
    SND               AU Format Sound                                                  audio/basic
    SPC               PKCS #7 Certificates                                             application/x-pkcs7-certificates
    SPL               Shockwave Flash Object                                           application/futuresplash
    SST               Microsoft Serialized Certificate Store                           application/vnd.ms-pki.certstore
    SVG               SVG Document                                                     image/svg+xml
    SWF               Shockwave Flash Object                                           application/x-shockwave-flash
    SYMLINK           .symlink                                                         
    SYS               System file                                                      
    THEME             Windows Theme File                                               
    THEMEPACK         Windows Theme Pack                                               
    THMX               Microsoft Office                                            application/vnd.ms-officetheme
    TIF               TIF File                                                         image/tiff
    TIFF              TIFF File                                                        image/tiff
    TP                MPEG-TS Video File                                               
    TPS               MPEG-TS Video File                                               
    TRP               MPEG-TS Video File                                               
    TS                MPEG-2 TS Video                                                  video/vnd.dlna.mpeg-tts
    TTC               TrueType Collection Font file                                    
    TTF               TrueType Font file                                               
    TTS               MPEG-2 TS Video                                                  video/vnd.dlna.mpeg-tts
    TXT               Text Document                                                    text/plain
    UDL               Microsoft Data Link                                              
    URL               URL File                                                         
    URLS              URLS File                                                        
    UXDC              UXDC File                                                        
    VBE               VBScript Encoded File                                            
    VBS               VBScript Script File                                             
    VCF               vCard File                                                       text/x-vcard
    VDW               Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VDX               Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VHD               Disc Image File                                                  
    VHDX              Disc Image File                                                  
    VOB               DVD VOB File                                                     
    VSD               Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VSDM              Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VSDX              Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VSS               Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VSSM              Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VSSX              Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VST               Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VSTM              Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VSTO              VSTO Deployment Manifest                                         application/x-ms-vsto
    VSTX              Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VSX               Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VTX               Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VXD               Virtual Device Driver                                            
    WAB               Address Book File                                                
    WAV               Wave Sound                                                       audio/wav
    WAX               Windows Media Audio shortcut                                     audio/x-ms-wax
    WBK                  Microsoft Word                          application/msword
    WCX               Workspace Configuration File                                     
    WDP               Windows Media Photo                                              image/vnd.ms-photo
    WEBM              WEBM Video File                                                  
    WEBPNP            Web Point And Print File                                         
    WEBSITE           Pinned Site Shortcut                                             application/x-mswebsite
    WIZ                Microsoft Word                                            application/msword
    WIZHTML           Microsoft Access HTML Template                                   
    WLL               WLL File                                                         
    WM                Windows Media Audio/Video file                                   video/x-ms-wm
    WMA               Windows Media Audio file                                         audio/x-ms-wma
    WMD               Windows Media Player Download Package                            application/x-ms-wmd
    WMDB              Windows Media Library                                            
    WMF               WMF File                                                         image/x-wmf
    WMS               Windows Media Player Skin File                                   
    WMV               Windows Media Audio/Video file                                   video/x-ms-wmv
    WMX               Windows Media Audio/Video playlist                               video/x-ms-wmx
    WMZ               Windows Media Player Skin Package                                application/x-ms-wmz
    WPL               Windows Media playlist                                           application/vnd.ms-wpl
    WSC               Windows Script Component                                         text/scriptlet
    WSF               Windows Script File                                              
    WSH               Windows Script Host Settings File                                
    WTX               Text Document                                                    
    WVX               Windows Media Audio/Video playlist                               video/x-ms-wvx
    XAML              Windows Markup File                                              application/xaml+xml
    XBAP              XAML Browser Application                                         application/x-ms-xbap
    XEVGENXML         XEVGENXML File                                                   
    XHT               XHTML Document                                                   application/xhtml+xml
    XHTML             XHTML Document                                                   application/xhtml+xml
    XLA                Microsoft Excel                                       application/vnd.ms-excel
    XLAM               Microsoft Excel                                       application/vnd.ms-excel.addin.macroEnabled.12
    XLD                 Microsoft Excel 5.0                                application/vnd.ms-excel
    XLK                  Microsoft Excel                             application/vnd.ms-excel
    XLL                Microsoft Excel XLL                                   application/vnd.ms-excel
    XLM                Microsoft Excel 4.0                                       application/vnd.ms-excel
    XLS                Microsoft Excel 97-2003                                     application/vnd.ms-excel
    XLSB                Microsoft Excel                                    application/vnd.ms-excel.sheet.binary.macroEnabled.12
    XLSHTML            Microsoft Excel   HTML                          
    XLSM               Microsoft Excel                          application/vnd.ms-excel.sheet.macroEnabled.12
    XLSMHTML          XLSMHTML File                                                    
    XLSX               Microsoft Excel                                             application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
    XLT                Microsoft Excel                                           application/vnd.ms-excel
    XLTHTML            Microsoft Excel   HTML                            
    XLTM               Microsoft Excel                        application/vnd.ms-excel.template.macroEnabled.12
    XLTX               Microsoft Excel                                           application/vnd.openxmlformats-officedocument.spreadsheetml.template
    XLW                 Microsoft Excel                                  application/vnd.ms-excel
    XLXML              Microsoft Excel   XML                               
    XML               XML Document                                                     text/xml
    XPS               XPS Document                                                     application/vnd.ms-xpsdocument
    XRM-MS            XrML Digital License                                             text/xml
    XSF                  Microsoft InfoPath                        
    XSL               XSL Stylesheet                                                   text/xml
    XSN                 Microsoft InfoPath                                  
    XTP               Microsoft InfoPath Template Part File                            
    XTP2              Microsoft InfoPath Template Part File                            
    ZFSENDTOTARGET    Compressed (zipped) Folder SendTo Target                         
    ZIP               Compressed (zipped) Folder                                       application/x-zip-compressed


--------[    ]--------------------------------------------------------------------------------------

  [ ???? ?????? ]

     :
                                                     ???? ??????
                                                ??????????????????????????????????????
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               RSSFeeds.Gadget\ja\gadget.xml

  [ ???? ??? ]

     :
                                                     ???? ???
                                                ????????????? ??????????
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               SlideShow.Gadget\ja\gadget.xml

  [ ???? ??? ]

     :
                                                     ???? ???
                                                ??????????????????
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               PicturePuzzle.Gadget\ja\gadget.xml

  [ ????? ]

     :
                                                     ?????
                                                ?????????,????????????
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               PicturePuzzle.Gadget\zh\gadget.xml

  [ ????? ]

     :
                                                     ?????
                                                ?????????????
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               SlideShow.Gadget\zh\gadget.xml

  [ ????? ]

     :
                                                     ?????
                                                ???????????????
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Calendar.Gadget\ja\gadget.xml

  [ ??? ]

     :
                                                     ???
                                                ???????????????
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               RSSFeeds.Gadget\zh\gadget.xml

  [ ?? ]

     :
                                                     ??
                                                ?????? ????????????????????????
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Clock.Gadget\ja\gadget.xml

  [ ?? ]

     :
                                                     ??
                                                ??????????????????
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Clock.Gadget\zh\gadget.xml

  [ ?? ]

     :
                                                     ??
                                                ??????????????
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Currency.Gadget\zh\gadget.xml

  [ ?? ]

     :
                                                     ??
                                                ?????????????????
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Weather.Gadget\ja\gadget.xml

  [ ?? ]

     :
                                                     ??
                                                ??????????
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Weather.Gadget\zh\gadget.xml

  [ ?? ]

     :
                                                     ??
                                                ?????????
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Calendar.Gadget\zh\gadget.xml

  [ Bildpuzzle ]

     :
                                                     Bildpuzzle
                                                Verschieben Sie die Puzzleteile, bis Sie das Puzzle gelost haben.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               PicturePuzzle.Gadget\de\gadget.xml

  [ Calendar ]

     :
                                                     Calendar
                                                Browse the days of the calendar.
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Calendar.Gadget\gadget.xml

  [ Calendrier ]

     :
                                                     Calendrier
                                                Parcourez les jours du calendrier.
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Calendar.Gadget\fr\gadget.xml

  [ Clock ]

     :
                                                     Clock
                                                Watch the clock in your own time zone or any city in the world.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Clock.Gadget\gadget.xml

  [ Compteur processeur ]

     :
                                                     Compteur processeur
                                                Affichez le processeur et la memoire vive systeme actuelle de lordinateur.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               CPU.Gadget\fr\gadget.xml

  [ CPU ???? ]

     :
                                                     CPU ????
                                                ??????????? CPU ????? ??? (RAM) ??????????
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               CPU.Gadget\ja\gadget.xml

  [ CPU ??? ]

     :
                                                     CPU ???
                                                ??????? CPU ?????(RAM)?
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               CPU.Gadget\zh\gadget.xml

  [ CPU Meter ]

     :
                                                     CPU Meter
                                                See the current computer CPU and system memory (RAM).
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               CPU.Gadget\gadget.xml

  [ CPU-Nutzung ]

     :
                                                     CPU-Nutzung
                                                Zeigt die aktuellen Computerwerte fur CPU und Systemarbeitsspeicher (RAM) an.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               CPU.Gadget\de\gadget.xml

  [ Currency ]

     :
                                                     Currency
                                                Convert from one currency to another.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Currency.Gadget\gadget.xml

  [ Devises ]

     :
                                                     Devises
                                                Convertisseur de devises
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Currency.Gadget\fr\gadget.xml

  [ Diaporama ]

     :
                                                     Diaporama
                                                Affichez un diaporama continu de vos images.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               SlideShow.Gadget\fr\gadget.xml

  [ Diashow ]

     :
                                                     Diashow
                                                Zeigt eine fortwahrende Diashow von Ihren Bildern an.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               SlideShow.Gadget\de\gadget.xml

  [ Feed Headlines ]

     :
                                                     Feed Headlines
                                                Track the latest news, sports, and entertainment headlines.
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               RSSFeeds.Gadget\gadget.xml

  [ Feedschlagzeilen ]

     :
                                                     Feedschlagzeilen
                                                Zeigt Nachrichten, Sportinfos und Unterhaltungsschlagzeilen an.
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               RSSFeeds.Gadget\de\gadget.xml

  [ Horloge ]

     :
                                                     Horloge
                                                Affichez lheure de votre propre fuseau horaire ou dune autre ville dans le monde.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Clock.Gadget\fr\gadget.xml

  [ Kalender ]

     :
                                                     Kalender
                                                Durchsucht den Kalender.
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Calendar.Gadget\de\gadget.xml

  [ Meteo ]

     :
                                                     Meteo
                                                Consultez la meteo partout dans le monde.
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Weather.Gadget\fr\gadget.xml

  [ Picture Puzzle ]

     :
                                                     Picture Puzzle
                                                Move the pieces of the puzzle and try to put them in order.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               PicturePuzzle.Gadget\gadget.xml

  [ Puzzle graphique ]

     :
                                                     Puzzle graphique
                                                Deplacez les pieces du puzzle et essayez de les mettre en ordre.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               PicturePuzzle.Gadget\fr\gadget.xml

  [ Slide Show ]

     :
                                                     Slide Show
                                                Show a continuous slide show of your pictures.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               SlideShow.Gadget\gadget.xml

  [ Titres des flux ]

     :
                                                     Titres des flux
                                                Suivez les dernieres nouvelles, evenements sportifs et culturels.
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               RSSFeeds.Gadget\fr\gadget.xml

  [ Uhr ]

     :
                                                     Uhr
                                                Zeigt die Zeit Ihrer Zeitzone oder die einer beliebigen Stadt an.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Clock.Gadget\de\gadget.xml

  [ Wahrungsrechner ]

     :
                                                     Wahrungsrechner
                                                Rechnen Sie zwischen verschiedenen internationalen Wahrungen um.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Currency.Gadget\de\gadget.xml

  [ Weather ]

     :
                                                     Weather
                                                See what the weather looks like around the world.
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Weather.Gadget\gadget.xml

  [ Wetter ]

     :
                                                     Wetter
                                                Informieren Sie sich uber das Wetter an Ihrem Wunschort.
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2012
                                                   ProgramFiles
      XML                                               Weather.Gadget\de\gadget.xml

  [  ]

     :
                                                     
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Currency.Gadget\ru\gadget.xml

  [  ]

     :
                                                     
                                                     .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               PicturePuzzle.Gadget\ru\gadget.xml

  [   - ]

     :
                                                       -
                                                   ,     .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               RSSFeeds.Gadget\ru\gadget.xml

  [   ]

     :
                                                      
                                                      (RAM).
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               CPU.Gadget\ru\gadget.xml

  [  ]

     :
                                                     
                                                  .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Calendar.Gadget\ru\gadget.xml

  [  ]

     :
                                                     
                                                      .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Weather.Gadget\ru\gadget.xml

  [   ]

     :
                                                      
                                                     .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               SlideShow.Gadget\ru\gadget.xml

  [  ]

     :
                                                     
                                                          .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Clock.Gadget\ru\gadget.xml


--------[  Windows ]----------------------------------------------------------------------------------------

      :
                                              Microsoft Windows 8.1 Professional
                                       -
      Winlogon Shell                                    explorer.exe
          (UAC)  
                                   

       (DEP, NX, EDB):
                                        
                                        
       ( )                       
       ( )                        


--------[  Windows ]------------------------------------------------------------------------------------------

    (Automatic Update)                                                                Download:Automatic, Install:Scheduled  Every Day 0:00
    Windows 8.1    64- (x64)  (KB2919355)                           27.07.2014
      Microsoft Excel 2013 (KB2881085) 32-                            27.07.2014
      Microsoft Excel 2013 (KB2883061) 32-                            14.08.2014
      Microsoft Lync 2013 (KB2850074) 32-                             27.07.2014
      Microsoft Lync 2013 (KB2881070) 32-                             14.08.2014
      Microsoft Lync 2013 (KB2881083) 32-                             14.08.2014
      Microsoft Office 2013 (KB2760249) 32-                           14.08.2014
      Microsoft Office 2013 (KB2760344) 32-                           27.07.2014
      Microsoft Office 2013 (KB2760544) 32-                           27.07.2014
      Microsoft Office 2013 (KB2768012) 32-                           27.07.2014
      Microsoft Office 2013 (KB2817302) 32-                           27.07.2014
      Microsoft Office 2013 (KB2826040) 32-                           27.07.2014
      Microsoft Office 2013 (KB2837644) 32-                           27.07.2014
      Microsoft Office 2013 (KB2863843) 32-                           27.07.2014
      Microsoft Office 2013 (KB2880457) 32-                           27.07.2014
      Microsoft Office 2013 (KB2880462) 32-                           27.07.2014
      Microsoft Office 2013 (KB2880464) 32-                           27.07.2014
      Microsoft Office 2013 (KB2880478) 32-                           27.07.2014
      Microsoft Office 2013 (KB2880987) 32-                           27.07.2014
      Microsoft Office 2013 (KB2881009) 32-                           14.08.2014
      Microsoft Office 2013 (KB2881035) 32-                           27.07.2014
      Microsoft Office 2013 (KB2881074) 32-                           27.07.2014
      Microsoft Office 2013 (KB2881084) 32-                           27.07.2014
      Microsoft Office 2013 (KB2881086) 32-                           27.07.2014
      Microsoft Office 2013 (KB2883036) 32-                           14.08.2014
      Microsoft Office 2013 (KB2883049) 32-                           14.08.2014
      Microsoft Office 2013 (KB2883060) 32-                           14.08.2014
      Microsoft Office 2013 (KB2883062) 32-                           14.08.2014
      Microsoft OneDrive for Business (KB2881087) 32-                 27.07.2014
      Microsoft OneDrive for Business (KB2883066) 32-                 14.08.2014
      Microsoft OneNote 2013 (KB2881082) 32-                          27.07.2014
      Microsoft Outlook 2013 (KB2880470) 32-                          27.07.2014
      Microsoft PowerPoint 2013 (KB2881075) 32-                       27.07.2014
      Microsoft PowerPoint 2013 (KB2883051) 32-                       14.08.2014
      Microsoft Publisher 2013 (KB2880999) 32-                        27.07.2014
      Microsoft Silverlight (KB2977218)                                              27.07.2014
      Microsoft Visio Viewer 2013 (KB2817301) 32-                     27.07.2014
      Microsoft Word 2013 (KB2878319) 32-                             27.07.2014
      Microsoft Word 2013 (KB2881080) 32-                             27.07.2014
      Windows 8.1      x64 (KB2955164)                     27.07.2014
      Windows 8.1      x64 (KB2976978)                     14.08.2014
      Windows 8.1      x64 (KB2976978)                     27.07.2014
      Windows 8.1      x64 (KB2980654)                     27.07.2014
        Microsoft Lync 2013 (KB2881013) 32-               27.07.2014
        Microsoft Office 2013 (KB2880502) 32-               27.07.2014
       Microsoft Office 2013 (KB2760587) 32-               14.08.2014
       Microsoft Office 2013 (KB2760587) 32-               27.07.2014
          Microsoft Visual C++ 2005    1 (SP1) (KB2538242)              28.07.2014
        Windows  Windows 8, 8.1  Windows Server 2012, 2012 R2 ( 64) -  2014 . (KB890830)              14.08.2014
        Windows  Windows 8, 8.1  Windows Server 2012, 2012 R2 ( 64) -  2014 . (KB890830)              27.07.2014


--------[  ]---------------------------------------------------------------------------------------------------

    Avast                                                 9.0.2021                                17.08.2014   2418258
    Windows Defender                                    4.5.0218.0                                18.07.2013         ?


--------[  ]--------------------------------------------------------------------------------------------------

    Avast Internet Security                               9.0.2021  ?
     Windows                              6.3.9600.16384  


--------[   ]--------------------------------------------------------------------------------------

     :
                                      ()
                            (UTC+04:00) , , -
                               
                                    

    :
       (.)                                      
       (.)                                      Russian
       (ISO 639)                                    ru

    /:
       (.)                                    
       (.)                                    Russia
       (ISO 3166)                                 RU
                                               7

     :
        (.)                          
        (.)                          Russian Ruble
         (.)                   ?
         (ISO 4217)                RUB
                                      123456789,00 ?
                         -123456789,00 ?

    :
                                           H:mm:ss
                                       dd.MM.yyyy
                                        d MMMM yyyy '.'
                                       123456789,00
                          -123456789,00
                                            first; second; third
                                               0123456789

     :
                                       / 
                                           / 
                                              / 
                                           / 
                                            / 
                                            / 
                                        / 

    :
                                             / 
                                            / 
                                              / 
                                             / 
                                                / 
                                               / 
                                               / 
                                            / 
                                           / 
                                            / 
                                             / 
                                            / 

    :
                                            Gregorian (localized)
                                 A4
                                        

    :
      LCID 0419h ()                              ()


--------[  ]---------------------------------------------------------------------------------------------------

    __COMPAT_LAYER            DetectorsWin7
    ALLUSERSPROFILE           C:\ProgramData
    APPDATA                   C:\Users\Black_SOKOL\AppData\Roaming
    CM2015DIR                 C:\Program Files (x86)\Common Files\Autodesk Shared\Materials\
    CommonProgramFiles(x86)   C:\Program Files (x86)\Common Files
    CommonProgramFiles        C:\Program Files (x86)\Common Files
    CommonProgramW6432        C:\Program Files\Common Files
    COMPUTERNAME              BLACK_SOKOL
    ComSpec                   C:\Windows\system32\cmd.exe
    FP_NO_HOST_CHECK          NO
    HOMEDRIVE                 C:
    HOMEPATH                  \Users\Black_SOKOL
    ILLDIR                    C:\Program Files (x86)\Common Files\Autodesk Shared\Materials\
    LOCALAPPDATA              C:\Users\Black_SOKOL\AppData\Local
    LOGONSERVER               \\MicrosoftAccount
    NUMBER_OF_PROCESSORS      4
    OMP_NUM_THREADS           4
    OS                        Windows_NT
    Path                      C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
    PATHEXT                   .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    PROCESSOR_ARCHITECTURE    x86
    PROCESSOR_ARCHITEW6432    AMD64
    PROCESSOR_IDENTIFIER      AMD64 Family 18 Model 1 Stepping 0, AuthenticAMD
    PROCESSOR_LEVEL           18
    PROCESSOR_REVISION        0100
    ProgramData               C:\ProgramData
    ProgramFiles(x86)         C:\Program Files (x86)
    ProgramFiles              C:\Program Files (x86)
    ProgramW6432              C:\Program Files
    PSModulePath              C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
    PUBLIC                    C:\Users\Public
    SystemDrive               C:
    SystemRoot                C:\Windows
    TEMP                      C:\Users\BLACK_~1\AppData\Local\Temp
    TMP                       C:\Users\BLACK_~1\AppData\Local\Temp
    USERDOMAIN_ROAMINGPROFILE  BLACK_SOKOL
    USERDOMAIN                BLACK_SOKOL
    USERNAME                  Black_SOKOL
    USERPROFILE               C:\Users\Black_SOKOL
    windir                    C:\Windows


--------[   ]-------------------------------------------------------------------------------------------

    Flash Player                                Flash Player
    Java                                      Java Control Panel


--------[  ]-----------------------------------------------------------------------------------------------------

    C:            0         0      ?  ?
    E:      8163         16      ?  ?


--------[   ]---------------------------------------------------------------------------------------------

  [ system.ini ]

    ; for 16-bit app support
    [386Enh]
    woafont=dosapp.fon
    EGA80WOA.FON=EGA80WOA.FON
    EGA40WOA.FON=EGA40WOA.FON
    CGA80WOA.FON=CGA80WOA.FON
    CGA40WOA.FON=CGA40WOA.FON
    
    [drivers]
    wave=mmdrv.dll
    timer=timer.drv
    
    [mci]

  [ win.ini ]

    ; for 16-bit app support
    [fonts]
    [extensions]
    [mci extensions]
    [files]
    [Mail]
    MAPI=1

  [ hosts ]

    

  [ lmhosts.sam ]

    
    
    
    


--------[   ]---------------------------------------------------------------------------------------------

    Administrative Tools         C:\Users\Black_SOKOL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    AppData                      C:\Users\Black_SOKOL\AppData\Roaming
    Cache                        C:\Users\Black_SOKOL\AppData\Local\Microsoft\Windows\INetCache
    CD Burning                   C:\Users\Black_SOKOL\AppData\Local\Microsoft\Windows\Burn\Burn
    Common Administrative Tools  C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    Common AppData               C:\ProgramData
    Common Desktop               C:\Users\Public\Desktop
    Common Documents             C:\Users\Public\Documents
    Common Favorites             C:\Users\Black_SOKOL\Favorites
    Common Files (x86)           C:\Program Files (x86)\Common Files
    Common Files                 C:\Program Files (x86)\Common Files
    Common Music                 C:\Users\Public\Music
    Common Pictures              C:\Users\Public\Pictures
    Common Programs              C:\ProgramData\Microsoft\Windows\Start Menu\Programs
    Common Start Menu            C:\ProgramData\Microsoft\Windows\Start Menu
    Common Startup               C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    Common Templates             C:\ProgramData\Microsoft\Windows\Templates
    Common Video                 C:\Users\Public\Videos
    Cookies                      C:\Users\Black_SOKOL\AppData\Local\Microsoft\Windows\INetCookies
    Desktop                      C:\Users\Black_SOKOL\Desktop
    Device                       C:\Windows\inf
    Favorites                    C:\Users\Black_SOKOL\Favorites
    Fonts                        C:\Windows\Fonts
    History                      C:\Users\Black_SOKOL\AppData\Local\Microsoft\Windows\History
    Local AppData                C:\Users\Black_SOKOL\AppData\Local
    My Documents                 E:\ \
    My Music                     E:\
    My Pictures                  E:\ \
    My Video                     C:\Users\Black_SOKOL\Videos
    NetHood                      C:\Users\Black_SOKOL\AppData\Roaming\Microsoft\Windows\Network Shortcuts
    PrintHood                    C:\Users\Black_SOKOL\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
    Profile                      C:\Users\Black_SOKOL
    Program Files (x86)          C:\Program Files (x86)
    Program Files                C:\Program Files (x86)
    Programs                     C:\Users\Black_SOKOL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
    Recent                       C:\Users\Black_SOKOL\AppData\Roaming\Microsoft\Windows\Recent
    Resources                    C:\Windows\resources
    SendTo                       C:\Users\Black_SOKOL\AppData\Roaming\Microsoft\Windows\SendTo
    Start Menu                   C:\Users\Black_SOKOL\AppData\Roaming\Microsoft\Windows\Start Menu
    Startup                      C:\Users\Black_SOKOL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    System (x86)                 C:\Windows\SysWOW64
    System                       C:\Windows\system32
    Temp                         C:\Users\BLACK_~1\AppData\Local\Temp\
    Templates                    C:\Users\Black_SOKOL\AppData\Roaming\Microsoft\Windows\Templates
    Windows                      C:\Windows


--------[   ]-------------------------------------------------------------------------------------------

                 101        2014-08-11 00:25:45                                  Application Hang                1002: 
                         2014-08-11 16:58:04                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-11 16:58:40                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-11 16:58:40                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-11 17:00:29                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-11 17:00:29                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
               7          2014-08-11 17:00:30                                  ESENT                           507: LiveComm (2144) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:      "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   16384 (0x0000000000004000)  8192 (0x00002000)  ,         (33 ). ,     .    ,     .  
                         2014-08-11 17:29:20                                  Software Protection Platform Service  1017: 
                         2014-08-11 19:44:26                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-11 19:44:26                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-11 19:45:57                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-11 19:45:57                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-11 20:05:07                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-11 21:18:05                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                 101        2014-08-11 21:47:40                                  Application Hang                1002: 
                         2014-08-11 22:59:52                                  Software Protection Platform Service  1017: 
                         2014-08-11 23:37:58                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-11 23:37:59                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-12 16:57:02                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-12 16:57:02                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-12 16:58:15                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-12 16:58:15                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-12 16:58:16                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-12 16:58:17                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-12 16:58:17                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-12 16:58:22  Black_SOKOL                     MsiInstaller                    11310: :   --  1310.     C:\Users\Black_SOKOL\AppData\Local\Yandex\Updater2\BrowserManager.exe.    0. ,        .  
                         2014-08-12 17:29:16                                  Software Protection Platform Service  1017: 
                         2014-08-12 18:23:19                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-12 19:40:15                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-12 19:40:15                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-12 19:41:25                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-12 19:41:25                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-12 22:03:47                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-12 22:05:53                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
               1          2014-08-12 22:11:58                                  ESENT                           532: LiveComm (4560) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:     "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   1458176 (0x0000000000164000)  8192 (0x00002000)       36.  ,      .         .  
               7          2014-08-12 22:11:58                                  ESENT                           507: LiveComm (4560) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:      "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   1449984 (0x0000000000162000)  8192 (0x00002000)  ,         (32 ). ,     .    ,     .  
                         2014-08-12 22:16:07                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                       2014-08-12 22:24:21  Black_SOKOL                     Microsoft-Windows-RestartManager  10010:     "C:\Windows\explorer.exe" (  3944) - 1.  
                       2014-08-12 22:24:21  Black_SOKOL                     Microsoft-Windows-RestartManager  10010:     "C:\Program Files\Classic Shell\ClassicStartMenu.exe" (  4060) - 1.  
                         2014-08-12 22:27:44                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-12 22:35:22                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
               1          2014-08-12 22:36:23                                  ESENT                           532: LiveComm (6696) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:     "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   1449984 (0x0000000000162000)  8192 (0x00002000)       36.  ,      .         .  
               7          2014-08-12 22:36:23                                  ESENT                           507: LiveComm (6696) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:      "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   1449984 (0x0000000000162000)  8192 (0x00002000)  ,         (36 ). ,     .    ,     .  
               7          2014-08-12 22:39:19                                  ESENT                           507: LiveComm (6696) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:      "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   16384 (0x0000000000004000)  8192 (0x00002000)  ,         (31 ). ,     .    ,     .  
                         2014-08-12 22:59:17                                  Software Protection Platform Service  1017: 
                       2014-08-12 23:17:01                           Microsoft-Windows-RestartManager  10010:     "C:\Windows\System32\dasHost.exe" (  1684) - 1.  
                       2014-08-12 23:17:01                           Microsoft-Windows-RestartManager  10010:     "C:\Users\Black_SOKOL\AppData\Local\Yandex\Elements\elements.exe\8.4.0.9140\elements64.exe" (  508) - 1.  
                       2014-08-12 23:17:01                           Microsoft-Windows-RestartManager  10010:     "C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe" (  5004) - 1.  
                       2014-08-12 23:17:01                           Microsoft-Windows-RestartManager  10010:     "C:\Users\Black_SOKOL\AppData\Roaming\Yandex\YandexDisk\YandexDisk.exe" (  5108) - 1.  
                       2014-08-12 23:17:01                           Microsoft-Windows-RestartManager  10010:     "C:\Windows\System32\SettingSyncHost.exe" (  5196) - 1.  
                       2014-08-12 23:17:01                           Microsoft-Windows-RestartManager  10010:     "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe" (  5672) - 1.  
                       2014-08-12 23:17:01                           Microsoft-Windows-RestartManager  10010:     "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" (  2168) - 1.  
                       2014-08-12 23:17:01                           Microsoft-Windows-RestartManager  10010:     "C:\Windows\explorer.exe" (  4368) - 1.  
                       2014-08-12 23:17:01                           Microsoft-Windows-RestartManager  10010:     "C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17044_x64__8wekyb3d8bbwe\glcnd.exe" (  4012) - 1.  
                         2014-08-13 17:08:25                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-13 17:08:55                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-13 17:14:45                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-13 22:44:55                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-13 22:45:35                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-13 22:45:42                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-13 22:46:10  Black_SOKOL                     MsiInstaller                    11310: :   --  1310.     C:\Users\Black_SOKOL\AppData\Local\Yandex\Updater2\BrowserManager.exe.    0. ,        .  
                         2014-08-13 22:47:15                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-13 22:54:51                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-13 22:59:13                                  Software Protection Platform Service  1017: 
                         2014-08-14 18:04:15                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-14 18:04:53                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-14 18:05:40  Black_SOKOL                     MsiInstaller                    11310: :   --  1310.     C:\Users\Black_SOKOL\AppData\Local\Yandex\Updater2\BrowserManager.exe.    0. ,        .  
                         2014-08-14 18:06:15                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-14 18:22:39                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-14 21:10:15                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-14 21:21:21                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-14 21:21:56                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-14 21:23:58                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-14 22:14:45                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-14 23:03:19                                  Software Protection Platform Service  1017: 
                 101        2014-08-14 23:06:59                                  Application Hang                1002: 
                         2014-08-14 23:18:26                                  .NET Runtime                    1026: : AutoPico.exe  : v4.0.30319 .    -  .   : System.Management.ManagementException :     System.Management.ManagementException.ThrowWithExtendedInfo(System.Management.ManagementStatus)     System.Management.ManagementObject.InvokeMethod(System.String, System.Management.ManagementBaseObject, System.Management.InvokeMethodOptions)     AutoPico.Activador.WMI.SoftwareLicensingProduct.SetKeyManagementServiceMachine(System.String)     AutoPico.Activador.WMISoftwareLicense.Activate(AutoPico.Activador.Variables ByRef, System.Collections.Generic.List`1<AutoPico.Activador.WMI.SoftwareLicensingProduct> ByRef)     AutoPico.Activador.Activador.ActivarWindows(AutoPico.Activador.Variables ByRef)     System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)     System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)     System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)     System.Threading.ThreadHelper.ThreadStart()   
                 100        2014-08-14 23:18:35                                  Application Error               1000:   : AutoPico.exe, : 12.2.0.0,  : 0x53a73867    : KERNELBASE.dll, : 6.3.9600.17055,  : 0x532954fb   : 0xe0434352   : 0x0000000000005bf8    : 0x1ef0     : 0x01cfb7f1d0213307    : C:\Program Files\KMSpico\AutoPico.exe    : C:\Windows\system32\KERNELBASE.dll   : c8fa4bfa-23e7-11e4-8281-001374000000     :    ,    :   
                         2014-08-14 23:27:13                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-15 17:03:02                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-15 17:03:47                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-15 17:05:49                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-15 17:29:24                                  Software Protection Platform Service  1017: 
                         2014-08-15 19:17:26                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-15 20:20:45                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 10:38:44                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 10:40:44                                  SideBySide                      35:      "c:\program files (x86)\microsoft office\Office15\lync.exe.Manifest".       "c:\program files (x86)\microsoft office\Office15\UccApi.DLL"   1.           .   - UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".   - UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".   sxstrace.exe   .  
                         2014-08-16 10:45:49                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 10:45:51                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 10:46:25                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 10:47:08                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 10:47:22  Black_SOKOL                     MsiInstaller                    11310: :   --  1310.     C:\Users\Black_SOKOL\AppData\Local\Yandex\Updater2\BrowserManager.exe.    0. ,        .  
                         2014-08-16 11:55:11                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 11:59:13                                  Software Protection Platform Service  1017: 
                         2014-08-16 12:05:05                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 12:28:16                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 12:36:34                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 12:42:29                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                 100        2014-08-16 12:42:53                                  Application Error               1000:   : Explorer.EXE, : 6.3.9600.17238,  : 0x53d0b98d    : aimp_menu64.dll, : 3.0.0.0,  : 0x4f9f92dc   : 0xc0000005   : 0x000000000002a819    : 0x108c     : 0x01cfb91db06669fe    : C:\Windows\Explorer.EXE    : C:\Program Files (x86)\AIMP3\Modules\aimp_menu64.dll   : 4f726264-2521-11e4-8284-001374000000     :    ,    :   
                         2014-08-16 12:56:13                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 12:56:20                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 12:57:04                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 12:58:58                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                 3          2014-08-16 12:59:13                                  ESENT                           455: SettingSyncHost (8012) {752B8411-DDC8-43FA-96BC-681B7CD1FD61}:  -1811 (0xfffff8ed)     C:\Users\Black_SOKOL\AppData\Local\Microsoft\Windows\SettingSync\metastore\edb00002.log.  
                 101        2014-08-16 13:52:16                                  Application Hang                1002: 
                       2014-08-16 14:14:28  Black_SOKOL                     MsiInstaller                    1015:     . : 0x800401F0  
                       2014-08-16 14:14:36  Black_SOKOL                     MsiInstaller                    1015:     . : 0x800401F0  
                       2014-08-16 14:18:57  Black_SOKOL                     Microsoft-Windows-System-Restore  8303: 
                         2014-08-16 14:19:25                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 14:25:44                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 14:26:51                                  Bonjour Service                 100: 
                         2014-08-16 14:26:51                                  Bonjour Service                 100: 
                         2014-08-16 14:26:51                                  Bonjour Service                 100: 
                         2014-08-16 14:26:52                                  Bonjour Service                 100: 
                         2014-08-16 14:26:52                                  Bonjour Service                 100: 
                         2014-08-16 14:26:52                                  Bonjour Service                 100: 
                         2014-08-16 14:26:54                                  Bonjour Service                 100: 
                         2014-08-16 14:26:54                                  Bonjour Service                 100: 
                         2014-08-16 14:26:54                                  Bonjour Service                 100: 
                         2014-08-16 14:26:55                                  Bonjour Service                 100: 
                         2014-08-16 14:26:55                                  Bonjour Service                 100: 
                         2014-08-16 14:26:55                                  Bonjour Service                 100: 
                         2014-08-16 14:26:57                                  Bonjour Service                 100: 
                         2014-08-16 14:26:57                                  Bonjour Service                 100: 
                         2014-08-16 14:26:57                                  Bonjour Service                 100: 
                         2014-08-16 14:26:59                                  Bonjour Service                 100: 
                         2014-08-16 14:26:59                                  Bonjour Service                 100: 
                         2014-08-16 14:26:59                                  Bonjour Service                 100: 
                         2014-08-16 14:27:00                                  Bonjour Service                 100: 
                         2014-08-16 14:27:00                                  Bonjour Service                 100: 
                         2014-08-16 14:27:00                                  Bonjour Service                 100: 
                         2014-08-16 14:27:02                                  Bonjour Service                 100: 
                         2014-08-16 14:27:02                                  Bonjour Service                 100: 
                         2014-08-16 14:27:02                                  Bonjour Service                 100: 
                         2014-08-16 14:27:03                                  Bonjour Service                 100: 
                         2014-08-16 14:27:03                                  Bonjour Service                 100: 
                         2014-08-16 14:27:03                                  Bonjour Service                 100: 
                         2014-08-16 14:27:05                                  Bonjour Service                 100: 
                         2014-08-16 14:27:05                                  Bonjour Service                 100: 
                         2014-08-16 14:27:05                                  Bonjour Service                 100: 
                         2014-08-16 14:27:06                                  Bonjour Service                 100: 
                         2014-08-16 14:27:06                                  Bonjour Service                 100: 
                         2014-08-16 14:27:06                                  Bonjour Service                 100: 
                         2014-08-16 16:30:03                                  Bonjour Service                 100: 
                         2014-08-16 16:30:03                                  Bonjour Service                 100: 
                         2014-08-16 16:30:03                                  Bonjour Service                 100: 
                         2014-08-16 16:30:05                                  Bonjour Service                 100: 
                         2014-08-16 16:30:06                                  Bonjour Service                 100: 
                         2014-08-16 16:30:06                                  Bonjour Service                 100: 
                         2014-08-16 16:30:07                                  Bonjour Service                 100: 
                         2014-08-16 16:30:07                                  Bonjour Service                 100: 
                         2014-08-16 16:30:07                                  Bonjour Service                 100: 
                         2014-08-16 16:30:09                                  Bonjour Service                 100: 
                         2014-08-16 16:30:09                                  Bonjour Service                 100: 
                         2014-08-16 16:30:09                                  Bonjour Service                 100: 
                         2014-08-16 16:30:10                                  Bonjour Service                 100: 
                         2014-08-16 16:30:10                                  Bonjour Service                 100: 
                         2014-08-16 16:30:10                                  Bonjour Service                 100: 
                         2014-08-16 16:30:12                                  Bonjour Service                 100: 
                         2014-08-16 16:30:12                                  Bonjour Service                 100: 
                         2014-08-16 16:30:12                                  Bonjour Service                 100: 
                 101        2014-08-16 16:32:03                                  Application Hang                1002: 
                 101        2014-08-16 16:33:43                                  Application Hang                1002: 
                         2014-08-16 16:35:35                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 16:35:38                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 16:35:43                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                 2400       2014-08-16 16:47:59  Black_SOKOL                     Microsoft-Windows-Immersive-Shell  2484:   Microsoft.Reader_6.3.9654.17044_x64__8wekyb3d8bbwe+Microsoft.Reader ,        .  
                         2014-08-16 16:55:54                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 20:48:57                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 20:49:25                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 21:13:04                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 21:13:39                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 21:16:23                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 22:45:42                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 22:54:33                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 22:55:06                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-16 22:59:07                                  Software Protection Platform Service  1017: 
                         2014-08-16 23:10:01                                  Customer Experience Improvement Program  
                         2014-08-17 00:46:27                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 00:46:47                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 00:48:48                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                 2414       2014-08-17 01:00:24  Black_SOKOL                     Microsoft-Windows-Immersive-Shell  2486:  winstore_1.0.0.0_neutral_neutral_cw5n1h2txyewy+Windows.Store     .  
                 5973       2014-08-17 01:00:55  Black_SOKOL                     Microsoft-Windows-Immersive-Shell  5973:    winstore_cw5n1h2txyewy!Windows.Store. : -2144927142.   .   Microsoft-Windows-TWinUI/Operational.  
                       2014-08-17 01:01:05                                  VSS                             8229: 
                         2014-08-17 01:02:14                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                 101        2014-08-17 01:05:41                                  Application Hang                1002: 
                       2014-08-17 01:40:05  Black_SOKOL                     MsiInstaller                    1015:     . : 0x800401F0  
                       2014-08-17 01:40:10  Black_SOKOL                     MsiInstaller                    1015:     . : 0x800401F0  
                 101        2014-08-17 01:50:49                                  Application Hang                1002: 
                 101        2014-08-17 01:50:56                                  Application Hang                1002: 
                 101        2014-08-17 02:17:58                                  Application Hang                1002: 
                 101        2014-08-17 02:19:59                                  Application Hang                1002: 
                 101        2014-08-17 02:20:08                                  Application Hang                1002: 
                         2014-08-17 02:39:09                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                       2014-08-17 02:39:12  Black_SOKOL                     MsiInstaller                    1032:    ""      .  ,     ,               .  
                         2014-08-17 02:47:00                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 03:01:43                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 03:11:25                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 03:13:45                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                 101        2014-08-17 05:48:32                                  Application Hang                1002: 
               3          2014-08-17 06:50:32                                  ESENT                           472: LiveComm (5796) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:      C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\edb.chk.       (4096).  
                 101        2014-08-17 08:00:15                                  Application Hang                1002: 
                 101        2014-08-17 08:05:40                                  Application Hang                1002: 
                         2014-08-17 08:24:34                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 08:25:02                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 08:27:08                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 08:30:11                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 08:44:26                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 08:44:58                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 08:47:10                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
               7          2014-08-17 08:47:20                                  ESENT                           507: LiveComm (3784) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:      "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   1449984 (0x0000000000162000)  8192 (0x00002000)  ,         (28 ). ,     .    ,     .  
                         2014-08-17 08:57:24                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
               1          2014-08-17 08:59:33                                  ESENT                           532: LiveComm (3104) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:     "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   1449984 (0x0000000000162000)  8192 (0x00002000)       36.  ,      .         .  
               7          2014-08-17 08:59:36                                  ESENT                           507: LiveComm (3104) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:      "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   1449984 (0x0000000000162000)  8192 (0x00002000)  ,         (40 ). ,     .    ,     .  
                 101        2014-08-17 09:02:11                                  Application Hang                1002: 
                 101        2014-08-17 09:02:11                                  Application Hang                1002: 
                         2014-08-17 09:38:28                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 10:34:51                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 10:35:09                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 10:37:39                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 10:37:40                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 13:52:50                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 13:53:13                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 13:54:30  Black_SOKOL                     MsiInstaller                    11310: :   --  1310.     C:\Users\Black_SOKOL\AppData\Local\Yandex\Updater2\BrowserManager.exe.    0. ,        .  
                         2014-08-17 13:56:13                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
               7          2014-08-17 13:56:21                                  ESENT                           507: LiveComm (4080) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:      "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   1449984 (0x0000000000162000)  8192 (0x00002000)  ,         (28 ). ,     .    ,     .  
                         2014-08-17 14:10:29                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 16:00:31                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 17:29:24                                  Software Protection Platform Service  1017: 
                 101        2014-08-17 18:03:44                                  Application Hang                1002: 
                         2014-08-17 18:14:55                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
               1          2014-08-17 18:16:31                                  ESENT                           532: LiveComm (8328) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:     "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   1458176 (0x0000000000164000)  8192 (0x00002000)       36.  ,      .         .  
               1          2014-08-17 18:16:31                                  ESENT                           532: LiveComm (8328) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:     "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   1449984 (0x0000000000162000)  8192 (0x00002000)       36.  ,      .         .  
               1          2014-08-17 18:16:35                                  ESENT                           532: LiveComm (8328) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:     "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   1466368 (0x0000000000166000)  8192 (0x00002000)       36.  ,      .         .  
               7          2014-08-17 18:16:35                                  ESENT                           507: LiveComm (8328) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:      "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   1449984 (0x0000000000162000)  8192 (0x00002000)  ,         (32 ). ,     .    ,     .  
                         2014-08-17 18:43:25                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
               7          2014-08-17 18:45:01                                  ESENT                           507: LiveComm (2560) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:      "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   1449984 (0x0000000000162000)  8192 (0x00002000)  ,         (16 ). ,     .    ,     .  
               7          2014-08-17 18:45:01                                  ESENT                           509: LiveComm (2560) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:      "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   1458176 (0x0000000000164000)  8192 (0x00002000)  ,         (33 ).  ,            2  ,  0   -        . ,     .    ,     .  
                         2014-08-17 19:00:00                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 19:00:34                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 19:02:24                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 19:07:05                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                 101        2014-08-17 22:23:32                                  Application Hang                1002: 
                         2014-08-17 22:25:31                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                 101        2014-08-17 22:27:38                                  Application Hang                1002: 
                         2014-08-17 22:31:34                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 22:31:53                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 22:50:48                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                 100        2014-08-17 22:56:32                                  Application Error               1000:   : aida64.exe, : 0.0.0.0,  : 0x2a425e19    : atiadlxy.dll, : 6.14.10.1129,  : 0x53b75468   : 0xc0000005   : 0x000489c6    : 0x1c88     : 0x01cfba4cc2e6e569    : C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe    : C:\Windows\SYSTEM32\atiadlxy.dll   : 33efe340-2640-11e4-828f-001374000000     :    ,    :   
                 100        2014-08-17 22:56:39                                  Application Error               1000:   : aida64.exe, : 0.0.0.0,  : 0x2a425e19    : unknown, : 0.0.0.0,  : 0x00000000   : 0x00000000   : 0x00000000    : 0x1c88     : 0x01cfba4cc2e6e569    : C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe    : unknown   : 37d63b45-2640-11e4-828f-001374000000     :    ,    :   
                         2014-08-17 23:00:20                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 23:00:37                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
                         2014-08-17 23:02:21                                  SideBySide                      78:       "C:\Program Files (x86)\LG Electronics\LG PC Suite\LGPCSuite.exe".       ""   .   ,   ,   ,   .   :   1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.   2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.  
               1          2014-08-17 23:03:14                                  ESENT                           532: LiveComm (3936) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:     "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   1449984 (0x0000000000162000)  8192 (0x00002000)       36.  ,      .         .  
               1          2014-08-17 23:03:19                                  ESENT                           532: LiveComm (3936) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:     "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   1458176 (0x0000000000164000)  8192 (0x00002000)       36.  ,      .         .  
               7          2014-08-17 23:03:19                                  ESENT                           507: LiveComm (3936) C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\:      "C:\Users\Black_SOKOL\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\3cf7d125510cc444\120712-0049\DBStore\livecomm.edb"   1449984 (0x0000000000162000)  8192 (0x00002000)  ,         (40 ). ,     .    ,     .  
                 100        2014-08-17 23:14:02                                  Application Error               1000:   : aida64.exe, : 0.0.0.0,  : 0x2a425e19    : amdocl.dll, : 10.0.1348.5,  : 0x53b75789   : 0xc0000005   : 0x0016e817    : 0x1ac0     : 0x01cfba4e26c0b898    : C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe    : C:\Windows\SYSTEM32\amdocl.dll   : a58b2768-2642-11e4-8290-001374000000     :    ,    :   
                 100        2014-08-17 23:14:06                                  Application Error               1000:   : aida64.exe, : 0.0.0.0,  : 0x2a425e19    : unknown, : 0.0.0.0,  : 0x00000000   : 0x00000000   : 0x00000000    : 0x1ac0     : 0x01cfba4e26c0b898    : C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe    : unknown   : a818fd28-2642-11e4-8290-001374000000     :    ,    :   
                 100        2014-08-17 23:19:04                                  Application Error               1000:   : aida64.exe, : 0.0.0.0,  : 0x2a425e19    : amdocl.dll, : 10.0.1348.5,  : 0x53b75789   : 0xc0000005   : 0x0016e817    : 0x1ce8     : 0x01cfba4fe2ec6556    : C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe    : C:\Windows\SYSTEM32\amdocl.dll   : 59cbdb11-2643-11e4-8290-001374000000     :    ,    :   
                 100        2014-08-17 23:19:05                                  Application Error               1000:   : aida64.exe, : 0.0.0.0,  : 0x2a425e19    : unknown, : 0.0.0.0,  : 0x00000000   : 0x00000000   : 0x00000000    : 0x1ce8     : 0x01cfba4fe2ec6556    : C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe    : unknown   : 5a4fc81b-2643-11e4-8290-001374000000     :    ,    :   
                 100        2014-08-17 23:20:26                                  Application Error               1000:   : aida64.exe, : 0.0.0.0,  : 0x2a425e19    : amdocl.dll, : 10.0.1348.5,  : 0x53b75789   : 0xc0000005   : 0x0016e817    : 0x117c     : 0x01cfba5025c9e1b3    : C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe    : C:\Windows\SYSTEM32\amdocl.dll   : 8a9556cb-2643-11e4-8290-001374000000     :    ,    :   
                 100        2014-08-17 23:20:27                                  Application Error               1000:   : aida64.exe, : 0.0.0.0,  : 0x2a425e19    : unknown, : 0.0.0.0,  : 0x00000000   : 0x00000000   : 0x00000000    : 0x117c     : 0x01cfba5025c9e1b3    : C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe    : unknown   : 8b030e58-2643-11e4-8290-001374000000     :    ,    :   
      Audit Success   12544      2014-08-11 00:25:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 00:25:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-08-11 01:08:14                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x420ae      ,   .  ,  ,  .        .  
      Audit Success   103        2014-08-11 01:08:26                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-11 16:55:58                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-11 16:55:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-08-11 16:55:59                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xdbec  
      Audit Success   12544      2014-08-11 16:56:07                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-11 16:56:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14552   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 16:56:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x1457b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 16:56:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 16:56:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 16:56:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 16:56:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14552    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-11 16:56:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x1457b    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12548      2014-08-11 16:56:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-11 16:56:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-11 16:56:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-11 16:56:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 16:56:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 16:56:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 16:56:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-11 16:56:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-11 16:56:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-11 16:56:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 16:56:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-11 16:56:10                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-08-11 16:56:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 16:56:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-11 16:56:15                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-11 16:56:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3b138   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 16:57:52                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x310    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-11 16:57:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x66d9b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x310    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 16:57:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x66e2a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x310    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 16:57:52                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-11 16:57:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x66cde   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 16:57:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x66d95   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-11 16:57:52                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66e2a     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-11 16:57:52                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66d9b     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-11 16:57:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x66d9b    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-11 16:57:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x66cde    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-11 16:57:52                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-11 16:57:52                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-11 16:57:52                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-11 16:57:52                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-11 16:57:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66d95     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 16:57:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66d95     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 16:57:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66d95     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-11 16:57:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 16:57:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-11 16:57:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66d95     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 16:57:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66d95     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 16:57:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66d95     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 16:57:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66d95     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 16:57:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66d95     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 16:57:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66d95     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-11 16:59:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 16:59:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-11 17:00:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 17:00:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-11 17:05:29                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:29                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:29                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:29                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:29                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12290      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66d95     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66d95     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 17:05:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66d95     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-11 17:06:44                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 17:06:44                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-11 17:10:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 17:10:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-11 17:18:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 17:18:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-11 17:34:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 17:34:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-11 17:48:14                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 17:48:14                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-11 17:48:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xf24d73   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  61744       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-11 17:48:25                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xf24d73     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-11 17:48:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xf27593   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  61745       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-11 17:48:42                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xf27593     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-11 17:52:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1017f99   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  61927       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 17:52:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1018236   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  61928       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-11 17:52:13                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1017f99     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-11 17:52:29                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1018236     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-11 17:53:15                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 17:53:15                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-11 17:56:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 17:56:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-11 17:58:15                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 17:58:15                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-11 18:00:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x12599cb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  62283       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-11 18:00:29                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x12599cb     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-11 18:00:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x125a4f4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  62285       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-11 18:00:45                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x125a4f4     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-11 18:03:15                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:03:15                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:08:15                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:08:15                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-11 18:12:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x151e35c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  63071       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 18:12:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x151e3a7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  63073       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-11 18:12:32                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x151e35c     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-11 18:12:48                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x151e3a7     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-11 18:13:15                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:13:15                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:18:15                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:18:15                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:23:15                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:23:15                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-11 18:24:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x179eb7d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  63684       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-11 18:24:34                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x179eb7d     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-11 18:24:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x179ed85   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  63686       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-11 18:24:45                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x179ed85     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-11 18:28:15                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:28:15                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:33:15                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:33:15                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:38:48                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:38:48                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:39:18                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:39:18                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:39:48                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:39:48                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:40:18                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:40:18                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:40:49                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:40:49                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:41:19                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:41:19                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:41:49                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:41:49                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:42:19                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:42:19                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:42:49                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:42:49                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:43:19                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:43:19                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:43:49                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:43:49                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:44:19                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:44:19                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:44:49                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:44:49                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:45:19                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:45:19                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:45:49                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:45:49                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:46:19                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:46:19                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:46:49                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:46:49                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:47:20                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:47:20                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:47:50                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:47:50                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:48:20                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:48:20                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:48:50                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:48:50                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:49:20                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:49:20                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:49:50                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:49:50                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:50:20                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:50:20                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 18:50:50                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 18:50:50                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12545      2014-08-11 19:40:01                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66d95      ,   .  ,  ,  .        .  
      Audit Success   103        2014-08-11 19:40:08                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-11 19:42:22                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-11 19:42:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 19:42:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 19:42:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 19:42:22                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-11 19:42:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x138b7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 19:42:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x138dc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 19:42:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-11 19:42:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-11 19:42:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x138b7    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-11 19:42:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x138dc    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   13568      2014-08-11 19:42:22                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xd70d  
      Audit Success   12544      2014-08-11 19:42:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 19:42:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 19:42:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 19:42:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-11 19:42:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-11 19:42:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-11 19:42:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 19:42:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-11 19:42:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 19:42:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-11 19:42:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 19:42:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-11 19:42:30                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-08-11 19:42:32                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-11 19:42:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2e693   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13824      2014-08-11 19:43:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-11 19:43:06                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 19:43:06                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x6bfdf   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x6c0c2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x308    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x6c0af   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x6c314   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6c314     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6c0af     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x6bfdf    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x6c0af    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6c0c2     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6c0c2     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6c0c2     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6c0c2     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6c0c2     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6c0c2     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6c0c2     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6c0c2     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6c0c2     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-11 19:43:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 19:43:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-11 19:43:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12290      2014-08-11 19:44:06                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 19:44:06                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 19:49:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 19:49:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-11 19:49:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x3045da   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  64829       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V2    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 19:49:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x304a4d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  64831       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V2    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-11 19:49:38                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x304a4d     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-11 19:49:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3161ae   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  64829       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-11 19:49:52                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3161ae     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-11 19:49:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x317dd6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  64829       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 19:49:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x3180a8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  64829       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V2    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 19:49:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x3180ee   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  64831       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V2    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-11 19:49:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x317dd6     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-11 19:49:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x3180ee     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-11 19:50:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x332295   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  64829       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-11 19:50:17                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x332295     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-11 19:53:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x435af3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  64829       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-11 19:53:14                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x435af3     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-11 19:53:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x440989   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  64829       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-11 19:53:24                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x440989     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-11 19:54:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x46dba7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  64829       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-11 19:54:05                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x46dba7     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-11 19:54:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 19:54:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-11 19:55:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 19:55:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-11 19:59:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 19:59:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12545      2014-08-11 20:03:27                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x3180a8     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-11 20:04:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 20:04:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-11 20:04:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 20:04:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-08-11 20:04:53                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6bfdf    :    : Security    : File    : C:\Users\BLACK_~1\AppData\Local\Temp\winre\ExtractedFromWim    : 0x2c4      :    : 0xec4    : C:\Windows\System32\taskhost.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   12544      2014-08-11 20:05:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 20:05:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-11 20:09:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 20:09:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 20:14:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 20:14:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 20:19:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 20:19:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 20:24:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 20:24:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 20:29:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 20:29:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12292      2014-08-11 20:34:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 20:34:38                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-08-11 20:39:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 20:39:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 20:44:38                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 20:44:38                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 20:49:38                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 20:49:38                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 20:54:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 20:54:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 20:59:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 20:59:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 21:04:38                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 21:04:38                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 21:09:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 21:09:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 21:14:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 21:14:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-11 21:14:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 21:14:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-11 21:14:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 21:14:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-11 21:15:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 21:15:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-11 21:18:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 21:18:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-11 21:19:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 21:19:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-11 21:23:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6c0c2     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-11 21:24:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 21:24:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 21:29:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 21:29:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 21:34:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 21:34:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 21:39:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 21:39:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 21:44:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 21:44:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-11 21:47:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 21:47:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-11 21:49:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 21:49:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 21:54:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 21:54:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 21:59:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 21:59:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:04:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:04:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:09:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:09:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:14:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:14:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:17:42                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:17:42                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:18:12                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:18:12                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12545      2014-08-11 22:18:21                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x3045da     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-11 22:18:43                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:18:43                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:19:13                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:19:13                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:19:43                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:19:43                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:20:13                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:20:13                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:20:43                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:20:43                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:21:13                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:21:13                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:21:43                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:21:43                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:22:13                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:22:13                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:22:43                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:22:43                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:23:14                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:23:14                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:23:44                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:23:44                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:24:14                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:24:14                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:24:44                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:24:44                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:25:14                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:25:14                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-11 22:25:44                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-11 22:25:44                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12288      2014-08-11 22:59:15                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    : 0x1fe0   :  C:\Program Files\KMSpico\AutoPico.exe     :  2014-08-11T18:59:18.194892700Z   :  2014-08-11T18:59:15.367000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2014-08-11 23:35:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 23:35:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-11 23:35:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-11 23:35:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 23:35:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-11 23:35:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-08-11 23:36:48                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7    :    : 0xf1c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x3e19cf2  
      Audit Success   13568      2014-08-11 23:36:48                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7    :    : 0xf1c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x3e19cf2  
      Audit Success   12544      2014-08-11 23:38:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-11 23:38:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-08-11 23:40:52                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6c0c2      ,   .  ,  ,  .        .  
      Audit Success   103        2014-08-11 23:41:00                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-12 16:54:17                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-12 16:54:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-08-12 16:54:17                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xda1f  
      Audit Success   12544      2014-08-12 16:54:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 16:54:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 16:54:28                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2e4    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-12 16:54:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14632   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e4    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 16:54:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x1465b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e4    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 16:54:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-12 16:54:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-12 16:54:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14632    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-12 16:54:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x1465b    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12544      2014-08-12 16:54:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 16:54:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 16:54:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 16:54:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 16:54:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-12 16:54:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-12 16:54:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-12 16:54:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 16:54:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 16:54:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-12 16:54:31                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-08-12 16:54:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 16:54:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-12 16:54:32                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-12 16:54:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2a256   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 16:55:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 16:55:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-12 16:55:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:55:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   12290      2014-08-12 16:55:05                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-12 16:55:05                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-12 16:55:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:55:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:55:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:55:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:55:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:55:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-12 16:55:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 16:55:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-12 16:56:03                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-12 16:56:03                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-12 16:56:03                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:03                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-12 16:56:03                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:03                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   12544      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x310    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xc33d4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x310    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xc3f98   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x310    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2e4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xc24c5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e4    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xc33a8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e4    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc3f98     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33d4     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xc33d4    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xc24c5    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-12 16:56:05                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-12 16:56:05                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-12 16:56:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 16:56:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 16:56:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12544      2014-08-12 16:57:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 16:57:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 16:57:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 16:57:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 17:02:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 17:02:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 17:07:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 17:07:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-08-12 17:29:08                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    : 0x1094   :  C:\Program Files\KMSpico\AutoPico.exe     :  2014-08-12T13:29:06.245729400Z   :  2014-08-12T13:29:09.000000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2014-08-12 18:23:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 18:23:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 18:23:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 18:23:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 18:23:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 18:23:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 18:27:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 18:27:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 18:29:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 18:29:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 18:29:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 18:29:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-12 18:46:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 18:46:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 18:46:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 18:46:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 18:46:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 18:46:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 18:47:42                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 18:47:42                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 18:47:42                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 18:49:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 18:49:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 18:49:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 18:49:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 18:49:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 18:49:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12545      2014-08-12 18:52:17                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xc33a8      ,   .  ,  ,  .        .  
      Audit Success   103        2014-08-12 18:52:25                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-12 19:39:03                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-12 19:39:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-08-12 19:39:03                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xd84c  
      Audit Success   12544      2014-08-12 19:39:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 19:39:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 19:39:04                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-12 19:39:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x139f8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 19:39:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13a1a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 19:39:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 19:39:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 19:39:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-12 19:39:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-12 19:39:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x139f8    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-12 19:39:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13a1a    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12548      2014-08-12 19:39:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-12 19:39:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 19:39:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 19:39:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 19:39:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 19:39:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 19:39:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 19:39:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-12 19:39:11                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-08-12 19:39:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 19:39:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-12 19:39:12                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-12 19:39:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x38532   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 19:39:33                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-12 19:39:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x56b50   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 19:39:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x56c0a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 19:39:33                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-12 19:39:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x56c0c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 19:39:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x56cda   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-12 19:39:33                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56cda     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-12 19:39:33                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0c     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-12 19:39:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x56b50    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-12 19:39:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x56c0c    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-12 19:39:33                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-12 19:39:33                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-12 19:39:33                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-12 19:39:33                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-12 19:39:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-12 19:39:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 19:39:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-12 19:39:42                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:42                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:42                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:42                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:42                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12290      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 19:39:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12544      2014-08-12 19:40:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 19:40:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-12 19:40:49                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-12 19:40:49                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-12 19:52:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 19:52:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 21:51:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 21:51:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 22:04:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 22:04:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 22:20:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 22:20:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 22:22:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 22:22:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 22:22:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 22:22:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 22:22:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 22:22:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-08-12 22:24:18                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7    :    : 0x1d00    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x32bb20a  
      Audit Success   13568      2014-08-12 22:24:18                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7    :    : 0x1d00    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x32bb20a  
      Audit Success   13824      2014-08-12 22:27:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:27:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:21                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:21                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:21                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-12 22:35:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12544      2014-08-12 22:40:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 22:40:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 23:09:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 23:09:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 23:13:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-12 23:13:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 23:13:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-12 23:13:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-08-12 23:13:57                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7    :    : 0x1d30    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x4875f83  
      Audit Success   13568      2014-08-12 23:13:57                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7    :    : 0x1d30    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x4875f83  
      Audit Success   13568      2014-08-12 23:14:02                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms    : 0x454      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:14:02                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms    : 0x6d0      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:14:02                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_common_files_d7a65bb2f0e854e7.cdf-ms    : 0x434      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:14:02                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_818c5a0e45020fba.cdf-ms    : 0x6c0      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:14:02                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_microsoft_camera_codec_pack_43bf6d6fddb204a6.cdf-ms    : 0x6d0      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:14:02                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86__676bbe2c7241b694.cdf-ms    : 0x454      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:14:02                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_common_files_dfa3680ec228c528.cdf-ms    : 0x6dc      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:14:02                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_common_files_microsoft_shared_635c287ec97ec0a5.cdf-ms    : 0x6e0      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:14:02                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_common_files_microsoft_shared_microsoft_camera_codec_pack_dad7c5bd343dbf1b.cdf-ms    : 0x674      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:14:02                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll    : 0x67c      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:14:03                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Common Files\microsoft shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll    : 0x6dc      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:14:59                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7    :    : 0x1d30    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x49180c5  
      Audit Success   13568      2014-08-12 23:14:59                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7    :    : 0x1d30    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x49180c5  
      Audit Success   13568      2014-08-12 23:17:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms    : 0xba0      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86__676bbe2c7241b694.cdf-ms    : 0xb64      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_internet_explorer_cafab575245eacb0.cdf-ms    : 0x1ad0      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_common_files_dfa3680ec228c528.cdf-ms    : 0x13a0      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_common_files_microsoft_shared_635c287ec97ec0a5.cdf-ms    : 0xeac      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_common_files_microsoft_shared_vgx_9d0cc8bc56d58860.cdf-ms    : 0xb64      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms    : 0x1ad0      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_a421d1bfaf856e2b.cdf-ms    : 0x1284      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_ru-ru_3f04dde1653a9868.cdf-ms    : 0x9a8      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_common_files_d7a65bb2f0e854e7.cdf-ms    : 0x1ad0      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_818c5a0e45020fba.cdf-ms    : 0xb20      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_vgx_3c86fd9f0b3afd9b.cdf-ms    : 0xf6c      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$.cdf-ms    : 0x964      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_21ffbdd2a2dd92e0.cdf-ms    : 0xf6c      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_ru-ru_b70b8052528b002f.cdf-ms    : 0xf6c      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_policydefinitions_89130cdfc4d9c27c.cdf-ms    : 0xeac      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_policydefinitions_ru-ru_3947e28191bee0bf.cdf-ms    : 0x1eb4      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms    : 0x57c      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_spp_tokens_ppdlic_0f09ba294211a24b.cdf-ms    : 0xeac      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_wdi_06656d5fd047ab7c.cdf-ms    : 0x1494      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_wdi_perftrack_e5904ddd3f58b556.cdf-ms    : 0xc3c      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_ru-ru_5b50e7f65fce4fdb.cdf-ms    : 0x1eb4      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\vbscript.dll    : 0xb20      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\jscript9diag.dll    : 0x888      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ieapfltr.dll    : 0x57c      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\dxtmsft.dll    : 0x1494      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\inetcpl.cpl    : 0x1eb4      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\jscript9.dll    : 0x57c      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\dxtrans.dll    : 0x1284      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ieetwcollectorres.dll    : 0xab8      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\iesetup.dll    : 0x13a0      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\iernonce.dll    : 0xf6c      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ie4uinit.exe    : 0xb64      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:17:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\mshtmled.dll    : 0x888      :    : 0x1bb8    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   12544      2014-08-12 23:27:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 23:27:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 23:27:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 23:27:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 23:31:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 23:31:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 23:45:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 23:45:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-12 23:45:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-12 23:45:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-08-12 23:47:39                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x56c0a      ,   .  ,  ,  .        .  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86__676bbe2c7241b694.cdf-ms    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_internet_explorer_cafab575245eacb0.cdf-ms    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_common_files_dfa3680ec228c528.cdf-ms    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_common_files_microsoft_shared_635c287ec97ec0a5.cdf-ms    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_common_files_microsoft_shared_vgx_9d0cc8bc56d58860.cdf-ms    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_a421d1bfaf856e2b.cdf-ms    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_ru-ru_3f04dde1653a9868.cdf-ms    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_common_files_d7a65bb2f0e854e7.cdf-ms    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_818c5a0e45020fba.cdf-ms    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_vgx_3c86fd9f0b3afd9b.cdf-ms    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$.cdf-ms    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_21ffbdd2a2dd92e0.cdf-ms    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_ru-ru_b70b8052528b002f.cdf-ms    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_policydefinitions_89130cdfc4d9c27c.cdf-ms    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_policydefinitions_ru-ru_3947e28191bee0bf.cdf-ms    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_spp_tokens_ppdlic_0f09ba294211a24b.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_wdi_06656d5fd047ab7c.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_wdi_perftrack_e5904ddd3f58b556.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_ru-ru_5b50e7f65fce4fdb.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\vbscript.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\jscript9diag.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ieapfltr.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\dxtmsft.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\inetcpl.cpl    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\jscript9.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\dxtrans.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ieetwcollectorres.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\iesetup.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\iernonce.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ie4uinit.exe    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\mshtmled.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\urlmon.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\msfeeds.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\iertutil.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\mshtml.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ieframe.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\msrating.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ieetwproxystub.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\JavaScriptCollectionAgent.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ieUnatt.exe    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\MshtmlDac.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\iedkcs32.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ieetwcollector.exe    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\mshtml.tlb    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\jsproxy.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wininet.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\ieframe.dll.mui    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\mshtml.dll.mui    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\inetcpl.cpl.mui    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wdi\perftrack\Microsoft-Windows-IE-F12-Provider.ptxml    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\spp\tokens\ppdlic\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\PolicyDefinitions\inetres.admx    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:18                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\PolicyDefinitions\ru-RU\InetRes.adml    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\vbscript.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\ieapfltr.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\jscript9diag.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\jscript9.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\inetcpl.cpl    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\dxtmsft.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\dxtrans.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\mshtmled.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\urlmon.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\iesetup.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\iernonce.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\mshtml.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\iertutil.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\ieframe.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\msfeeds.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\ieetwproxystub.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\msrating.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\ieUnatt.exe    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\MshtmlDac.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\jsproxy.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\wininet.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\mshtml.tlb    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\iedkcs32.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Common Files\microsoft shared\VGX\VGX.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Internet Explorer\DiagnosticsHub.DataWarehouse.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Internet Explorer\DiagnosticsHub.ScriptedSandboxPlugin.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Internet Explorer\Timeline.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Internet Explorer\iexplore.exe    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Internet Explorer\DiagnosticsTap.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Internet Explorer\MemoryAnalyzer.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Internet Explorer\F12Resources.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Internet Explorer\F12.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Internet Explorer\networkinspection.dll    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Internet Explorer\ieinstal.exe    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Internet Explorer\F12Tools.dll    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Internet Explorer\ieproxy.dll    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Internet Explorer\IEShims.dll    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Internet Explorer\Timeline.cpu.xml    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Internet Explorer\Timeline_is.dll    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Internet Explorer\ru-RU\F12.dll.mui    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Internet Explorer\ru-RU\F12Resources.dll.mui    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll    : 0x14      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files (x86)\Internet Explorer\iexplore.exe    : 0x18      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files (x86)\Internet Explorer\DiagnosticsTap.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files (x86)\Internet Explorer\networkinspection.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files (x86)\Internet Explorer\ieproxy.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files (x86)\Internet Explorer\ieinstal.exe    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files (x86)\Internet Explorer\F12Tools.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files (x86)\Internet Explorer\IEShims.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_3296b36dbe4c7fa3.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_083d4e330e766c5d.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v2.0.50727_443de60f3f6e0828.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v2.0.50727_1049_b3c88eb313ae6c54.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v2.0.50727_1033_b3c88eb113ae6c57.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v2.0.50727_mui_0409_ffa7e0a2ff8e4b5a.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v2.0.50727_mui_0419_ffa7e0a4ff8e4b51.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v2.0.50727_ru_37601495d41259a7.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_83386eac0379231b.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_e9368840261e60ee.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_1049_7994ec1e0abd5342.cdf-ms    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_1033_7994eb100abd5435.cdf-ms    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_mui_0409_fbbb44c0c63bd26c.cdf-ms    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_mui_0419_fbbb46a6c63bcf93.cdf-ms    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_ru_9d42e46d3d1bb62b.cdf-ms    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_21ffbdd2a2dd92e0.cdf-ms    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_mui_0419_29ea5b14e6ab1a5d.cdf-ms    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_mui_0419_ecc96e109498d625.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\MUI\0419\mscorees.dll    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\MUI\0419\mscorees.dll    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscortim.dll    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe    : 0x28      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\CasPol.exe    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscoree.tlb    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Management.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorld.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\normalization.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\ngen.exe    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.tlb    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\alink.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Data.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\peverify.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.tlb    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\dfdll.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:20                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\IEHost.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\cscomp.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Web.tlb    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\IEExec.exe    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.tlb    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\vsavb7.olb    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.tlb    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.tlb    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.tlb    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.tlb    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\shfusion.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\ru\aspnet_rc.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\ru\mscorrc.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\ru\ShFusRes.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\MUI\0419\mscorsecr.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\1049\CvtResUI.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\1049\alinkui.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\1049\cscompui.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\1049\Vsavb7rtUI.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\1049\vbc7ui.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscortim.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscordacwks.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Windows.Forms.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\dw20.exe    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Deployment.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CORPerfMonExt.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\IEExecRemote.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\InstallUtil.exe    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:21                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\PerfCounter.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Messaging.dll    : 0x18      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CasPol.exe    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorpjt.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscoree.tlb    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\EventLogMessages.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Microsoft.Build.Engine.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\aspnet_filter.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Management.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorld.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\fusion.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\aspnet_isapi.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\RegSvcs.exe    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\normalization.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\MSBuild.exe    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\ShFusRes.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscordbi.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Microsoft.Vsa.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\ilasm.exe    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Microsoft.Vsa.tlb    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Data.OracleClient.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Microsoft.Build.Utilities.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\ngen.exe    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\alink.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\aspnet_rc.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\sysglobl.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsn.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\IIEHost.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\ISymWrapper.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\diasymreader.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Data.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\peverify.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.EnterpriseServices.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\SOS.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.EnterpriseServices.tlb    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.DirectoryServices.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\vbc.exe    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Microsoft.Build.Framework.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\dfdll.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Transactions.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\aspnet_wp.exe    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.EnterpriseServices.Wrapper.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Microsoft.VisualBasic.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Security.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Data.SqlXml.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\MmcAspExt.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.XML.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsec.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorrc.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\IEHost.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\webengine.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Ldr64.exe    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\InstallUtilLib.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.DirectoryServices.Protocols.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cscomp.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cscompmgd.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Web.tlb    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\RegAsm.exe    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Web.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\TLBREF.DLL    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscordbc.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\AppLaunch.exe    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Configuration.Install.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\IEExec.exe    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Microsoft.JScript.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.EnterpriseServices.Thunk.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.configuration.dll    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Drawing.tlb    : 0x24      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Microsoft.JScript.tlb    : 0x20      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Drawing.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Microsoft.Build.Tasks.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\jsc.exe    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\AdoNetDiag.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.ServiceProcess.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:22                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Aspnet_perf.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Windows.Forms.tlb    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\dfsvc.exe    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvc.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Web.RegularExpressions.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Drawing.Design.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Accessibility.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Design.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\shfusion.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CustomMarshalers.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\ru\aspnet_rc.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\ru\mscorrc.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\ru\ShFusRes.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\MUI\0419\mscorsecr.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\MUI\0409\mscorsecr.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\1033\CvtResUI.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\1033\alinkui.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\1033\cscompui.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\1033\vbc7ui.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\1049\CvtResUI.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\1049\alinkui.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\1049\cscompui.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\1049\vbc7ui.dll    : 0x2c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_f89c5a39d351281a.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_a4ba21b6f468ca9e.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_61efdd9e2d0263ca.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.0_44577d982216c291.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86__676bbe2c7241b694.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_reference_assemblies_41115a5fd4566dab.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_reference_assemblies_microsoft_ad470207ad610db1.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_reference_assemblies_microsoft_framework_b81ea2cfde84fb19.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_reference_assemblies_microsoft_framework_v3.0_1dfad1527dc1078c.cdf-ms    : 0x3c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_3296b36dbe4c7fa3.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_083d4e330e766c5d.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v3.0_d97e7188b51e6116.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v3.0_wpf_f80a7f17f38f3771.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v3.0_wpf_ru-ru_19ab931b774defe2.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v3.0_windows_communication_foundation_7de82ac14fafbb1e.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v3.0_windows_communication_foundation_ru-ru_8a6a171c2f279b81.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_83386eac0379231b.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_wpf_b56a2354fbfa0c31.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_wpf_ru-ru_3abd41056abbbebc.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_windows_communication_foundation_e07323de19ff1b52.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_21ffbdd2a2dd92e0.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_xpsviewer_ru-ru_aeef64bf80f1009a.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_ru-ru_b70b8052528b002f.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_ru-ru_5b50e7f65fce4fdb.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\TsWpfWrp.exe    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\PresentationHost.exe.mui    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\TsWpfWrp.exe    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\ru-RU\PresentationHost.exe.mui    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\XPSViewer\ru-RU\XPSViewer.exe.mui    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.Dtc.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMConfigInstaller.exe    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceMonikerSupport.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v3.0\WPF\ru-RU\PresentationHostDLL.dll.mui    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.Dtc.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelEvents.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMConfigInstaller.exe    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceMonikerSupport.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMdiagnostics.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\System.ServiceModel.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ru-RU\ServiceModelInstallRC.dll.mui    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ru-RU\ServiceModelEvents.dll.mui    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\ru-RU\PresentationHostDLL.dll.mui    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\System.IdentityModel.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\System.ServiceModel.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.IdentityModel.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:24                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.ServiceModel.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_21ffbdd2a2dd92e0.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_spp_tokens_ppdlic_ee939189101570f7.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_spp_tokens_ppdlic_0f09ba294211a24b.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\msihnd.dll    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\authui.dll    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\consent.exe    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\msi.dll    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\spp\tokens\ppdlic\authui-ppdlic.xrm-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\msihnd.dll    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\authui.dll    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\msi.dll    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\spp\tokens\ppdlic\authui-ppdlic.xrm-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\dxgkrnl.sys    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_21ffbdd2a2dd92e0.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\dwmcore.dll    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\dxgi.dll    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\dxgi.dll    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_21ffbdd2a2dd92e0.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\rpcrt4.dll    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\rpcrt4.dll    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_21ffbdd2a2dd92e0.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\gdi32.dll    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:25                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\win32k.sys    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\gdi32.dll    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_21ffbdd2a2dd92e0.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_en-us_9e576ab077991fe8.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_ru-ru_b70b8052528b002f.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_globalization_0fc22903a221b67f.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_globalization_time_zone_08f498d155d3913e.cdf-ms    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_en-us_429cd25484dc6f94.cdf-ms    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_ru-ru_5b50e7f65fce4fdb.cdf-ms    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\MrmCoreR.dll    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\tzres.dll.mui    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\en-US\tzres.dll.mui    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Globalization\Time Zone\timezoneMapping.xml    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Globalization\Time Zone\timezones.xml    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$.cdf-ms    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_wbem_06656d9fdf2f8577.cdf-ms    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\MDMAgent.exe    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wbem\MDMSettingsProv.dll    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wbem\MDMAppProv.mof    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wbem\MDMAppProv.dll    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wbem\MDMAppProv_Uninstall.mof    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\winload.efi    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\lsasrv.dll    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\winload.exe    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\winresume.exe    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\httpprxm.dll    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\winresume.efi    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ntoskrnl.exe    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\iphlpsvc.dll    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\adhsvc.dll    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\spp\tokens\ppdlic\Microsoft-Windows-NetworkBridge-ppdlic.xrm-ms    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\migration\IphlpsvcMigPlugin.dll    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\ndis.sys    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\bridge.sys    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\ks.sys    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\mrxsmb20.sys    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\tcpip.sys    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\netio.sys    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\ntfs.sys    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\migration\IphlpsvcMigPlugin.dll    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Boot\EFI\bootmgr.efi    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Boot\EFI\bootmgfw.efi    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Boot\PCAT\bootmgr    : 0x38      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms    : 0x3c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms    : 0x3c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_windows_journal_ada99bf7bc9c9733.cdf-ms    : 0x3c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_common_files_d7a65bb2f0e854e7.cdf-ms    : 0x3c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_818c5a0e45020fba.cdf-ms    : 0x3c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_ink_3c86e3db0b3b254c.cdf-ms    : 0x3c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$.cdf-ms    : 0x3c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_winstore_04445b88cf0b8e8d.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_boot_40104b85a18bfcb2.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_boot_pcat_0f8924c0debe64e4.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_boot_efi_0f890f82be247f42.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_21ffbdd2a2dd92e0.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_inputmethod_chs_5a48e65b9306b31f.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_migration_bdcfa47e8790e0c4.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_wbem_1bf25d11bb30b33f.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_wbem_ru-ru_032534f8d4f2171a.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_ru-ru_b70b8052528b002f.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_spp_tokens_ppdlic_ee939189101570f7.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_setup_b8f1f0fc4fb15499.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_inf_3f581daba4c8c835.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_1e6ccf0e6a91b570.cdf-ms    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_settings_08eec740d2195455.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_policydefinitions_89130cdfc4d9c27c.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_policydefinitions_ru-ru_3947e28191bee0bf.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_inputmethod_chs_f1e99f17c8c32153.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_drivers_ru-ru_646d299e39ab4c16.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_boot_06654401df2fc50e.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_migration_927a21df1acd7c18.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_wbem_06656d9fdf2f8577.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_wbem_ru-ru_438138a6b5df4494.cdf-ms    : 0x34      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_ru-ru_5b50e7f65fce4fdb.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_spp_tokens_ppdlic_0f09ba294211a24b.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_oobe_06655c95df2fa06f.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_setup_5d3758a05cf4a445.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_fonts_40104ba9a1d20dac.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_systemresources_0307ca33e1cd9708.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsapp_041d35a886a9ab39.cdf-ms    : 0x44      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsapp_pris_5b98fa23432d61fd.cdf-ms    : 0x44      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingshandlers_5b3af40f40f8bda7.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingshandlers_pris_71ec33a38f3576eb.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_resources_fbee56ab048ab239.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_resources_themes_4d0d4910e83c2273.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_resources_themes_aero_3fd78bf4cb5fa2c4.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_apppatch_1143992cbbbebcab.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_apppatch_apppatch64_e39bab3b20714e20.cdf-ms    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\explorer.exe    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\apppatch\drvmain.sdb    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\apppatch\sysmain.sdb    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\apppatch\apppatch64\sysmain.sdb    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Resources\Themes\aero\aerolite.msstyles    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Resources\Themes\aero\aero.msstyles    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:29                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SystemResources\Windows.UI.SettingsHandlers\Windows.UI.SettingsHandlers.pri    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SystemResources\Windows.UI.SettingsHandlers\pris\Windows.UI.SettingsHandlers.ru-RU.pri    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SystemResources\Windows.UI.SettingsApp\Windows.UI.SettingsApp.pri    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SystemResources\Windows.UI.SettingsApp\pris\Windows.UI.SettingsApp.ru-RU.pri    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\segoeuisl.ttf    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\arialbd.ttf    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\times.ttf    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\tahomabd.ttf    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\seguisbi.ttf    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\arial.ttf    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\timesbi.ttf    : 0x40      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\segoeui.ttf    : 0x44      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\seguisli.ttf    : 0x44      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\timesi.ttf    : 0x44      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\segoeuil.ttf    : 0x44      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\segoeuiz.ttf    : 0x44      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\micross.ttf    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\ariali.ttf    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\arialbi.ttf    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\tahoma.ttf    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\seguili.ttf    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\seguisb.ttf    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\segoeuib.ttf    : 0x60      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\segoeuii.ttf    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Fonts\timesbd.ttf    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\win32spl.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\mfmp4srcsnk.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\mfplat.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\winmm.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\rsaenh.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\netcfgx.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\usbmon.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\mstscax.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wshbth.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\VAN.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ActionCenter.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\mftranscode.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wsecedit.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wuauclt.exe    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\defragsvc.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\KBDRUM.DLL    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\schannel.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wucltux.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wwanmm.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wlansvcpal.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\WSDMon.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\KBDTAT.DLL    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wlanapi.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\authui.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\SRH.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\SettingsHandlers.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\mfreadwrite.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\winspool.drv    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wisp.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\GdiPlus.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wlansvc.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\compstui.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\DafPrintProvider.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\rdpudd.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wups.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\KBDTT102.DLL    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\stobject.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\WMVDECOD.DLL    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wcmcsp.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\Windows.Media.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\Windows.ApplicationModel.Store.TestingFramework.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\SndVolSSO.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wlansec.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\AppxSip.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:30                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\powercfg.cpl    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\workfolderssvc.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\bcryptprimitives.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\WebClnt.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\puiobj.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ApnDatabase.xml    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\d3d10warp.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\Windows.Devices.Bluetooth.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\WorkfoldersControl.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\user32.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wpdbusenum.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\shell32.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\actxprxy.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\srvsvc.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\KBDRU.DLL    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\SystemSettingsAdminFlows.exe    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\pmcsnap.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\WSShared.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\prnntfy.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\comdlg32.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\twinapi.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\mfcore.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\Display.dll    : 0x58      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\Windows.UI.Xaml.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\SettingSync.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\spoolsv.exe    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\conhost.exe    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\KBDRU1.DLL    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\Defrag.exe    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\AppxPackaging.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\clusapi.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\gpedit.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\BluetoothApis.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\aclui.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\profsvc.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\SndVol.exe    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\storagewmi.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\twinui.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\rdvidcrl.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\osk.exe    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\dwmapi.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\localspl.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\SHCore.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wups2.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\XpsPrint.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\KBDYAK.DLL    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wwanconn.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wudriver.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wuapi.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\PrintDialogs.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\SystemSettingsAdminFlowUI.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\KBDBASH.DLL    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\gpsvc.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\AppxSysprep.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\Windows.UI.Search.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\browser.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\printui.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\WiFiDisplay.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\winmmbase.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\rdpcorets.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\WorkFoldersShell.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\Windows.Networking.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wlanmsm.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wuaueng.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ppcsnap.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\uDWM.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\mfps.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\puiapi.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\WUSettingsProvider.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:31                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\locale.nls    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\SearchFolder.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\iasnap.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\WorkFoldersGPExt.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\mispace.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\certcli.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\dab.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\setup\tssysprep.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\oobe\msoobeplugins.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\spp\tokens\ppdlic\explorer-ppdlic.xrm-ms    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\spp\tokens\ppdlic\authui-ppdlic.xrm-ms    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\spp\tokens\ppdlic\TabletPCInputPanel-ppdlic.xrm-ms    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\spp\tokens\ppdlic\SMBServer-ppdlic.xrm-ms    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\spp\tokens\ppdlic\WinStoreUI-ppdlic.xrm-ms    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\shsvcs.dll.mui    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\storagewmi.dll.mui    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\aclui.dll.mui    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\twinui.dll.mui    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\KernelBase.dll.mui    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\DfrgUI.exe.mui    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\defragsvc.dll.mui    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wbem\netswitchteamcim.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wbem\ndisimplatcim.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wbem\storagewmi.mof    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wbem\ru-RU\storagewmi.mfl    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\Boot\winload.exe    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\Boot\winload.efi    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\nwifi.sys    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\srv2.sys    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\srvnet.sys    : 0x60      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\srv.sys    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\msgpioclx.sys    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\NdisImPlatform.sys    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\ru-RU\spaceport.sys.mui    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\ru-RU\usbhub.sys.mui    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\InputMethod\CHS\ChsIFEComp.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\PolicyDefinitions\Taskbar.admx    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\PolicyDefinitions\ru-RU\Taskbar.adml    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\ImmersiveControlPanel\SystemSettings.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\ImmersiveControlPanel\Settings\AAA_SystemSettings_Input_Touch_TapAndDrag.settingcontent-ms    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\ImmersiveControlPanel\Settings\AAA_SystemSettings_Input_Touch_DisableWithMouse.settingcontent-ms    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\ImmersiveControlPanel\Settings\AAA_SystemSettings_Input_Touch_RightClickZoneEnabled.settingcontent-ms    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Inf\printupg.inf    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Inf\apps.inf    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\mfplat.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\winmm.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\mfmp4srcsnk.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\rsaenh.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\netcfgx.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\explorer.exe    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\mstscax.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\wshbth.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\ActionCenter.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\VAN.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\wsecedit.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\mftranscode.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\KBDRUM.DLL    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\schannel.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\authui.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\KBDTAT.DLL    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\wlanapi.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\SRH.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\mfreadwrite.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\winspool.drv    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\wisp.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\GdiPlus.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\DafPrintProvider.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\wups.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\KBDTT102.DLL    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\stobject.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\Windows.Media.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\WMVDECOD.DLL    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\AppxSip.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\bcryptprimitives.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\powercfg.cpl    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\WebClnt.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\puiobj.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\d3d10warp.dll    : 0x54      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\user32.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\shell32.dll    : 0x64      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\actxprxy.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\KBDRU.DLL    : 0x64      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\prnntfy.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\comdlg32.dll    : 0x64      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\WSShared.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\mfcore.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\Display.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\SettingSync.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\Windows.UI.Xaml.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\KBDRU1.DLL    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\AppxPackaging.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\BluetoothApis.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\clusapi.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\gpedit.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\aclui.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\storagewmi.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\SndVol.exe    : 0x6c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\twinui.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\rdvidcrl.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\osk.exe    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\SHCore.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\dwmapi.dll    : 0x30      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\KBDYAK.DLL    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\XpsPrint.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\PrintDialogs.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\wuapi.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\wudriver.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\KBDBASH.DLL    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\Windows.UI.Search.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\winmmbase.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\printui.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\Windows.Networking.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\wlanmsm.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\puiapi.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\iasnap.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\certcli.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\mispace.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\setup\tssysprep.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\spp\tokens\ppdlic\authui-ppdlic.xrm-ms    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\wbem\storagewmi.mof    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\InputMethod\CHS\ChsIFEComp.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinStore\WinStoreUI.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinStore\AppxSignature.p7x    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Common Files\microsoft shared\ink\TipRes.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Common Files\microsoft shared\ink\tipskins.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Windows Journal\Journal.exe    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Windows Journal\InkSeg.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Windows Journal\JNTFiltr.dll    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Windows Journal\NBDoc.DLL    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Windows Journal\MSPVWCTL.DLL    : 0x68      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$.cdf-ms    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_21ffbdd2a2dd92e0.cdf-ms    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_migration_927a21df1acd7c18.cdf-ms    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-12 23:48:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\WpcWebSync.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\Wpc.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\WpcMon.exe    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\migration\WpcMigration.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-12 23:48:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\Wpc.dll    : 0x4c      :    : 0x1cfc    : C:\Windows\System32\poqexec.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   103        2014-08-12 23:49:38                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-13 17:06:22                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-13 17:06:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-08-13 17:06:22                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x10b97  
      Audit Success   12544      2014-08-13 17:06:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-13 17:06:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-13 17:06:26                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-13 17:06:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x1756c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-13 17:06:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x1758d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 17:06:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-13 17:06:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-13 17:06:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x1756c    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-13 17:06:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x1758d    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12544      2014-08-13 17:06:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 17:06:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-13 17:06:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-13 17:06:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-13 17:06:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 17:06:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-13 17:06:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-13 17:06:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-13 17:06:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 17:06:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-13 17:06:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 17:06:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-13 17:06:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 17:06:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-13 17:06:35                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-08-13 17:06:37                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-13 17:06:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3ec60   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\bg-BG\bootmgr.exe.mui    : 0x394      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\bootmgr    : 0x30c      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\bootnxt    : 0x30c      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\cs-CZ\bootmgr.exe.mui    : 0x3b8      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\cs-CZ\memtest.exe.mui    : 0x398      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\da-DK\bootmgr.exe.mui    : 0x398      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\da-DK\memtest.exe.mui    : 0x398      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\de-DE\bootmgr.exe.mui    : 0x2c0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\de-DE\memtest.exe.mui    : 0x328      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\el-GR\bootmgr.exe.mui    : 0x1fc      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\el-GR\memtest.exe.mui    : 0x1fc      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\en-GB\bootmgr.exe.mui    : 0x1fc      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\en-US\bootmgr.exe.mui    : 0x1fc      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\en-US\memtest.exe.mui    : 0x3ac      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\es-ES\bootmgr.exe.mui    : 0x3d4      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\es-ES\memtest.exe.mui    : 0x3ac      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\et-EE\bootmgr.exe.mui    : 0x3d4      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\fi-FI\bootmgr.exe.mui    : 0x3d4      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\fi-FI\memtest.exe.mui    : 0x3d4      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\fr-FR\bootmgr.exe.mui    : 0x3f4      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\fr-FR\memtest.exe.mui    : 0x30c      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\hr-HR\bootmgr.exe.mui    : 0x398      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\hu-HU\bootmgr.exe.mui    : 0x34c      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\hu-HU\memtest.exe.mui    : 0x34c      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\it-IT\bootmgr.exe.mui    : 0x34c      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\it-IT\memtest.exe.mui    : 0x3c8      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\ja-JP\bootmgr.exe.mui    : 0x38c      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\ja-JP\memtest.exe.mui    : 0x32c      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\ko-KR\bootmgr.exe.mui    : 0x38c      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\ko-KR\memtest.exe.mui    : 0x38c      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\lt-LT\bootmgr.exe.mui    : 0x32c      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\lv-LV\bootmgr.exe.mui    : 0x3ac      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\memtest.exe    : 0x1fc      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\nb-NO\bootmgr.exe.mui    : 0x3f4      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\nb-NO\memtest.exe.mui    : 0x32c      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\nl-NL\bootmgr.exe.mui    : 0x32c      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\nl-NL\memtest.exe.mui    : 0x38c      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\pl-PL\bootmgr.exe.mui    : 0x2e0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\pl-PL\memtest.exe.mui    : 0x3c8      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\pt-BR\bootmgr.exe.mui    : 0x38c      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\pt-BR\memtest.exe.mui    : 0x3c8      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\pt-PT\bootmgr.exe.mui    : 0x3b8      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\pt-PT\memtest.exe.mui    : 0x3a4      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\qps-ploc\bootmgr.exe.mui    : 0x3a4      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\qps-ploc\memtest.exe.mui    : 0x3a4      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\ro-RO\bootmgr.exe.mui    : 0x3a4      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\ru-RU\bootmgr.exe.mui    : 0x3a4      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\ru-RU\memtest.exe.mui    : 0x3c8      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\sk-SK\bootmgr.exe.mui    : 0x2e0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\sl-SI\bootmgr.exe.mui    : 0x2e0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\sr-Latn-CS\bootmgr.exe.mui    : 0x2e0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\sr-Latn-RS\bootmgr.exe.mui    : 0x2e0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\sv-SE\bootmgr.exe.mui    : 0x2e0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\sv-SE\memtest.exe.mui    : 0x2e0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\tr-TR\bootmgr.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\tr-TR\memtest.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\uk-UA\bootmgr.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\zh-CN\bootmgr.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\zh-CN\memtest.exe.mui    : 0x2f0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\zh-HK\bootmgr.exe.mui    : 0x2f0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\zh-HK\memtest.exe.mui    : 0x2f0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\zh-TW\bootmgr.exe.mui    : 0x360      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\zh-TW\memtest.exe.mui    : 0x370      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\bootmgr    : 0x3b0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\bg-BG\bootmgr.exe.mui    : 0x3a0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\bootmgr    : 0x360      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\bootnxt    : 0x360      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\cs-CZ\bootmgr.exe.mui    : 0x3a0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\cs-CZ\memtest.exe.mui    : 0x3a0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\da-DK\bootmgr.exe.mui    : 0x3a0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\da-DK\memtest.exe.mui    : 0x3a0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\de-DE\bootmgr.exe.mui    : 0x3a0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\de-DE\memtest.exe.mui    : 0x3a0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\el-GR\bootmgr.exe.mui    : 0x3a0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\el-GR\memtest.exe.mui    : 0x3a0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\en-GB\bootmgr.exe.mui    : 0x3a0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\en-US\bootmgr.exe.mui    : 0x3a0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\en-US\memtest.exe.mui    : 0x3a0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\es-ES\bootmgr.exe.mui    : 0x3a0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\es-ES\memtest.exe.mui    : 0x3a0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\et-EE\bootmgr.exe.mui    : 0x3a0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\fi-FI\bootmgr.exe.mui    : 0x3a0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\fi-FI\memtest.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\fr-FR\bootmgr.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\fr-FR\memtest.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\hr-HR\bootmgr.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\hu-HU\bootmgr.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\hu-HU\memtest.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\it-IT\bootmgr.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\it-IT\memtest.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\ja-JP\bootmgr.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\ja-JP\memtest.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\ko-KR\bootmgr.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\ko-KR\memtest.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\lt-LT\bootmgr.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\lv-LV\bootmgr.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\memtest.exe    : 0x360      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\nb-NO\bootmgr.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\nb-NO\memtest.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\nl-NL\bootmgr.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\nl-NL\memtest.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\pl-PL\bootmgr.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\pl-PL\memtest.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\pt-BR\bootmgr.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\pt-BR\memtest.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\pt-PT\bootmgr.exe.mui    : 0x3ec      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\pt-PT\memtest.exe.mui    : 0x3c8      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\qps-ploc\bootmgr.exe.mui    : 0x3c8      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\qps-ploc\memtest.exe.mui    : 0x3c8      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\ro-RO\bootmgr.exe.mui    : 0x3c8      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\ru-RU\bootmgr.exe.mui    : 0x3c8      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\ru-RU\memtest.exe.mui    : 0x3c8      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\sk-SK\bootmgr.exe.mui    : 0x2e0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\sl-SI\bootmgr.exe.mui    : 0x2e0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\sr-Latn-CS\bootmgr.exe.mui    : 0x2e0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\sr-Latn-RS\bootmgr.exe.mui    : 0x2e0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\sv-SE\bootmgr.exe.mui    : 0x2e0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\sv-SE\memtest.exe.mui    : 0x2e0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\tr-TR\bootmgr.exe.mui    : 0x3fc      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\tr-TR\memtest.exe.mui    : 0x3fc      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\uk-UA\bootmgr.exe.mui    : 0x3fc      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\zh-CN\bootmgr.exe.mui    : 0x3fc      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\zh-CN\memtest.exe.mui    : 0x3fc      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\zh-HK\bootmgr.exe.mui    : 0x2e0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\zh-HK\memtest.exe.mui    : 0x2e0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\zh-TW\bootmgr.exe.mui    : 0x2e0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\Boot\zh-TW\memtest.exe.mui    : 0x2e0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-13 17:07:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : \Device\HarddiskVolume1\bootmgr    : 0x3b0      :    : 0x4c0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   12544      2014-08-13 17:07:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 17:07:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-13 17:08:04                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-13 17:08:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xb36a4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-13 17:08:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xb3728   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-13 17:08:04                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-13 17:08:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xb35d5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-13 17:08:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xb3688   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-13 17:08:04                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3728     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-13 17:08:04                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb36a4     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-13 17:08:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xb36a4    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-13 17:08:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xb35d5    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-13 17:08:04                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-13 17:08:04                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-13 17:08:04                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-13 17:08:04                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   12544      2014-08-13 17:08:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 17:08:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-13 17:08:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 17:08:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-13 17:08:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:08:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:08:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:08:21                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:08:21                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:08:21                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:08:21                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:08:21                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:08:21                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:32                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-13 17:10:47                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-13 17:10:47                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-13 17:10:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:10:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-13 17:11:47                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-13 17:11:47                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-13 17:11:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:11:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:11:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:11:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:11:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:11:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-13 17:12:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 17:12:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-13 17:14:39                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-08-13 17:14:39                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-13 17:14:39                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12292      2014-08-13 17:14:39                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-13 17:14:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:14:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:14:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-13 17:15:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 17:15:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-13 17:22:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:22:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 17:22:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12545      2014-08-13 17:46:55                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xb3688      ,   .  ,  ,  .        .  
      Audit Success   103        2014-08-13 17:47:02                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-13 22:39:54                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-13 22:39:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-13 22:39:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-13 22:39:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-13 22:39:54                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-13 22:39:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13a47   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-13 22:39:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13a6a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 22:39:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-13 22:39:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-13 22:39:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13a47    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-13 22:39:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13a6a    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   13568      2014-08-13 22:39:54                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xe777  
      Audit Success   12544      2014-08-13 22:39:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 22:39:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-13 22:39:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-13 22:39:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 22:39:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-13 22:39:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-13 22:40:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 22:40:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-13 22:40:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 22:40:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-13 22:40:08                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-08-13 22:40:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 22:40:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-13 22:40:13                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-13 22:40:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x38ece   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13824      2014-08-13 22:41:13                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:41:13                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:41:13                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:41:13                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:41:13                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:41:13                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:41:13                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:41:13                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-13 22:41:14                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-13 22:41:14                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-13 22:41:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 22:41:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-13 22:41:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 22:41:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-13 22:42:15                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-13 22:42:15                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-13 22:42:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 22:42:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x199631   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x19973a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x308    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x199756   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x1997d2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x1997d2     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x199756     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x199631    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x199756    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x19973a     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x19973a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x19973a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x19973a     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x19973a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x19973a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x19973a     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x19973a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x19973a     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:41                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-13 22:44:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12544      2014-08-13 22:45:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 22:45:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-13 22:52:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 22:52:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-13 22:53:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 22:53:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-13 22:54:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 22:54:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-13 22:57:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-13 22:57:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-08-13 23:02:07                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x19973a      ,   .  ,  ,  .        .  
      Audit Success   103        2014-08-13 23:02:20                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-14 17:58:55                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-14 17:58:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 17:58:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 17:58:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-08-14 17:58:55                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xe326  
      Audit Success   12544      2014-08-14 17:58:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 17:58:56                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2e4    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-14 17:58:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13f7e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e4    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 17:58:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13fa0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e4    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 17:58:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-14 17:58:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13f7e    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-14 17:58:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13fa0    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12544      2014-08-14 17:58:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 17:58:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 17:58:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-14 17:58:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 17:59:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 17:59:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 17:59:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 17:59:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 17:59:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 17:59:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 17:59:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 17:59:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-14 17:59:08                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-08-14 17:59:12                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-14 17:59:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3af1b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12290      2014-08-14 18:00:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 18:00:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 18:00:05                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 18:00:05                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-14 18:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-14 18:00:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 18:00:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-14 18:01:06                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 18:01:06                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 18:01:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 18:01:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x318    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xa271a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x318    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xa279e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x318    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2e4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xa264a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e4    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xa2705   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e4    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xa279e     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xa271a     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xa271a    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0xa264a    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xa2705     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xa2705     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xa2705     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xa2705     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xa2705     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xa2705     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xa2705     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xa2705     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xa2705     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 18:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12290      2014-08-14 18:05:04                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 18:05:04                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 18:05:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 18:05:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 18:10:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x282133   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49484       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V2    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 18:10:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2821de   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49484       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 18:10:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2822f9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49578       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 18:10:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2826cb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49484       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 18:10:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x282bcc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49598       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V2    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 18:10:41                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2821de     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-14 18:10:41                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2826cb     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-14 18:10:41                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x282bcc     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-14 18:10:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x286264   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49484       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 18:10:44                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x286264     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-14 18:10:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2822f9     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-14 18:10:57                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 18:10:57                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 18:10:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 18:10:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 18:11:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 18:11:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 18:11:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-14 18:11:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 18:11:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 18:11:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 18:11:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 18:11:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 18:12:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 18:12:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 18:12:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 18:12:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 18:14:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 18:14:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 18:14:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 18:14:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 18:14:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 18:14:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-08-14 18:14:56                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms    : 0x49c      :    : 0xab0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-14 18:14:56                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$.cdf-ms    : 0x448      :    : 0xab0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-14 18:14:56                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms    : 0x4bc      :    : 0xab0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-14 18:14:56                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_compattel_387f970722416aa9.cdf-ms    : 0x508      :    : 0xab0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     :      :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2014-08-14 18:14:56                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\aeinv.dll    : 0x470      :    : 0xab0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-14 18:14:56                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\aepdu.dll    : 0x4c0      :    : 0xab0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-14 18:14:56                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\CompatTel\drvmain32.sdb    : 0x4e0      :    : 0xab0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-14 18:14:56                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\CompatTel\sysmain64runtime.sdb    : 0x3cc      :    : 0xab0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-14 18:14:56                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\CompatTel\drvmain64.sdb    : 0x448      :    : 0xab0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-14 18:14:57                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\CompatTel\aeinv.dll    : 0x508      :    : 0xab0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-14 18:14:57                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\CompatTel\sysmain32.sdb    : 0x4dc      :    : 0xab0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-14 18:14:57                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\CompatTel\sysmain64.sdb    : 0x4c0      :    : 0xab0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-14 18:14:57                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\CompatTel\sysmain32runtime.sdb    : 0x498      :    : 0xab0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-14 18:14:57                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\CompatTel\DevInv.dll    : 0x4e8      :    : 0xab0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-14 18:14:57                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\CompatTel\QueryAppBlock.exe    : 0x478      :    : 0xab0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-08-14 18:14:57                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\CompatTel\wica.dll    : 0x3d4      :    : 0xab0    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe     :     : S:AI     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   12544      2014-08-14 18:15:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 18:15:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-14 18:15:57                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 18:15:57                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 18:16:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 18:16:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 18:17:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 18:17:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 18:17:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 18:17:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 18:20:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x7f7659   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  50627       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V2    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12290      2014-08-14 18:20:57                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 18:20:57                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 18:21:13                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 18:21:13                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 18:23:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 18:23:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-08-14 18:23:25                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x282133     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-14 18:25:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xbccf50   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  50627       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 18:25:53                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xbccf50     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-14 18:25:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xbd0967   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  51053       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 18:26:07                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xbd0967     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-14 18:26:13                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 18:26:13                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 18:31:13                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 18:31:13                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 18:36:13                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 18:36:13                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 18:37:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x122e734   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  50627       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 18:37:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x122e734     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-14 18:37:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x122e89d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  51773       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 18:38:05                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x122e89d     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-14 18:41:13                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 18:41:13                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12545      2014-08-14 18:43:41                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x7f7659     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-14 18:45:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x132246e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49280       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 18:45:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x13225af   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49281       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 18:45:22                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x132246e     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-14 18:45:37                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x13225af     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-14 18:50:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 18:50:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 18:55:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 18:55:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 18:57:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1458219   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49699       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 18:57:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x145854f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49700       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 18:57:23                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1458219     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-14 18:57:34                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x145854f     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-14 19:00:27                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 19:00:27                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 19:05:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 19:05:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 19:09:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x159df9e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  50456       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 19:09:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x159e03d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  50458       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 19:09:24                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x159df9e     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-14 19:09:34                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x159e03d     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-14 19:10:27                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 19:10:27                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 19:11:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 19:11:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-14 19:15:27                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 19:15:27                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 19:20:27                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 19:20:27                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 19:21:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x16ec873   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  51270       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 19:21:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x16ec8e3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  51271       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 19:21:25                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x16ec873     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-14 19:21:41                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x16ec8e3     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-14 19:25:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 19:25:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 19:30:27                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 19:30:27                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 19:31:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 19:31:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 19:31:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 19:31:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 19:33:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x18d1af1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  52163       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 19:33:27                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x18d1af1     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-14 19:33:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x18d1cb2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  52165       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 19:33:38                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x18d1cb2     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-14 19:35:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 19:35:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 19:40:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 19:40:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 19:45:27                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 19:45:27                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 19:45:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1a2890d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  52894       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 19:45:28                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1a2890d     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-14 19:45:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1a28994   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  52895       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 19:45:39                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1a28994     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-14 19:50:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 19:50:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 19:55:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 19:55:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 19:57:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1b948a7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  53795       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 19:57:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1b948e3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  53796       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 19:57:29                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1b948a7     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-14 19:57:45                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1b948e3     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-14 20:00:27                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 20:00:27                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 20:05:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 20:05:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 20:09:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1d0e441   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  54586       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 20:09:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1d0e549   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  54587       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 20:09:31                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1d0e441     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-14 20:09:47                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1d0e549     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-14 20:10:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 20:10:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 20:11:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 20:11:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-14 20:12:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xa2705     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 20:12:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xa2705     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-14 20:15:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 20:15:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 20:20:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 20:20:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 20:21:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2040313   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  55583       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 20:21:32                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2040313     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-14 20:21:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x20404ac   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  55585       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 20:21:48                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x20404ac     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-14 20:25:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 20:25:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 20:30:27                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 20:30:27                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 20:33:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x218ddd0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  56422       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 20:33:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x218e24c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  56424       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 20:33:35                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x218ddd0     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-14 20:33:45                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x218e24c     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-14 20:35:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 20:35:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 20:40:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 20:40:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 20:45:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 20:45:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 20:45:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x22bc714   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  57257       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 20:45:35                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x22bc714     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-14 20:45:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x22bc99f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  57259       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 20:45:51                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x22bc99f     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-14 20:50:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 20:50:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 20:55:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 20:55:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 20:57:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x23d0bba   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  58148       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 20:57:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x23d0c15   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  58150       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 20:57:37                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x23d0bba     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-14 20:57:48                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x23d0c15     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-14 21:00:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 21:00:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 21:05:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 21:05:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 21:12:12                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 21:12:12                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 21:12:42                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 21:12:42                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 21:13:12                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 21:13:12                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 21:13:36                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 21:13:36                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-14 21:14:12                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 21:14:12                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12545      2014-08-14 21:14:17                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0xa2705      ,   .  ,  ,  .        .  
      Audit Success   103        2014-08-14 21:14:30                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-14 21:20:06                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-14 21:20:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-08-14 21:20:06                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xd762  
      Audit Success   12544      2014-08-14 21:20:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 21:20:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 21:20:16                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-14 21:20:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14053   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 21:20:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x1407a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 21:20:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 21:20:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-14 21:20:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-14 21:20:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14053    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-14 21:20:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x1407a    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12548      2014-08-14 21:20:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 21:20:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 21:20:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 21:20:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 21:20:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-14 21:20:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-14 21:20:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 21:20:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 21:20:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 21:20:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 21:20:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-14 21:20:21                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-08-14 21:20:22                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-14 21:20:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3cad6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 21:20:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x304    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-14 21:20:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x5518e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 21:20:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x552c1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 21:20:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-14 21:20:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x54711   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-14 21:20:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x54af4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-14 21:20:49                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x552c1     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-14 21:20:49                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x5518e     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-14 21:20:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x5518e    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-14 21:20:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x54711    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-14 21:20:49                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-14 21:20:49                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-14 21:20:49                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-14 21:20:49                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-14 21:21:01                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 21:21:01                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-14 21:21:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:07                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:07                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:07                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-14 21:21:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 21:21:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 21:21:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12290      2014-08-14 21:22:01                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-14 21:22:01                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-14 21:22:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 21:22:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 21:24:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 21:24:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 21:33:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 21:33:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-08-14 23:03:05                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    : 0x1ef0   :  C:\Program Files\KMSpico\AutoPico.exe     :  2014-08-14T19:03:06.898479600Z   :  2014-08-14T19:03:05.330000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2014-08-14 23:06:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 23:06:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-14 23:08:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 23:08:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 23:08:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 23:08:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 23:08:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 23:08:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 23:09:10                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 23:09:10                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 23:09:10                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 23:09:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-14 23:09:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-14 23:09:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-14 23:18:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 23:18:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-14 23:22:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-14 23:22:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-08-14 23:28:40                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54af4      ,   .  ,  ,  .        .  
      Audit Success   103        2014-08-14 23:29:09                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-15 17:01:53                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-15 17:01:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-15 17:01:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-15 17:01:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 17:01:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-15 17:01:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-08-15 17:01:53                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xf3f4  
      Audit Success   12544      2014-08-15 17:01:54                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-15 17:01:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14756   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-15 17:01:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14785   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 17:01:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14756    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-15 17:01:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14785    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12544      2014-08-15 17:01:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-15 17:01:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-15 17:01:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-15 17:01:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 17:01:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-15 17:01:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-15 17:01:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-15 17:01:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-15 17:01:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-15 17:01:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 17:01:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-15 17:01:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-15 17:01:59                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-08-15 17:02:03                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-15 17:02:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3aabe   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-15 17:02:40                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-15 17:02:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x66731   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-15 17:02:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x667b1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-15 17:02:40                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-15 17:02:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x6654c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-15 17:02:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x66715   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-15 17:02:40                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x667b1     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-15 17:02:40                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66731     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-15 17:02:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x66731    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-15 17:02:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x6654c    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-15 17:02:40                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-15 17:02:40                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-15 17:02:40                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-15 17:02:40                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-15 17:02:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12290      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66715     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66715     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66715     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66715     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66715     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66715     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66715     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66715     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66715     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66715     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66715     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x66715     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:02:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-15 17:02:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 17:02:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:03                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:03                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:03                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:03                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-15 17:03:03                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12544      2014-08-15 17:03:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 17:03:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-15 17:03:49                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-15 17:03:49                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-15 17:06:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 17:06:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-15 17:07:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 17:07:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-15 17:15:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 17:15:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-15 17:29:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 17:29:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-15 17:44:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 17:44:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-15 18:25:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 18:25:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-15 18:25:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 18:25:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-15 19:14:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 19:14:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-15 19:45:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 19:45:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-15 19:48:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 19:48:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-15 19:54:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 19:54:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-15 20:05:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 20:05:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-15 20:14:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 20:14:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-15 20:20:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 20:20:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-15 20:20:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 20:20:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-15 20:21:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-15 20:21:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-08-16 10:27:00                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-16 10:27:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 10:27:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 10:27:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 10:27:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 10:27:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-08-16 10:27:00                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xdc62  
      Audit Success   12544      2014-08-16 10:27:01                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 10:27:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13e54   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 10:27:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13e81   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 10:27:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13e54    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 10:27:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13e81    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12544      2014-08-16 10:27:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 10:27:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 10:27:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 10:27:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 10:27:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 10:27:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 10:27:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 10:27:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 10:27:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 10:27:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 10:27:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 10:27:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 10:27:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 10:27:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-16 10:27:13                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-08-16 10:27:16                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-16 10:27:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3e884   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12290      2014-08-16 10:28:15                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 10:28:15                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-16 10:28:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 10:28:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-16 10:28:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:28:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:28:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:28:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:28:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:28:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:28:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:28:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-16 10:29:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 10:29:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-16 10:29:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 10:29:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-16 10:33:16                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 10:33:16                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-16 10:37:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 10:37:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 10:37:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 10:37:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-16 10:38:16                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 10:38:16                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-16 10:38:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 10:38:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 10:41:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 10:41:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-16 10:43:16                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 10:43:16                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-16 10:43:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 10:43:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 10:43:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 10:43:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x310    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x6883f1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x310    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x6884a5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x310    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x6882b1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x6883cd   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6884a5     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883f1     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x6883f1    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x6882b1    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:35                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:40                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:45                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:45                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:45                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:45:53                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12544      2014-08-16 10:47:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 10:47:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-16 10:48:16                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 10:48:16                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-16 10:53:16                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 10:53:16                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-16 10:53:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x3a0    :  C:\Windows\System32\svchost.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x925bc8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x3a0    :  C:\Windows\System32\svchost.exe      :     : BLACK_SOKO     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x925d08   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x3a0    :  C:\Windows\System32\svchost.exe      :     : BLACK_SOKO     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x925d08     :   2          .           " ".      ,       .  
      Audit Success   12545      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x925bc8     :   2          .           " ".      ,       .  
      Audit Success   12548      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x925bc8    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:07                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:07                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:07                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:07                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:07                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:07                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:07                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:07                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:07                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 10:54:07                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-16 10:58:17                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 10:58:17                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-16 10:58:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 10:58:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-16 11:03:16                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 11:03:16                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-16 11:35:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 11:35:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 11:35:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 11:35:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 11:35:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 11:35:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 11:35:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 11:35:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 11:58:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 11:58:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-08-16 11:59:07                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    : 0xccc   :  C:\Program Files\KMSpico\AutoPico.exe     :  2014-08-16T07:59:05.770752700Z   :  2014-08-16T07:59:07.000000000Z          .    Windows,    ,    .           .  
      Audit Success   13824      2014-08-16 12:06:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:06:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:06:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:06:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:06:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:06:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:06:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:06:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:06:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-16 12:07:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 12:07:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 12:12:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:12:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:12:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:12:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:12:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:12:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:12:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:12:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:12:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:12:51                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:12:51                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:12:51                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:12:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:12:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:12:59                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:13:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:13:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:13:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:13:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:13:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:13:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-16 12:22:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 12:22:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 12:22:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 12:22:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 12:22:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 12:22:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 12:22:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 12:22:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 12:24:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:24:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:24:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:27:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:27:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:27:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:28:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:28:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:28:00                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:28:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:28:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:28:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-16 12:30:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 12:30:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 12:30:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:30:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:30:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:30:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:30:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:30:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:30:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:30:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:30:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:30:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:30:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:30:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:30:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:30:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:30:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:36:30                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:36:30                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:36:30                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:36:35                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:36:35                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:36:35                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:36:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:36:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:36:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:36:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:36:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:36:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:24                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:24                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:24                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:30                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:30                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:30                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:30                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:30                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:30                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:37:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-16 12:39:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 12:39:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 12:42:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:42:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:42:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:42:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:42:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:42:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-16 12:47:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 12:47:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-08-16 12:47:43                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x6883cd      ,   .  ,  ,  .        .  
      Audit Success   103        2014-08-16 12:47:55                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-16 12:53:57                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-16 12:53:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 12:53:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 12:53:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-08-16 12:53:57                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xedb4  
      Audit Success   12544      2014-08-16 12:53:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 12:53:58                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2cc    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 12:53:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14c14   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2cc    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 12:53:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14c44   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2cc    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 12:53:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 12:53:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 12:53:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 12:53:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 12:53:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14c14    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 12:53:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14c44    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12548      2014-08-16 12:53:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 12:53:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 12:53:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 12:53:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 12:53:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 12:54:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 12:54:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 12:54:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 12:54:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-16 12:54:01                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-08-16 12:54:01                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-16 12:54:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3c14e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12290      2014-08-16 12:54:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 12:54:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-16 12:54:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:54:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:54:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:54:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:54:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:54:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:54:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:54:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-16 12:55:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 12:55:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x300    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x77e7f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x77f2f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2cc    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x77dd0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2cc    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x77e94   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2cc    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77f2f     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e7f     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x77e7f    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x77dd0    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-16 12:56:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 12:56:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 12:56:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12544      2014-08-16 13:03:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 13:03:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 13:06:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 13:06:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 13:11:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 13:11:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 13:13:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 13:13:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 13:14:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 13:14:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 13:17:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 13:17:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 13:26:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 13:26:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 13:28:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 13:28:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 13:36:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 13:36:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 13:38:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 13:38:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 13:41:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 13:41:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 13:43:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 13:43:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 13:52:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 13:52:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 13:53:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 13:53:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 13:59:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 13:59:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 14:05:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 14:05:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 14:14:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 14:14:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 14:15:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 14:15:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 14:16:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 14:16:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 14:16:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 14:16:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-08-16 14:17:46                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7    :    : 0xe3c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x53a7b5d  
      Audit Success   13568      2014-08-16 14:17:46                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7    :    : 0xe3c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x53a7b5d  
      Audit Success   13568      2014-08-16 14:18:39                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7    :    : 0xe3c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x5514755  
      Audit Success   13568      2014-08-16 14:18:39                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7    :    : 0xe3c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x5514755  
      Audit Success   12544      2014-08-16 14:18:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 14:18:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 16:31:06                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 16:31:06                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 16:31:09                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   12544      2014-08-16 16:31:12                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x300    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 16:31:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x61d33bc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 16:31:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x61f3b68   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 16:31:12                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2cc    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 16:31:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x61b1028   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2cc    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 16:31:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x61e3e13   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2cc    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-16 16:31:12                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x61f3b68     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-16 16:31:12                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x61e3e13     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-16 16:31:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x61d33bc    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 16:31:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x61b1028    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 16:31:12                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 16:31:12                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12545      2014-08-16 16:31:13                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x61d33bc     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-16 16:31:13                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x61b1028     :   7          .           " ".      ,       .  
      Audit Success   13824      2014-08-16 16:31:14                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:14                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:14                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:14                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:15                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:15                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:15                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:15                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:15                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:31:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-16 16:32:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 16:32:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 16:47:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 16:47:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 16:53:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 16:53:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 16:55:21                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:55:21                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:55:21                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:55:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:55:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:55:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:55:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:55:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:55:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x77e94     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 16:56:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12288      2014-08-16 20:47:35                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-16 20:47:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-08-16 20:47:35                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xe61c  
      Audit Success   12544      2014-08-16 20:47:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 20:47:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 20:47:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 20:47:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 20:47:39                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 20:47:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x150b6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 20:47:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x150e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 20:47:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 20:47:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x150b6    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 20:47:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x150e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12548      2014-08-16 20:47:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 20:47:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 20:47:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 20:47:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 20:47:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2014-08-16 20:47:42                                  Microsoft-Windows-Eventlog      1101: 
      Audit Success   12544      2014-08-16 20:47:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 20:47:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 20:47:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 20:47:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 20:47:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 20:47:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-16 20:47:48                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-08-16 20:47:51                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-16 20:48:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x43d5c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13824      2014-08-16 20:48:11                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   12544      2014-08-16 20:48:12                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 20:48:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4c874   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 20:48:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4c90d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 20:48:12                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 20:48:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4a1ef   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 20:48:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4c6a7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-16 20:48:12                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4c90d     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-16 20:48:12                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4c874     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-16 20:48:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4c874    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 20:48:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4a1ef    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 20:48:12                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 20:48:12                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 20:48:12                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   12544      2014-08-16 20:48:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 20:48:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 20:48:33                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4c6a7     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:33                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4c6a7     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:33                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4c6a7     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:33                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4c6a7     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:33                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4c6a7     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:33                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4c6a7     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4c6a7     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4c6a7     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:34                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4c6a7     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-16 20:48:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 20:48:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 20:48:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:48:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12290      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4c6a7     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4c6a7     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 20:49:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4c6a7     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-16 20:50:02                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 20:50:02                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12545      2014-08-16 20:50:38                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4c6a7      ,   .  ,  ,  .        .  
      Audit Success   12544      2014-08-16 20:50:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 20:50:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2014-08-16 20:50:49                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-16 21:12:00                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-16 21:12:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 21:12:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 21:12:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 21:12:00                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 21:12:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13cb0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 21:12:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13cd7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 21:12:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 21:12:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 21:12:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13cb0    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 21:12:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13cd7    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   13568      2014-08-16 21:12:00                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xd9fa  
      Audit Success   12544      2014-08-16 21:12:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 21:12:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 21:12:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 21:12:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 21:12:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 21:12:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 21:12:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 21:12:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 21:12:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 21:12:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 21:12:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 21:12:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-16 21:12:14                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-08-16 21:12:15                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-16 21:12:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3d3ef   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 21:12:37                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x308    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 21:12:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x44465   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 21:12:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4455b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 21:12:37                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 21:12:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x43ee5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 21:12:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x44471   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-16 21:12:37                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4455b     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-16 21:12:37                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44465     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-16 21:12:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x44465    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 21:12:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x43ee5    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 21:12:37                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 21:12:37                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 21:12:37                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 21:12:37                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 21:12:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-16 21:12:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 21:12:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-16 21:12:55                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 21:12:55                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-16 21:12:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:12:55                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12290      2014-08-16 21:13:56                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 21:13:56                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-16 21:15:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 21:15:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 21:15:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 21:15:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 21:16:24                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:16:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:19:11                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:19:11                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:19:11                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:19:11                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:19:11                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:19:11                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-16 21:19:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 21:19:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 21:19:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:19:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:19:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:19:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:19:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:19:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:20:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:20:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:20:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:20:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:20:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:20:06                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-16 21:24:33                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 21:24:33                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-16 21:25:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 21:25:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 21:33:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:33:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:33:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:33:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:33:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:33:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:34:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:34:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:34:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:34:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:34:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:34:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:34:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:34:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:34:49                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:34:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:34:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:34:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-16 21:36:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 21:36:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 21:40:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:10                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:10                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:10                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:14                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:14                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:14                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:18                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:18                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:18                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:18                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:18                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:18                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:22                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:23                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:24                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:24                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:40:24                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:44:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:44:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 21:44:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-16 22:29:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 22:29:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 22:33:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 22:33:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-16 22:47:04                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-16 22:47:04                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-16 22:47:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 22:47:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 22:50:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 22:50:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-08-16 22:52:53                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x44471      ,   .  ,  ,  .        .  
      Audit Success   103        2014-08-16 22:52:58                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-16 22:53:53                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-16 22:53:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-08-16 22:53:53                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xe48a  
      Audit Success   12544      2014-08-16 22:53:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 22:53:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 22:53:54                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 22:53:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x142f2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 22:53:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14318   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 22:53:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 22:53:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 22:53:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 22:53:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 22:53:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x142f2    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 22:53:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14318    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12548      2014-08-16 22:53:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 22:53:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 22:53:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 22:53:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 22:53:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 22:53:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-16 22:53:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 22:53:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 22:53:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 22:53:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-16 22:53:57                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-08-16 22:53:57                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-16 22:54:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x365d8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 22:54:10                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x314    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 22:54:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x3ed32   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x314    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 22:54:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x3edd9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x314    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 22:54:10                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-16 22:54:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x3ebb4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-16 22:54:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x3ed3d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-16 22:54:10                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3edd9     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-16 22:54:10                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed32     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-16 22:54:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x3ed32    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-16 22:54:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x3ebb4    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 22:54:10                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 22:54:10                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 22:54:10                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 22:54:10                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-16 22:54:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 22:54:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 22:54:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 22:54:18                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 22:54:18                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 22:54:18                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 22:54:18                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 22:54:18                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 22:54:18                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-16 22:54:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 22:54:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-16 22:56:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 22:56:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 22:56:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 22:56:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 22:56:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 22:56:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 22:56:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-16 22:56:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-16 22:56:27                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-16 23:07:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-16 23:07:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-08-16 23:10:42                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ed3d      ,   .  ,  ,  .        .  
      Audit Success   103        2014-08-16 23:10:45                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-17 00:45:30                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-17 00:45:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 00:45:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 00:45:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-08-17 00:45:30                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xefe7  
      Audit Success   12544      2014-08-17 00:45:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 00:45:31                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d4    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 00:45:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x15316   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d4    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 00:45:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x15353   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d4    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 00:45:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 00:45:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x15316    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 00:45:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x15353    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12544      2014-08-17 00:45:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 00:45:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 00:45:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 00:45:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 00:45:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 00:45:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 00:45:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 00:45:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 00:45:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 00:45:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 00:45:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 00:45:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-17 00:45:46                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-08-17 00:45:47                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-17 00:46:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3fd14   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13824      2014-08-17 00:46:05                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 00:46:05                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 00:46:05                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 00:46:05                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   12544      2014-08-17 00:46:06                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2fc    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 00:46:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x43106   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2fc    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 00:46:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x431b2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2fc    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 00:46:06                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 00:46:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x43066   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d4    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 00:46:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4311d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d4    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 00:46:06                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x431b2     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 00:46:06                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x43106     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-17 00:46:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x43106    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 00:46:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x43066    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 00:46:15                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4311d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:46:15                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4311d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:46:15                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4311d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-17 00:46:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 00:46:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 00:46:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4311d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:46:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4311d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:46:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4311d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:46:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4311d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:46:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4311d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:46:17                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4311d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:10                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:10                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:10                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:10                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:10                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12290      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4311d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4311d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 00:47:46                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4311d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-17 00:47:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 00:47:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 00:48:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 00:48:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-17 00:48:47                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 00:48:47                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 00:57:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 00:57:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 00:57:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 00:57:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 00:57:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 00:57:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 00:57:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 00:57:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-08-17 01:01:56                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7    :    : 0x1e3c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x78725f  
      Audit Success   13568      2014-08-17 01:01:56                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7    :    : 0x1e3c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x78725f  
      Audit Success   12544      2014-08-17 01:05:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 01:05:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 01:13:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 01:13:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 01:38:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 01:38:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 01:40:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 01:40:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 01:41:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 01:41:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 01:41:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 01:41:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 01:41:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 01:41:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 01:50:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 01:50:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 02:02:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 02:02:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 02:08:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 02:08:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 02:09:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 02:09:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 02:17:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 02:17:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 02:19:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 02:19:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 02:20:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 02:20:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 02:38:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 02:38:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 02:51:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 02:51:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 02:59:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 02:59:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 03:02:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 03:02:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 03:02:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 03:02:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 03:03:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 03:03:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 03:11:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 03:11:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 03:21:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 03:21:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 03:25:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 03:25:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 03:27:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 03:27:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 03:33:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 03:33:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 03:36:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 03:36:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 03:39:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 03:39:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 03:42:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 03:42:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 03:45:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 03:45:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 03:49:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 03:49:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 03:52:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 03:52:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 03:56:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 03:56:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 04:01:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 04:01:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 04:04:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 04:04:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 04:10:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 04:10:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 04:14:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 04:14:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 04:17:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 04:17:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 04:22:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 04:22:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 04:27:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 04:27:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 04:30:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 04:30:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 04:32:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 04:32:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 04:35:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 04:35:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 04:48:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 04:48:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 04:51:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 04:51:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 05:48:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 05:48:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 07:58:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 07:58:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 08:04:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:04:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 08:08:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:08:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 08:13:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:13:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-08-17 08:18:57                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4311d      ,   .  ,  ,  .        .  
      Audit Success   103        2014-08-17 08:19:10                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-17 08:20:15                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-17 08:20:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-08-17 08:20:15                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xe3a3  
      Audit Success   12544      2014-08-17 08:20:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x310    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:20:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x310    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:20:18                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2e8    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 08:20:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14d0e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:20:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14d35   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:20:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:20:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:20:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14d0e    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:20:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14d35    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12544      2014-08-17 08:20:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x310    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:20:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x310    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:20:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x310    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:20:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x310    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:20:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:20:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:20:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:20:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 08:20:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x310    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:20:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x310    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:20:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:20:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-17 08:20:22                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-08-17 08:20:24                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-17 08:20:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x44a7a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   103        2014-08-17 08:20:50                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-17 08:22:59                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-17 08:22:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:22:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:22:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:22:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:22:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-08-17 08:22:59                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xde7e  
      Audit Success   12544      2014-08-17 08:23:00                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 08:23:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13f18   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:23:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13f4b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:23:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13f18    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:23:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13f4b    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12544      2014-08-17 08:23:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:23:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 08:23:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:23:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:23:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:23:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 08:23:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:23:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 08:23:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:23:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:23:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:23:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-17 08:23:16                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-08-17 08:23:21                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-17 08:23:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x47ace   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:24:09                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x308    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 08:24:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4f424   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:24:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4f4ae   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x308    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:24:09                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 08:24:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4f2c8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:24:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4f40c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 08:24:09                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f4ae     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 08:24:09                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f424     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-17 08:24:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4f424    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:24:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4f2c8    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 08:24:09                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 08:24:09                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 08:24:09                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 08:24:09                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 08:24:19                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f40c     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:19                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f40c     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:19                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f40c     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:19                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f40c     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:19                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f40c     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:19                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f40c     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:19                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f40c     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:19                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f40c     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:19                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f40c     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-17 08:24:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:24:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 08:24:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:25                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:26                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:26                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:26                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:26                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:26                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:26                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:26                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:26                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:26                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:26                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:26                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:26                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:26                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:26                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:26                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12290      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f40c     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f40c     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:24:31                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f40c     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-17 08:24:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:24:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-17 08:25:32                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 08:25:32                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 08:26:31                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 08:26:31                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 08:26:33                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 08:26:33                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-17 08:26:33                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f40c     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:26:33                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f40c     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:26:33                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f40c     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-17 08:26:36                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 08:26:36                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 08:30:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:30:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 08:32:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:32:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 08:37:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:37:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 08:39:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:39:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-08-17 08:42:26                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f40c      ,   .  ,  ,  .        .  
      Audit Success   103        2014-08-17 08:42:37                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-17 08:43:34                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-17 08:43:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:43:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:43:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:43:34                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 08:43:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x143dd   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:43:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x143f8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:43:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:43:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:43:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x143dd    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:43:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x143f8    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   13568      2014-08-17 08:43:34                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xe545  
      Audit Success   12544      2014-08-17 08:43:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:43:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:43:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:43:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:43:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:43:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 08:43:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:43:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-17 08:43:37                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-08-17 08:43:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:43:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:43:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 08:43:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-17 08:43:38                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-17 08:43:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x42222   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:44:04                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 08:44:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x54e5f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:44:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x54f2d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:44:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x54e5f    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 08:44:04                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 08:44:04                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 08:44:04                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   12544      2014-08-17 08:44:05                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 08:44:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x54f2f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 08:44:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x55b30   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 08:44:05                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x55b30     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 08:44:05                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54f2f     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-17 08:44:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x54f2f    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 08:44:05                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 08:44:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:11                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54f2d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:11                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54f2d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:11                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54f2d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:12                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54f2d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:12                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54f2d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:12                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54f2d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:12                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54f2d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:12                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54f2d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:12                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54f2d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-17 08:44:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:44:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 08:44:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:16                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12290      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54f2d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54f2d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54f2d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 08:44:20                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-17 08:45:21                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 08:45:21                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 08:45:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:45:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 08:57:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:57:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 08:57:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:57:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 08:57:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:57:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 08:57:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 08:57:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 09:02:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 09:02:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 09:20:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x9dff21   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49661       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 09:20:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x9dffac   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49663       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 09:20:30                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x9dff21     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 09:20:41                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x9dffac     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-17 09:25:22                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 09:25:22                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 09:30:21                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 09:30:21                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 09:32:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xbf057b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49910       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 09:32:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xbf0760   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49911       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 09:32:30                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xbf057b     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 09:32:41                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xbf0760     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 09:33:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 09:33:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 09:33:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 09:33:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 09:34:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 09:34:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-17 09:35:23                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 09:35:23                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 09:38:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 09:38:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 09:38:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 09:38:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 09:38:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 09:38:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 09:39:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x300    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 09:39:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-17 09:40:22                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 09:40:22                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 09:44:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xf75c62   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  50085       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 09:44:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xf760e9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  50090       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 09:44:32                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xf75c62     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 09:44:48                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xf760e9     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-17 09:45:22                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 09:45:22                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-17 09:45:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54f2d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 09:45:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54f2d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-17 09:50:21                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 09:50:21                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 09:52:36                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 09:52:36                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 09:53:06                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 09:53:06                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 09:53:36                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 09:53:36                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 09:53:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x118e8e1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49309       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 09:53:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x118e927   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49310       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 09:53:44                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x118e8e1     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 09:53:58                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x118e927     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-17 09:58:50                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 09:58:50                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 09:58:55                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 09:58:55                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12545      2014-08-17 10:00:47                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x54f2d      ,   .  ,  ,  .        .  
      Audit Success   103        2014-08-17 10:00:50                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-17 10:33:49                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-17 10:33:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 10:33:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 10:33:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 10:33:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 10:33:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13d5d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 10:33:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13d82   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 10:33:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 10:33:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 10:33:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13d5d    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 10:33:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13d82    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   13568      2014-08-17 10:33:49                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xde81  
      Audit Success   12544      2014-08-17 10:33:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 10:33:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 10:33:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 10:33:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 10:33:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 10:33:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 10:33:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 10:33:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 10:34:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 10:34:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 10:34:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 10:34:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-17 10:34:02                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-08-17 10:34:02                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-17 10:34:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x42512   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 10:34:27                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 10:34:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x45258   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 10:34:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x45367   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x30c    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 10:34:27                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 10:34:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x44eeb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 10:34:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x45243   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 10:34:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x45258    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 10:34:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x44eeb    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 10:34:27                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 10:34:27                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 10:34:27                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 10:34:27                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   12545      2014-08-17 10:34:28                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x45367     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 10:34:28                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x45258     :   7          .           " ".      ,       .  
      Audit Success   13824      2014-08-17 10:34:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x45243     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x45243     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x45243     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x45243     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x45243     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x45243     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x45243     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x45243     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x45243     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-17 10:34:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 10:34:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12290      2014-08-17 10:34:44                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 10:34:44                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x45243     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x45243     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 10:34:48                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x45243     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-17 10:35:48                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 10:35:48                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 10:35:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 10:35:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 10:36:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 10:36:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-17 10:39:45                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 10:39:45                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 10:44:45                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 10:44:45                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 10:47:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 10:47:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-17 10:49:45                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 10:49:45                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 10:54:45                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 10:54:45                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 10:59:45                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 10:59:45                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 11:01:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 11:01:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 11:01:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 11:01:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-17 11:04:45                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 11:04:45                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 11:09:45                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 11:09:45                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 11:14:45                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 11:14:45                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 11:19:45                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 11:19:45                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 11:24:45                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 11:24:45                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12545      2014-08-17 11:25:58                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x45243      ,   .  ,  ,  .        .  
      Audit Success   103        2014-08-17 11:26:09                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-17 13:51:55                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-17 13:51:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 13:51:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 13:51:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 13:51:55                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 13:51:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x143f7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 13:51:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14425   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 13:51:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 13:51:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 13:51:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x143f7    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 13:51:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x14425    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   13568      2014-08-17 13:51:55                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xe506  
      Audit Success   12544      2014-08-17 13:51:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 13:51:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 13:51:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 13:51:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 13:51:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 13:51:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 13:51:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 13:51:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 13:51:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 13:51:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-17 13:51:58                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-08-17 13:51:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 13:51:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-17 13:51:59                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-17 13:52:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x36916   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 13:52:27                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x314    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 13:52:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4f35a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x314    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 13:52:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4f3fd   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x314    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 13:52:27                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 13:52:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4f2b2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 13:52:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4f35d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 13:52:27                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f3fd     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 13:52:27                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f35a     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-17 13:52:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4f35a    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 13:52:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x4f2b2    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 13:52:27                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 13:52:27                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 13:52:27                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 13:52:27                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 13:52:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f35d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f35d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:36                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f35d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f35d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f35d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f35d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f35d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f35d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f35d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-17 13:52:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 13:52:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:44                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12290      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f35d     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f35d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 13:52:47                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f35d     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-17 13:53:47                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 13:53:47                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 13:53:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 13:53:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 13:54:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 13:54:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 14:05:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 14:05:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 14:10:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 14:10:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 14:16:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 14:16:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 14:16:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 14:16:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 14:18:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 14:18:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 14:19:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 14:19:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 15:33:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xe4449a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49703       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:33:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xe4449a     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 15:33:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xe4479f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49709       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:34:12                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xe4479f     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 15:39:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xebeb57   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49336       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:39:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xebed0e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49345       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:39:44                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xebeb57     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:39:55                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xebed0e     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-17 15:40:06                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 15:40:06                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 15:40:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xed5e6c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49477       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:40:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xed5edf   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49482       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:40:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xed5e6c     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 15:41:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0xed7b0e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49482       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V2    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:41:08                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xed5edf     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:41:24                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0xed7b0e     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 15:41:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0xeebc77   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V2    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:41:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0xeed9be   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49507       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V2    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:41:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0xeed9be     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-17 15:45:06                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 15:45:06                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 15:45:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfab73a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfac007   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49552       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfac022   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:45:40                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfab73a     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:40                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfac022     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:52                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfac007     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 15:45:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb2594   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb25ab   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb25c2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb25da   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb25f1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:45:55                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb2594     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:55                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb25ab     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:55                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb25c2     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:55                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb25da     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:55                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb25f1     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 15:45:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb34dd   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb34f4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb350b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3523   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb353a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb35cd   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb35fc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3617   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb363a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:45:56                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb34dd     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:56                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb34f4     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:56                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb350b     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:56                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3523     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:56                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb353a     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:56                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb35cd     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:56                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb35fc     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:56                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3617     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3651   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3668   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb373f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3806   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3889   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb38a2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb38ba   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb38d1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb38e8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3907   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3923   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb393a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3951   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb363a     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3651     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3668     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb373f     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3806     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3889     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb38a2     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb38ba     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb38d1     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb38e8     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3907     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3923     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb393a     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3951     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 15:45:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3e42   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3e59   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3e70   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3e88   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:45:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3e9f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:45:58                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3e42     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:58                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3e59     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:58                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3e70     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:58                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3e88     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:45:58                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb3e9f     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 15:46:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb681c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:46:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb683f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:46:04                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb681c     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:46:04                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb683f     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 15:46:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb6856   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:46:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb6871   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:46:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb6888   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:46:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb689f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:46:05                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb6856     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:46:05                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb6871     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:46:05                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb6888     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:46:05                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfb689f     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfbbebe   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfbbed5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfbbeec   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfbbf03   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfbbf1b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfbbf32   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfbbf49   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfbbf60   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0xfbbf76   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : fe80::f969:615:75d5:dabb    :  49503       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V2    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0xfbc045   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49507       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V2    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfbbebe     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfbbed5     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfbbeec     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfbbf03     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfbbf1b     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfbbf32     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfbbf49     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfbbf60     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:46:22                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0xfbc045     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-17 15:50:06                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 15:50:06                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 15:51:27                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 15:51:27                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 15:51:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 15:51:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 15:52:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x1040922   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  50007       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V2    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:52:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1041d03   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  50007       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:52:39                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1041d03     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 15:52:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1042f3a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  50007       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:52:44                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1042f3a     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 15:52:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x104310c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  50021       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:52:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1043127   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  50007       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:52:45                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1043127     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:52:48                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0xeebc77     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:52:58                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x104310c     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 15:54:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1060b98   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  50007       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:54:49                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1060b98     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 15:54:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1061619   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  50178       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 15:54:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1061634   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  50007       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 15:54:50                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1061634     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:55:01                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1061619     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:55:21                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0xfbbf76     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 15:56:16                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x1040922     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-17 15:56:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 15:56:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 16:00:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 16:00:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-17 16:04:02                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 16:04:02                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 16:04:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x12d9c48   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49406       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:04:42                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x12d9c48     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 16:04:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x12de7e6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49407       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:04:58                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x12de7e6     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-17 16:09:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 16:09:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 16:10:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x13f7c43   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49451       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:10:31                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x13f7c43     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 16:10:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x13f7ee6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49454       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:10:47                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x13f7ee6     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-17 16:14:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 16:14:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 16:15:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x1468553   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49796       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V2    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:15:48                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x1468553     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 16:15:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x146db57   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V2    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ef0b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ef23   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ef52   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ef69   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ef82   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146eff5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f05e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f0e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f107   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f11e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f135   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f14c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f163   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f17a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f191   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f1a8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f1c0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f1d7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f1ee   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f205   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f21c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f233   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f24a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f261   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ef0b     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ef23     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ef52     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ef69     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ef82     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146eff5     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f05e     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f0e5     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f107     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f11e     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f135     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f14c     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f163     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f17a     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f191     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f1a8     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f1c0     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f1d7     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f1ee     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f205     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f21c     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f233     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:54                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f24a     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 16:15:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f278   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:15:55                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f261     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:55                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146f278     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146fdff   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146fe16   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146fec1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146fed8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146fef5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ff1d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ff34   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ff4c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ff7b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ffed   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146fdff     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146fe16     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146fec1     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146fed8     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146fef5     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ff1d     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ff34     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ff4c     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ff7b     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:57                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x146ffed     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147202d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147204c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472064   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147207b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14720ea   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472126   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147213d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147216e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14721c9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14721fe   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472215   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147222c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147224f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147226c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14722a3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472313   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147232a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472341   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472358   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14723b4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14723fc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472417   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147242e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147202d     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147204c     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472064     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147207b     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14720ea     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472126     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147213d     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147216e     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14721c9     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14721fe     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472215     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147222c     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147224f     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147226c     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14722a3     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472313     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147232a     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472341     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472358     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14723b4     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14723fc     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472417     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:15:59                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147242e     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472551   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472568   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14725b2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147260b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472634   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147264b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14726b1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14726f2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472715   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147272c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472743   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147275a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472551     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472568     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14725b2     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147260b     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472634     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147264b     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14726b1     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14726f2     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472715     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147272c     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1472743     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:00                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147275a     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473841   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473858   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147386f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147388d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14738b5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14738cc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14738e3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14738fa   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473a00   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473aa3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473e5a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473e7e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473e99   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473f45   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473f68   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473f81   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473fa2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473fc9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473fe0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473ff9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1474020   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1474043   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147405f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1474086   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147409e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14740b5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14740dc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14740f3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147410a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473841     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473858     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147386f     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147388d     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14738b5     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14738cc     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14738e3     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14738fa     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473a00     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473aa3     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473e5a     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473e7e     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473e99     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473f45     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473f68     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473f81     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473fa2     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473fc9     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473fe0     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1473ff9     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1474020     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1474043     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147405f     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1474086     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147409e     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14740b5     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14740dc     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:02                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14740f3     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 16:16:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14741e8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1474307   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14743ef   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147446f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147451f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 16:16:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14745d6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  49818       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:16:03                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147410a     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:03                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14741e8     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:03                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1474307     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:03                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14743ef     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:03                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147446f     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:03                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x147451f     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 16:16:03                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x14745d6     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-17 16:19:04                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 16:19:04                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 16:24:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 16:24:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 16:29:02                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 16:29:02                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12545      2014-08-17 16:31:47                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1006     :  HomeGroupUser$     :  Black_SOKOL    :  0x146db57     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-17 16:34:04                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 16:34:04                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 16:35:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1603f6e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  50922       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:35:18                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1603f6e     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 16:35:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x160419a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  50924       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:35:34                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x160419a     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-17 16:39:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 16:39:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 16:44:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 16:44:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 16:49:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 16:49:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 16:49:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x172866d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  51922       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:49:32                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x172866d     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 16:49:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x172930c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  51925       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:49:48                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x172930c     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 16:53:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x178c986   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  52377       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:53:32                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x178c986     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-08-17 16:53:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x178d031   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : KOLJAB-PC     : 192.168.1.144    :  52378       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 16:53:48                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x178d031     :   3          .           " ".      ,       .  
      Audit Success   12290      2014-08-17 16:54:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 16:54:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 16:59:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 16:59:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:04:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:04:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:09:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:09:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:14:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:14:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:19:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:19:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:24:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:24:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:29:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:29:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12288      2014-08-17 17:29:07                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    : 0x191c   :  C:\Program Files\KMSpico\AutoPico.exe     :  2014-08-17T13:29:08.122326000Z   :  2014-08-17T13:29:07.047000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2014-08-17 17:30:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 17:30:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 17:31:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 17:31:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-17 17:34:01                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:34:01                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 17:37:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 17:37:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-17 17:38:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:38:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:39:07                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:39:07                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:39:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:39:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:40:07                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:40:07                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:40:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:40:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 17:40:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 17:40:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-17 17:41:07                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:41:07                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:41:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:41:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:42:07                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:42:07                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:42:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:42:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:43:07                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:43:07                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:43:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:43:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:44:07                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:44:07                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:44:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:44:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:45:07                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:45:07                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:45:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:45:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:46:07                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:46:07                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:46:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:46:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:47:07                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:47:07                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:47:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:47:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:48:07                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:48:07                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:48:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:48:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12290      2014-08-17 17:49:07                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 17:49:07                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d4695536-1559-4344-94b0-582a25cff1a3    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b52803bf697a031db2805e208b6512c5_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 17:54:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 17:54:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 17:55:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 17:55:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 18:03:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 18:03:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 18:14:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 18:14:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 18:19:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 18:19:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 18:43:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 18:43:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 18:45:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 18:45:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-08-17 18:57:45                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x4f35d      ,   .  ,  ,  .        .  
      Audit Success   103        2014-08-17 18:57:58                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-17 18:58:54                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-17 18:58:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 18:58:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 18:58:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 18:58:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 18:58:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-08-17 18:58:54                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xeae9  
      Audit Success   12544      2014-08-17 18:58:55                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 18:58:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13ea9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 18:58:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13ecf   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 18:58:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13ea9    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 18:58:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x13ecf    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12544      2014-08-17 18:58:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 18:58:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 18:58:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 18:58:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 18:58:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 18:58:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 18:58:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 18:58:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 18:59:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 18:59:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 18:59:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 18:59:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-17 18:59:03                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-08-17 18:59:05                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-17 18:59:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3f092   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 18:59:35                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x310    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 18:59:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x42e0a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x310    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 18:59:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x42ef7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x310    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 18:59:35                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 18:59:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x42be8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 18:59:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x42e2e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 18:59:35                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42ef7     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 18:59:35                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e0a     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-17 18:59:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x42e0a    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 18:59:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x42be8    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 18:59:35                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 18:59:35                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 18:59:35                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 18:59:35                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 18:59:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:50                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:51                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:51                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:51                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-17 18:59:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 18:59:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 18:59:56                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 19:00:02                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12544      2014-08-17 19:00:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 19:00:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-08-17 19:00:58                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 19:00:58                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 19:05:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 19:05:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 19:06:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 19:06:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 19:06:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 19:06:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-08-17 19:06:58                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7    :    : 0x1a94    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x3527d9  
      Audit Success   13568      2014-08-17 19:06:58                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7    :    : 0x1a94    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x3527d9  
      Audit Success   12544      2014-08-17 19:12:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 19:12:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 20:07:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 20:07:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 21:21:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 21:21:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 21:38:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 21:38:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 21:49:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 21:49:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 21:49:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 21:49:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 22:04:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 22:04:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 22:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:04:08                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:04:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:04:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:04:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-17 22:21:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 22:21:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 22:25:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:09                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:10                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:10                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:11                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:11                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:11                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:37                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:25:39                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12544      2014-08-17 22:26:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 22:26:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 22:39:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 22:39:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:50:43                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12544      2014-08-17 22:50:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 22:50:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 22:56:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x304    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 22:56:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-08-17 22:57:56                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x42e2e      ,   .  ,  ,  .        .  
      Audit Success   103        2014-08-17 22:58:05                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2014-08-17 22:59:36                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-08-17 22:59:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-08-17 22:59:36                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xecd2  
      Audit Success   12544      2014-08-17 22:59:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x314    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 22:59:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x314    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 22:59:38                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2e8    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 22:59:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x156bc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 22:59:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   2     :  %%1833     :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x156e2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e8    :  C:\Windows\System32\winlogon.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 22:59:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 22:59:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 22:59:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x156bc    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 22:59:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-1     :  DWM-1     :  Window Manager    :  0x156e2    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12544      2014-08-17 22:59:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x314    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 22:59:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x314    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 22:59:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x314    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 22:59:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 22:59:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 22:59:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 22:59:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x314    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 22:59:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x314    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 22:59:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 22:59:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-17 22:59:41                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-08-17 22:59:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x314    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 22:59:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-08-17 22:59:42                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-08-17 22:59:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :  %%1833     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x30bb8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 22:59:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x320    :  C:\Windows\System32\lsass.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 22:59:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x3ecf2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x320    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 22:59:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   7     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x3edb1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x320    :  C:\Windows\System32\lsass.exe      :     : BLACK_SOKO     : -    :  -       :    :  Negotiat     : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 22:59:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  nicksab1491@mail.ru     :  MicrosoftAccount   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2e8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-08-17 22:59:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x3ec46   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-08-17 22:59:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   11     :  %%1833     :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x3ecf3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e8    :  C:\Windows\System32\winlogon.exe      :     : BLACK_SOKO     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-08-17 22:59:49                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3edb1     :   7          .           " ".      ,       .  
      Audit Success   12545      2014-08-17 22:59:49                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf2     :   7          .           " ".      ,       .  
      Audit Success   12548      2014-08-17 22:59:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x3ecf2    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-08-17 22:59:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  nicksab1491@mail.ru     :  MicrosoftAccount    :  0x3ec46    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 22:59:49                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 22:59:49                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 22:59:49                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 22:59:49                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  Black_SOKOL     :      SAM: -    :  Black_SOKOL 123     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2014-08-17 22:59:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:59:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:59:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:59:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:59:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:59:54                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:59:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:59:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 22:59:58                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-17 23:00:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x314    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 23:00:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 23:00:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:04                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   12290      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :      : BLACK_SOKOL      : Black_SOKOL      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:00:05                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12290      2014-08-17 23:01:05                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-08-17 23:01:05                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : {E26E9877-A8D0-4CB7-88CD-DB861FA75E22}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\26eeb30b335145deacd75c80feb58f57_98fe15f0-956a-480f-b19a-cc70db9dded3   : %%2458    : 0x0  
      Audit Success   12544      2014-08-17 23:01:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x314    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 23:01:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 23:06:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x314    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 23:06:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-08-17 23:12:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x314    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 23:12:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-08-17 23:14:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:14:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:14:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:14:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:14:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:14:52                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:15:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:15:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:15:01                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:16:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      : HomeGroupUser$      : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:16:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   13824      2014-08-17 23:16:38                                  Microsoft-Windows-Security-Auditing  4797:        .    :    :  S-1-5-21-2392427619-4168570856-2050312051-1001     :  Black_SOKOL     :  BLACK_SOKOL    :  0x3ecf3     :      : BLACK_SOKOL      :       : Black_SOKOL  
      Audit Success   12544      2014-08-17 23:19:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BLACK_SOKOL$     :  WORKGROUP    :  0x3e7     :   5     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x314    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "            .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-08-17 23:19:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
                            2014-08-11 16:55:47                                  volmgr                          46:     .  
                            2014-08-11 16:55:47                           Microsoft-Windows-HAL           13: 
                  212        2014-08-11 16:56:01                           Microsoft-Windows-Kernel-PnP    219: 
                            2014-08-11 16:56:08                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                    2          2014-08-11 16:59:28                                  Microsoft-Windows-NDIS          10317: 
                  1014       2014-08-11 17:00:20  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     appexdb3.stb.s-msn.com        DNS.  
                  1014       2014-08-11 17:00:59  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     col403-m.hotmail.com        DNS.  
                  1014       2014-08-11 17:01:32  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     sba.cdn.yandex.net.cache-default01e.cdn.yandex.net        DNS.  
                    2          2014-08-11 17:05:18                                  Microsoft-Windows-NDIS          10317: 
                            2014-08-11 19:42:12                           Microsoft-Windows-HAL           13: 
                            2014-08-11 19:42:13                                  volmgr                          46:     .  
                            2014-08-11 19:42:25                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                  212        2014-08-11 19:42:50                           Microsoft-Windows-Kernel-PnP    219: 
                            2014-08-12 16:54:07                           Microsoft-Windows-HAL           13: 
                            2014-08-12 16:54:08                                  volmgr                          46:     .  
                            2014-08-12 16:54:29                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                  212        2014-08-12 16:54:47                           Microsoft-Windows-Kernel-PnP    219: 
                  212        2014-08-12 16:54:47                           Microsoft-Windows-Kernel-PnP    219: 
                            2014-08-12 18:14:03                                  Service Control Manager         7009: 
                            2014-08-12 18:14:03                                  Service Control Manager         7000: 
                  1014       2014-08-12 18:52:37  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     win8.ipv6.microsoft.com.        DNS.  
                            2014-08-12 19:38:54                                  volmgr                          46:     .  
                            2014-08-12 19:38:54                           Microsoft-Windows-HAL           13: 
                            2014-08-12 19:39:07                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                  212        2014-08-12 19:39:24                           Microsoft-Windows-Kernel-PnP    219: 
                            2014-08-12 22:03:22                                  Service Control Manager         7034: 
                            2014-08-12 22:03:28                                  Service Control Manager         7030: 
                            2014-08-12 22:18:06                                  Service Control Manager         7000: 
                  1014       2014-08-12 22:32:33  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     dm1.storage.live.com        DNS.  
                            2014-08-13 17:03:50                                  volmgr                          46:     .  
                            2014-08-13 17:03:50                           Microsoft-Windows-HAL           13: 
                            2014-08-13 17:04:40                           Microsoft-Windows-HAL           13: 
                            2014-08-13 17:04:41                                  volmgr                          46:     .  
                            2014-08-13 17:06:32                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                  212        2014-08-13 17:06:53                           Microsoft-Windows-Kernel-PnP    219: 
                  1014       2014-08-13 17:10:52  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     login.live.com        DNS.  
                  1014       2014-08-13 17:11:10  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     client.wns.windows.com        DNS.  
                  1014       2014-08-13 17:11:22  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     watson.telemetry.microsoft.com        DNS.  
                            2014-08-13 17:12:25                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                  1014       2014-08-13 17:15:12  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     static.dl.mail.ru        DNS.  
                  1014       2014-08-13 17:15:47  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     lb.datarating.com        DNS.  
                  1014       2014-08-13 17:16:00  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     api.fri-gate.org        DNS.  
                  1014       2014-08-13 17:19:07  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     syndication.twitter.com        DNS.  
                  1014       2014-08-13 17:45:06  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     m2138814.iavs9x.u.avast.com        DNS.  
                            2014-08-13 22:39:43                                  volmgr                          46:     .  
                            2014-08-13 22:39:43                           Microsoft-Windows-HAL           13: 
                            2014-08-13 22:40:03                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                            2014-08-13 22:40:34                                  Service Control Manager         7000: 
                  212        2014-08-13 22:40:48                           Microsoft-Windows-Kernel-PnP    219: 
                            2014-08-14 17:58:33                                  volmgr                          46:     .  
                            2014-08-14 17:58:33                           Microsoft-Windows-HAL           13: 
                            2014-08-14 17:59:04                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                            2014-08-14 17:59:32                                  Service Control Manager         7000: 
                  212        2014-08-14 17:59:42                           Microsoft-Windows-Kernel-PnP    219: 
                            2014-08-14 21:19:55                                  volmgr                          46:     .  
                            2014-08-14 21:19:55                           Microsoft-Windows-HAL           13: 
                            2014-08-14 21:20:17                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                  212        2014-08-14 21:20:33                           Microsoft-Windows-Kernel-PnP    219: 
                          2014-08-14 21:24:07                           Microsoft-Windows-Bits-Client   16393: 
                  1014       2014-08-14 21:26:09  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     soft.oszone.net        DNS.  
                            2014-08-15 17:01:30                                  volmgr                          46:     .  
                            2014-08-15 17:01:30                           Microsoft-Windows-HAL           13: 
                            2014-08-16 10:26:18                                  volmgr                          46:     .  
                            2014-08-16 10:26:18                           Microsoft-Windows-HAL           13: 
                            2014-08-16 10:26:50                                  volmgr                          46:     .  
                            2014-08-16 10:26:50                           Microsoft-Windows-HAL           13: 
                            2014-08-16 10:27:07                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                  212        2014-08-16 10:27:54                           Microsoft-Windows-Kernel-PnP    219: 
                            2014-08-16 10:38:39                           Microsoft-Windows-Kernel-General  5: 
                            2014-08-16 11:35:29                           Microsoft-Windows-Kernel-General  5: 
                            2014-08-16 11:54:01                                  Service Control Manager         7034: 
                            2014-08-16 11:54:51                                  Service Control Manager         7030: 
                  1014       2014-08-16 12:05:50  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     uib.ff.avast.com        DNS.  
                            2014-08-16 12:22:07                           Microsoft-Windows-Kernel-General  5: 
                            2014-08-16 12:27:19                                  Service Control Manager         7034: 
                            2014-08-16 12:27:57                                  Service Control Manager         7030: 
                            2014-08-16 12:27:59                                  Service Control Manager         7034: 
                            2014-08-16 12:53:23                           Microsoft-Windows-HAL           13: 
                            2014-08-16 12:53:24                                  volmgr                          46:     .  
                            2014-08-16 12:53:59                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                  212        2014-08-16 12:54:15                           Microsoft-Windows-Kernel-PnP    219: 
                  1014       2014-08-16 13:07:10  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     15.56.157.93.in-addr.arpa.        DNS.  
                            2014-08-16 20:47:00                                  volmgr                          46:     .  
                            2014-08-16 20:47:00                           Microsoft-Windows-HAL           13: 
                            2014-08-16 20:47:42                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                            2014-08-16 20:47:47                                  BugCheck                        
                            2014-08-16 20:48:08                                  Service Control Manager         7000: 
                            2014-08-16 21:11:50                           Microsoft-Windows-HAL           13: 
                            2014-08-16 21:11:51                                  volmgr                          46:     .  
                            2014-08-16 21:12:09                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                            2014-08-16 21:12:36                                  Service Control Manager         7000: 
                  212        2014-08-16 21:12:37                           Microsoft-Windows-Kernel-PnP    219: 
                  1014       2014-08-16 21:13:30  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     ds.ssw.live.com        DNS.  
                  1014       2014-08-16 21:13:54  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     image.gamatrix.com        DNS.  
                  1014       2014-08-16 21:21:45  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     api.vk.com        DNS.  
                  1014       2014-08-16 21:22:39  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     uib.ff.avast.com        DNS.  
                  1014       2014-08-16 21:22:42  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     su.ff.avast.com        DNS.  
                  1014       2014-08-16 21:23:42  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     license.drweb.com        DNS.  
                  1014       2014-08-16 21:33:39  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     col403-m.hotmail.com        DNS.  
                  1014       2014-08-16 21:35:25  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     m2138814.iavs9x.u.avast.com        DNS.  
                  1014       2014-08-16 21:40:33  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     export.yandex.ru        DNS.  
                  1014       2014-08-16 21:42:25  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     watson.telemetry.microsoft.com        DNS.  
                  1014       2014-08-16 21:53:21  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     ajax.googleapis.com        DNS.  
                  1014       2014-08-16 21:55:47  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     mc.yandex.ru        DNS.  
                  1014       2014-08-16 21:57:23  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     watson.telemetry.microsoft.com        DNS.  
                  1014       2014-08-16 21:58:25  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     clients2.google.com        DNS.  
                  1014       2014-08-16 21:59:30  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     clients2.googleusercontent.com        DNS.  
                  1014       2014-08-16 22:00:56  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     messages.api.autodesk.com.s3.amazonaws.com        DNS.  
                  1014       2014-08-16 22:02:00  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     syndication.twitter.com        DNS.  
                  1014       2014-08-16 22:02:53  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     download.geo.drweb.com        DNS.  
                  1014       2014-08-16 22:04:01  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     syndication.twitter.com        DNS.  
                  1014       2014-08-16 22:04:52  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     api.browser.yandex.ru        DNS.  
                  223        2014-08-16 22:14:04                           Microsoft-Windows-Kernel-PnP    225: 
                  1014       2014-08-16 22:25:34  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     syndication.twitter.com        DNS.  
                  223        2014-08-16 22:26:20                           Microsoft-Windows-Kernel-PnP    225: 
                          2014-08-16 22:33:08                                  disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-08-16 22:33:08                                  disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-08-16 22:33:08                                  disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-08-16 22:33:08                                  Ntfs                            50: 
                          2014-08-16 22:33:08                           Microsoft-Windows-Ntfs          140: 
                          2014-08-16 22:33:09                                  Ntfs                            50: 
                          2014-08-16 22:33:11                                  Ntfs                            50: 
                          2014-08-16 22:33:12                                  Ntfs                            50: 
                          2014-08-16 22:33:14                                  Ntfs                            50: 
                          2014-08-16 22:33:15                                  Ntfs                            50: 
                          2014-08-16 22:33:15                                  Ntfs                            50: 
                          2014-08-16 22:33:15                                  Ntfs                            50: 
                          2014-08-16 22:33:16                                  Ntfs                            50: 
                          2014-08-16 22:33:16                                  Ntfs                            50: 
                          2014-08-16 22:33:16                                  Ntfs                            50: 
                          2014-08-16 22:33:16                                  Ntfs                            50: 
                            2014-08-16 22:49:59                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                  223        2014-08-16 22:51:17                           Microsoft-Windows-Kernel-PnP    225: 
                  223        2014-08-16 22:51:27                           Microsoft-Windows-Kernel-PnP    225: 
                            2014-08-16 22:52:49  Black_SOKOL                     DCOM                            
                            2014-08-16 22:52:49  Black_SOKOL                     DCOM                            
                            2014-08-16 22:53:29                                  volmgr                          46:     .  
                            2014-08-16 22:53:29                           Microsoft-Windows-HAL           13: 
                            2014-08-16 22:53:55                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                  212        2014-08-16 22:54:09                           Microsoft-Windows-Kernel-PnP    219: 
                  223        2014-08-16 23:02:57                           Microsoft-Windows-Kernel-PnP    225: 
                            2014-08-17 00:45:21                                  volmgr                          46:     .  
                            2014-08-17 00:45:21                           Microsoft-Windows-HAL           13: 
                            2014-08-17 00:45:41                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                  212        2014-08-17 00:58:12                           Microsoft-Windows-Kernel-PnP    219: 
                  223        2014-08-17 01:13:25                           Microsoft-Windows-Kernel-PnP    225: 
                          2014-08-17 08:10:41  Black_SOKOL                     User32                          1073:   BLACK_SOKOL\Black_SOKOL      BLACK_SOKOL    
                    2          2014-08-17 08:16:50                                  Ntfs                            137: 
                            2014-08-17 08:19:52                                  volmgr                          46:     .  
                            2014-08-17 08:19:52                           Microsoft-Windows-HAL           13: 
                            2014-08-17 08:20:20                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                  212        2014-08-17 08:20:49                           Microsoft-Windows-Kernel-PnP    219: 
                          2014-08-17 08:20:50                           Microsoft-Windows-Bits-Client   16393: 
                            2014-08-17 08:20:51                                  Service Control Manager         7024: 
                            2014-08-17 08:20:51                                  Service Control Manager         7023: 
                            2014-08-17 08:20:51                                  Service Control Manager         7023: 
                            2014-08-17 08:20:51                           Microsoft-Windows-Bits-Client   16392: 
                            2014-08-17 08:22:49                                  volmgr                          46:     .  
                            2014-08-17 08:22:49                           Microsoft-Windows-HAL           13: 
                            2014-08-17 08:23:10                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                            2014-08-17 08:23:54                                  Service Control Manager         7000: 
                            2014-08-17 08:27:04                                  Service Control Manager         7034: 
                            2014-08-17 08:29:53                                  Service Control Manager         7030: 
                            2014-08-17 08:43:06                           Microsoft-Windows-HAL           13: 
                            2014-08-17 08:43:07                                  volmgr                          46:     .  
                            2014-08-17 08:43:36                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                            2014-08-17 08:43:56                                  Service Control Manager         7000: 
                            2014-08-17 08:57:12                           Microsoft-Windows-Kernel-General  5: 
                            2014-08-17 10:33:38                           Microsoft-Windows-HAL           13: 
                            2014-08-17 10:33:39                                  volmgr                          46:     .  
                            2014-08-17 10:33:57                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                            2014-08-17 10:34:25                                  Service Control Manager         7000: 
                            2014-08-17 13:51:30                           Microsoft-Windows-HAL           13: 
                            2014-08-17 13:51:31                                  volmgr                          46:     .  
                            2014-08-17 13:51:57                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                            2014-08-17 13:52:11                                  Service Control Manager         7000: 
                            2014-08-17 18:58:44                                  volmgr                          46:     .  
                            2014-08-17 18:58:44                           Microsoft-Windows-HAL           13: 
                            2014-08-17 18:58:59                           Microsoft-Windows-WLAN-AutoConfig  10000: 
                            2014-08-17 18:59:31                                  Service Control Manager         7000: 
                  1014       2014-08-17 19:24:33  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     www.mywot.com        DNS.  
                          2014-08-17 21:38:07                                  Display                         4101: 
                          2014-08-17 21:38:15                                  Display                         4101: 
                            2014-08-17 22:55:21  Black_SOKOL                     DCOM                            
                            2014-08-17 22:55:25                                  Service Control Manager         7000: 
                            2014-08-17 22:55:51  Black_SOKOL                     DCOM                            
                            2014-08-17 22:58:52                                  volmgr                          46:     .  
                            2014-08-17 22:58:52                           Microsoft-Windows-HAL           13: 
                            2014-08-17 22:59:40                           Microsoft-Windows-WLAN-AutoConfig  10000: 


--------[ Debug - PCI ]-------------------------------------------------------------------------------------------------

    B00 D00 F00:  AMD K12 - Root Complex
                  
      Offset 000:  22 10 05 17  06 00 20 02  00 00 00 06  00 20 00 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  22 10 05 17 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  02 20 00 00 
      Offset 050:  22 10 05 17  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  CD 00 00 00  00 00 04 02  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  10 00 00 03  00 00 00 00  31 20 00 00 
      Offset 090:  00 00 00 D0  4B 01 00 00  00 01 20 00  00 00 00 00 
      Offset 0A0:  01 80 30 01  EF BE AD DE  01 00 00 00  01 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  16 80 32 01  1F 00 FF 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 80 80 00  00 00 00 00  00 00 00 00 

    B00 D01 F00:  AMD Radeon HD 6520G (Sumo) Video Adapter
                  
      Offset 000:  02 10 47 96  07 04 10 00  00 00 00 03  10 00 80 00 
      Offset 010:  08 00 00 D0  01 50 00 00  00 00 30 F0  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  79 11 51 FC 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  00 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  79 11 51 FC 
      Offset 050:  01 58 03 06  00 00 00 00  10 A0 92 00  A0 8F 00 00 
      Offset 060:  10 08 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 00 81 00  0C F0 E0 FE  00 00 00 00  71 49 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D01 F01:  AMD K12 - High Definition Audio Controller
                  
      Offset 000:  02 10 14 17  06 00 10 00  00 00 03 04  10 00 80 00 
      Offset 010:  00 40 34 F0  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  02 10 14 17 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  13 02 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  02 10 14 17 
      Offset 050:  01 58 03 06  00 00 00 00  10 A0 92 00  A0 8F 00 00 
      Offset 060:  10 08 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 00 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D02 F00:  AMD K12 - PCI Express Root Port
                  
      Offset 000:  22 10 07 17  07 00 10 00  00 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 01 01 00  41 41 00 20 
      Offset 020:  20 F0 20 F0  01 E0 F1 EF  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  12 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 58 03 C8  00 00 00 00  10 A0 42 01  20 80 00 00 
      Offset 060:  10 28 00 00  01 0D 30 00  00 00 11 30  C0 25 14 00 
      Offset 070:  00 00 48 01  00 00 01 00  00 00 00 00  1F 00 00 00 
      Offset 080:  06 00 00 00  00 00 00 00  21 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 B0 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  0D B8 00 00  22 10 34 12  08 00 03 A8  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  A4 00 00 00  40 80 82 13  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D04 F00:  AMD K12 - PCI Express Root Port
                  
      Offset 000:  22 10 09 17  07 00 10 00  00 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 02 02 00  31 31 00 20 
      Offset 020:  10 F0 10 F0  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  12 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 58 03 C8  00 01 00 00  10 A0 42 01  20 80 00 00 
      Offset 060:  10 28 00 00  11 0C 30 01  00 00 11 30  80 25 24 00 
      Offset 070:  00 00 48 01  00 00 01 00  00 00 00 00  1F 00 00 00 
      Offset 080:  06 00 00 00  00 00 00 00  21 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 B0 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  0D B8 00 00  22 10 34 12  08 00 03 A8  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  50 00 00 00  02 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D05 F00:  AMD K12 - PCI Express Root Port
                  
      Offset 000:  22 10 0A 17  07 00 10 00  00 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 03 03 00  21 21 00 20 
      Offset 020:  00 F0 00 F0  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  11 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 58 03 C8  00 00 00 00  10 A0 42 01  20 80 00 00 
      Offset 060:  10 28 00 00  11 0C 30 02  03 00 11 30  80 25 2C 00 
      Offset 070:  00 00 48 01  00 00 01 00  00 00 00 00  1F 00 00 00 
      Offset 080:  06 00 00 00  00 00 00 00  21 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 B0 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  0D B8 00 00  22 10 34 12  08 00 03 A8  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  A0 00 00 00  30 00 80 40  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D11 F00:  AMD Hudson-2 FCH - SATA AHCI Controller
                  
      Offset 000:  22 10 01 78  07 00 30 02  00 01 06 01  10 40 00 00 
      Offset 010:  19 51 00 00  25 51 00 00  11 51 00 00  21 51 00 00 
      Offset 020:  01 51 00 00  00 F0 34 F0  00 00 00 00  79 11 50 FC 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  13 01 00 00 
      Offset 040:  10 00 FC 00  01 00 20 00  40 08 00 80  00 00 34 FC 
      Offset 050:  05 70 84 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  01 50 22 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  12 00 10 00  0F 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  21 00 00 00  06 00 14 40  AB 01 08 00  F0 00 00 00 
      Offset 090:  27 60 74 C7  1F 00 7F 00  02 83 07 00  20 01 00 00 
      Offset 0A0:  01 58 B1 02  10 00 00 00  0C 96 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 20 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  10 00 00 FF  00 00 00 00 
      Offset 0D0:  13 00 06 03  00 00 64 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  80 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D12 F00:  AMD Hudson-2 FCH - USB OHCI Controller
                  
      Offset 000:  22 10 07 78  16 00 A0 02  11 10 03 0C  10 20 80 00 
      Offset 010:  00 E0 34 F0  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  79 11 50 FC 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  12 01 00 00 
      Offset 040:  80 01 00 F0  11 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 03 18 F0  00 00 00 00  FF FF FF FF  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  FF 00 00 80  00 00 00 30  00 00 00 00 
      Offset 080:  BB 05 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  10 01 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D12 F02:  AMD Hudson-2 FCH - USB 2.0 EHCI Controller
                  
      Offset 000:  22 10 08 78  16 00 B0 02  11 20 03 0C  10 20 00 00 
      Offset 010:  00 D0 34 F0  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  79 11 50 FC 
      Offset 030:  00 00 00 00  C0 00 00 00  00 00 00 00  11 02 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 11 2A A2  7B AA 0F 00  00 00 00 00  00 00 00 00 
      Offset 060:  20 20 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  20 00 00 01  00 00 00 00  00 00 00 00 
      Offset 0A0:  01 00 00 01  00 20 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  01 E4 02 7E  00 00 40 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  0A 00 E0 20  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D13 F00:  AMD Hudson-2 FCH - USB OHCI Controller
                  
      Offset 000:  22 10 07 78  16 00 A0 02  11 10 03 0C  10 20 80 00 
      Offset 010:  00 C0 34 F0  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  79 11 50 FC 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  12 01 00 00 
      Offset 040:  80 01 00 F0  11 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 03 18 F0  00 00 00 00  FF FF FF FF  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  FF 00 00 80  00 00 00 30  00 00 00 00 
      Offset 080:  BB 05 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  10 01 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D13 F02:  AMD Hudson-2 FCH - USB 2.0 EHCI Controller
                  
      Offset 000:  22 10 08 78  16 00 B0 02  11 20 03 0C  10 20 00 00 
      Offset 010:  00 B0 34 F0  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  79 11 50 FC 
      Offset 030:  00 00 00 00  C0 00 00 00  00 00 00 00  11 02 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 11 2A A2  7B AA 0F 00  00 00 00 00  00 00 00 00 
      Offset 060:  20 20 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  20 00 00 01  00 00 00 00  00 00 00 00 
      Offset 0A0:  01 00 00 01  00 20 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  01 E4 02 7E  00 00 40 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  0A 00 E0 20  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F00:  AMD Hudson-2 FCH - SMBus and ACPI Controller
                  
      Offset 000:  22 10 0B 78  03 04 20 02  13 00 05 0C  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  79 11 50 FC 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F02:  AMD Hudson-2 FCH - High Definition Audio Controller
                  
      Offset 000:  22 10 0D 78  06 00 10 04  01 00 03 04  10 20 00 00 
      Offset 010:  04 00 34 F0  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  79 11 50 FC 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  10 01 00 00 
      Offset 040:  00 00 40 00  01 00 00 00  00 00 00 00  01 00 00 00 
      Offset 050:  01 00 42 C8  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F03:  AMD Hudson-2 FCH - LPC Bridge
                  
      Offset 000:  22 10 0E 78  0F 00 20 02  11 00 01 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  79 11 50 FC 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  24 00 00 00  00 C0 03 64  37 FF 20 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  80 FF 80 FF  68 00 00 00  00 00 0F 00  E0 FF FF FF 
      Offset 070:  67 45 23 00  01 00 00 00  9C 00 00 00  05 0A 00 00 
      Offset 080:  08 00 03 A8  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 10 D6 FE 
      Offset 0A0:  02 00 C1 FE  2F 01 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 E9 3D  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 F7 FF 
      Offset 0D0:  02 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F04:  AMD Hudson-2 FCH - PCI-PCI Host Bridge
                  
      Offset 000:  22 10 0F 78  07 04 A0 02  40 01 04 06  00 40 81 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 04 04 40  F0 00 80 22 
      Offset 020:  F0 FF 00 00  F0 FF 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  26 00 00 FF  00 00 00 00  0C 0F 3E D1  00 00 00 00 
      Offset 050:  01 00 00 00  08 00 03 A8  00 00 00 00  85 00 FF FF 
      Offset 060:  CA 0E 17 00  BA 98 10 02  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  01 00 02 06 
      Offset 0E0:  00 00 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F05:  AMD Hudson-2 FCH - USB OHCI Controller
                  
      Offset 000:  22 10 09 78  16 00 A0 02  11 10 03 0C  10 20 00 00 
      Offset 010:  00 A0 34 F0  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  79 11 50 FC 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  12 03 00 00 
      Offset 040:  80 01 00 F0  11 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 03 18 F0  00 00 00 00  FF FF FF FF  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  FF 00 00 80  00 00 00 00  00 00 00 00 
      Offset 080:  BB 05 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  10 01 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D16 F00:  AMD Hudson-2 FCH - USB OHCI Controller
                  
      Offset 000:  22 10 07 78  16 00 A0 02  11 10 03 0C  10 20 80 00 
      Offset 010:  00 90 34 F0  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  79 11 50 FC 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  12 01 00 00 
      Offset 040:  80 01 00 F0  11 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 03 18 F0  00 00 00 00  FF FF FF FF  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  FF 00 00 80  00 00 00 30  00 00 00 00 
      Offset 080:  BB 05 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  10 01 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D16 F02:  AMD Hudson-2 FCH - USB 2.0 EHCI Controller
                  
      Offset 000:  22 10 08 78  16 00 B0 02  11 20 03 0C  10 20 00 00 
      Offset 010:  00 80 34 F0  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  79 11 50 FC 
      Offset 030:  00 00 00 00  C0 00 00 00  00 00 00 00  11 02 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 11 2A A2  7B AA 0F 00  00 00 00 00  00 00 00 00 
      Offset 060:  20 20 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  20 00 00 01  00 00 00 00  00 00 00 00 
      Offset 0A0:  01 00 00 01  00 20 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  01 E4 02 7E  00 00 40 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  0A 00 E0 20  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F00:  AMD K12 - Link Control
                  
      Offset 000:  22 10 00 17  00 00 10 00  43 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  20 08 2E 00  00 06 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F01:  AMD K12 - Address Map
                  
      Offset 000:  22 10 01 17  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  03 00 00 00  00 00 2E 01  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  03 00 FC 00  00 BF FE 00  03 00 D0 00  00 FF F7 00 
      Offset 090:  03 0A 00 00  00 0B 00 00  03 C0 FE 00  80 D8 FE 00 
      Offset 0A0:  03 00 F8 00  80 FF FB 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  80 00 00 00 
      Offset 0C0:  13 00 00 00  00 F0 FF 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  01 30 00 D0  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F02:  AMD K12 - DRAM Controller
                  
      Offset 000:  22 10 02 17  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  01 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  E0 3F 78 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  07 40 CA 04  90 00 02 18 
      Offset 080:  07 00 00 00  51 00 A0 00  05 00 00 FC  54 60 32 00 
      Offset 090:  00 00 60 06  8E 88 41 3E  0A E0 0F 8D  00 60 00 00 
      Offset 0A0:  00 00 00 00  01 00 00 00  00 00 40 00  00 00 00 00 
      Offset 0B0:  6F 1D 4B E3  4A 05 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 08  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  32 00 00 80  06 05 00 00  00 00 00 00  00 00 00 00 
      Offset 100:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 110:  44 01 00 00  00 02 00 00  A4 84 08 00  70 40 40 00 
      Offset 120:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 130:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 140:  01 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 150:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 160:  E0 3F 78 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 170:  00 00 00 00  00 00 00 00  07 40 CA 04  90 00 02 18 
      Offset 180:  07 00 00 00  51 00 A0 00  05 00 00 FC  54 60 32 00 
      Offset 190:  00 00 60 06  8E 88 41 3E  0A E0 0F 8D  00 60 00 00 
      Offset 1A0:  00 00 00 00  00 00 00 00  00 00 40 00  00 00 00 00 
      Offset 1B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1C0:  18 00 10 00  00 00 00 00  06 80 00 02  00 00 00 00 
      Offset 1D0:  00 00 00 00  83 77 5C 65  00 00 00 00  00 00 00 00 
      Offset 1E0:  00 00 00 00  00 00 00 00  00 FF 00 00  00 00 00 00 
      Offset 1F0:  32 00 00 80  06 05 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F03:  AMD K12 - Miscellaneous Control
                  
      Offset 000:  22 10 03 17  00 00 10 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  F0 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  20 3B 03 02  40 00 30 0A  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  01 00 7E F0  00 00 00 70  1E 01 00 00 
      Offset 070:  00 00 00 00  97 08 00 00  00 00 00 00  01 01 01 19 
      Offset 080:  00 00 00 00  06 00 06 00  00 02 00 00  00 00 00 04 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  D8 02 0E 80  EF 0F 40 45  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  D8 4F 02 00  C0 07 00 00  31 D7 8A 99 
      Offset 0E0:  00 00 00 00  20 0B 00 00  41 37 00 10  00 00 00 00 
      Offset 0F0:  0F 00 10 00  00 00 00 00  00 00 00 00  10 0F 30 00 
      Offset 100:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 110:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 120:  00 00 00 00  00 00 00 00  58 80 00 00  00 00 00 00 
      Offset 130:  00 00 00 00  00 00 00 00  01 00 56 A2  A0 44 00 00 
      Offset 140:  A0 43 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 150:  00 00 00 00  00 00 00 00  00 00 00 00  35 2D 2D 2D 
      Offset 160:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 170:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 180:  20 00 20 00  00 00 00 00  01 00 00 1B  00 00 00 00 
      Offset 190:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 01 00 00 
      Offset 1D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1E0:  00 00 00 00  00 00 00 80  00 00 00 00  00 00 00 00 
      Offset 1F0:  11 18 08 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F04:  AMD K12 - Extended Miscellaneous Control
                  
      Offset 000:  22 10 04 17  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 100:  00 00 00 00  41 86 20 03  00 00 00 00  E1 03 54 00 
      Offset 110:  00 00 00 00  00 00 00 00  01 01 00 00  00 00 00 00 
      Offset 120:  00 00 00 90  00 80 13 0D  00 00 00 00  2F 01 00 00 
      Offset 130:  01 01 01 01  00 51 45 C5  00 00 00 00  0F 00 0F 00 
      Offset 140:  61 B7 69 19  D8 05 00 00  A4 49 8E 22  21 58 35 05 
      Offset 150:  00 00 00 00  00 00 00 00  00 00 00 00  05 00 00 3F 
      Offset 160:  10 0F 30 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 170:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 180:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 190:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1A0:  00 00 00 00  FC FF FF FF  E8 01 9E 37  E0 01 07 4C 
      Offset 1B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F05:  AMD K12 - Miscellaneous Control
                  
      Offset 000:  22 10 18 17  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F06:  AMD K12 - Miscellaneous Control
                  
      Offset 000:  22 10 16 17  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  04 00 00 00  20 10 08 00  40 20 10 00  20 10 08 00 
      Offset 060:  20 10 08 00  10 08 04 00  10 08 04 00  80 40 20 00 
      Offset 070:  80 40 20 00  1E 00 00 00  37 00 00 00  09 88 52 0A 
      Offset 080:  00 00 70 00  7F 3F 00 C6  00 00 00 00  00 00 00 00 
      Offset 090:  28 35 00 80  0A 00 00 02  02 00 00 00  F8 01 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  C0 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F07:  AMD K12 - Miscellaneous Control
                  
      Offset 000:  22 10 19 17  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 2D 00 00  00 00 00 00  40 0B 00 00 
      Offset 050:  8D D7 07 00  76 1C 00 00  3B 09 10 00  15 09 10 00 
      Offset 060:  B0 B4 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 3A 00  00 FF 54 00  00 FF 54 00  00 FF 0D 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B01 D00 F00:  AMD Radeon HD 6450M/6470M/6490M (Seymour) Video Adapter
                  
      Offset 000:  02 10 60 67  06 04 10 00  00 00 00 03  10 00 00 00 
      Offset 010:  0C 00 00 E0  00 00 00 00  04 00 2E F0  00 00 00 00 
      Offset 020:  01 4F 00 00  00 00 00 00  00 00 00 00  79 11 51 FC 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  00 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  79 11 51 FC 
      Offset 050:  01 58 03 06  00 00 00 00  10 A0 12 00  A1 8F 00 00 
      Offset 060:  10 29 09 00  02 0D 00 00  00 00 11 10  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  02 00 01 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 00 81 00  0C F0 E0 FE  00 00 00 00  61 49 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B02 D00 F00:  Atheros AR8152/8158 PCI-E Fast Ethernet Controller
                  
      Offset 000:  69 19 62 20  07 00 10 00  C1 00 00 02  10 00 00 00 
      Offset 010:  04 00 10 F0  00 00 00 00  01 30 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  79 11 50 FC 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  10 01 00 00 
      Offset 040:  01 48 C3 F9  08 01 00 00  05 58 80 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  10 6C 01 00  C5 FF 00 00 
      Offset 060:  00 20 1A 00  11 FC 07 00  00 00 11 10  03 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  1C 02 00 00  00 0C 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B03 D00 F00:  Realtek RTL8188CE Wireless LAN 802.11n PCI-E Network Adapter
                  
      Offset 000:  EC 10 76 81  07 00 10 00  01 00 80 02  10 00 00 00 
      Offset 010:  01 20 00 00  00 00 00 00  04 00 00 F0  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  EC 10 81 81 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  11 01 00 00 
      Offset 040:  01 50 C3 FF  08 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  05 70 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  10 00 02 00  C0 8C 00 00  10 20 19 00  11 3C 07 00 
      Offset 080:  03 00 11 10  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  10 00 00 00  10 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 


--------[ Debug - Video BIOS ]------------------------------------------------------------------------------------------

    C000:0000  U.x...........................IBM............... 761295520......
    C000:0040  ................05/10/11,11:11:28...............................
    C000:0080  BR40913.bin.SUMO.PCI_EXPRESS.DDR3...Toshiba Llano/SUMO VBIOS    
    C000:00C0                                                  ..... ...(C) 198
    C000:0100  8-2010, AMD Technologies Inc. .ATOMBIOSBK-ATI VER012.043.000.014
    C000:0140  .040913.BR40913.bin .655113  .190133  .        .Toshiba_Celtic_B
    C000:0180  S_AS_Llano\config.h...$...ATOM..{.H..........P..G...........PCIR
    C000:01C0  ..G.........x.+.....AMD ATOMBIOS..k.............................
    C000:0200  .V.......LP. .^..fPfQfRfSfUfVfW..................f......f.(....5
    C000:0240  .2......2&.H'.-&....T...%..&.......DP. u......i.hi.......LP.....
    C000:0280  1..DX...w...f.......fP........fXt.. f............f_f^f]f[fZfYfX.
    C000:02C0  ............F.f3..F...F..R......HZ..........f......(.f.\.f.L.;.u
    C000:0300  ...f.^.f.N.................>...u.............f....e.....@.....B.
    C000:0340  ............|.Xq..~.....ku........Sk............Uk.ek.wk...PMID.
    C000:0380  ..P....................f.............>..f.E....................f
    C000:03C0  PfR.1f...f....fZfX.fPfR.1f...f....fZfX...,..H.u..:&..u..G.....Ou


--------[ Debug - Unknown ]---------------------------------------------------------------------------------------------

    Optical         DTSOFT Virtual CdRom Device
    Optical         TSSTcorp CDDVDW TS-L633F


------------------------------------------------------------------------------------------------------------------------

The names of actual companies and products mentioned herein may be the trademarks of their respective owners.
