Advertisement
Guest User

Untitled

a guest
Oct 1st, 2016
426
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
XML 207.44 KB | None | 0 0
  1. <?xml version=”1.0″ encoding=”utf-8″ standalone=”yes”?>
  2. <Events><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’VSS’/><EventID Qualifiers=’0′>8224</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:41:20.020946500Z’/><EventRecordID>4051</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data></Data><Binary>2D20436F64653A2020434F525356434330303030303736302D2043616C6C3A2020434F525356434330303030303734322D205049443A202030303031333436382D205449443A202030303030323236302D20434D443A2020433A5C57494E444F57535C73797374656D33325C76737376632E6578652020202D20557365723A204E616D653A204E5420415554484F524954595C53595354454D2C205349443A532D312D352D313820</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Defrag’/><EventID Qualifiers=’0′>258</EventID><Level>0</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:38:58.794322400Z’/><EventRecordID>4050</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>analysis</Data><Data>OS (C:)</Data><Binary>00000000CC010000990100000000000022B6B6A4DCB1BD381B0700000000000000000000</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>508</EventID><Level>3</Level><Task>7</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:54.459973000Z’/><EventRecordID>4049</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>7984</Data><Data>{EC424B9C-11B0-4F65-BA06-0A0DEFB6A37D}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\remotemetastore\v1\meta.edb</Data><Data>851968 (0x00000000000d0000)</Data><Data>16384 (0x00004000)</Data><Data>25</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>508</EventID><Level>3</Level><Task>7</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:52.457799700Z’/><EventRecordID>4048</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>7984</Data><Data>{EC424B9C-11B0-4F65-BA06-0A0DEFB6A37D}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\remotemetastore\v1\edb.log</Data><Data>282624 (0x0000000000045000)</Data><Data>4096 (0x00001000)</Data><Data>24</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>508</EventID><Level>3</Level><Task>7</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:49.458944100Z’/><EventRecordID>4047</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>7984</Data><Data>{7B40AAE2-D568-4B58-A71F-8C1F76004616}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\edb.log</Data><Data>290816 (0x0000000000047000)</Data><Data>4096 (0x00001000)</Data><Data>23</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>508</EventID><Level>3</Level><Task>7</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:47.954454200Z’/><EventRecordID>4046</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>7984</Data><Data>{EC424B9C-11B0-4F65-BA06-0A0DEFB6A37D}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\remotemetastore\v1\meta.jfm</Data><Data>0 (0x0000000000000000)</Data><Data>8192 (0x00002000)</Data><Data>22</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>508</EventID><Level>3</Level><Task>7</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:46.418522400Z’/><EventRecordID>4045</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>7984</Data><Data>{7B40AAE2-D568-4B58-A71F-8C1F76004616}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.jfm</Data><Data>0 (0x0000000000000000)</Data><Data>8192 (0x00002000)</Data><Data>20</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>508</EventID><Level>3</Level><Task>7</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:43.453366000Z’/><EventRecordID>4044</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>7984</Data><Data>{7B40AAE2-D568-4B58-A71F-8C1F76004616}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1540096 (0x0000000000178000)</Data><Data>16384 (0x00004000)</Data><Data>15</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>103</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:42.360529600Z’/><EventRecordID>4043</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.094, [4] 0.000, [5] 0.016, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.015, [10] 0.000, [11] 0.000, [12] 0.000, [13] 0.047, [14] 0.000, [15] 0.000.</Data><Data>0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>326</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:42.060851900Z’/><EventRecordID>4042</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>1</Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.016, [6] 0.047, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.</Data><Data>0 0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>105</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:41.987847100Z’/><EventRecordID>4041</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>0</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.000, [4] 0.109, [5] 0.000, [6] 0.000, [7] 0.031, [8] 0.000, [9] 0.000, [10] 0.000.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>102</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:41.848923700Z’/><EventRecordID>4040</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>0</Data><Data>10</Data><Data>00</Data><Data>14393</Data><Data>0000</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>103</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:41.739190900Z’/><EventRecordID>4039</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.031, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.234, [10] 0.000, [11] 0.000, [12] 0.000, [13] 0.000, [14] 0.000, [15] 0.000.</Data><Data>0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>326</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:41.223580800Z’/><EventRecordID>4038</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>1</Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.015, [4] 0.000, [5] 0.047, [6] 0.063, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.</Data><Data>0 0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>105</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:41.107683500Z’/><EventRecordID>4037</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>0</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.000, [4] 0.015, [5] 0.000, [6] 0.000, [7] 0.032, [8] 0.000, [9] 0.000, [10] 0.000.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>102</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:41.060783200Z’/><EventRecordID>4036</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>0</Data><Data>10</Data><Data>00</Data><Data>14393</Data><Data>0000</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>103</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:41.038141500Z’/><EventRecordID>4035</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>0</Data><Data>[1] 0.000, [2] 0.047, [3] 0.000, [4] 0.000, [5] 0.031, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.015, [10] 0.000, [11] 0.016, [12] 0.000, [13] 0.000, [14] 0.000, [15] 0.000.</Data><Data>0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>326</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:40.590804300Z’/><EventRecordID>4034</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>1</Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.047, [6] 0.031, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.</Data><Data>0 0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>105</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:40.506104100Z’/><EventRecordID>4033</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>0</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.016, [8] 0.000, [9] 0.000, [10] 0.000.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>102</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:40.490479400Z’/><EventRecordID>4032</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>0</Data><Data>10</Data><Data>00</Data><Data>14393</Data><Data>0000</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>103</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:40.459046200Z’/><EventRecordID>4031</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>0</Data><Data>[1] 0.000, [2] 0.125, [3] 0.000, [4] 0.000, [5] 0.032, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.015, [10] 0.016, [11] 0.000, [12] 0.000, [13] 0.000, [14] 0.000, [15] 0.000.</Data><Data>0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>326</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:39.836692000Z’/><EventRecordID>4030</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>1</Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.016, [4] 0.000, [5] 0.000, [6] 0.078, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.</Data><Data>0 0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>105</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:39.736825300Z’/><EventRecordID>4029</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>0</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.000, [4] 0.360, [5] 0.000, [6] 0.000, [7] 0.015, [8] 0.000, [9] 0.000, [10] 0.000.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>102</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:04:39.373752200Z’/><EventRecordID>4028</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>0</Data><Data>10</Data><Data>00</Data><Data>14393</Data><Data>0000</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>103</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:03:46.868434100Z’/><EventRecordID>4027</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.016, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.016, [10] 0.000, [11] 0.000, [12] 0.000, [13] 0.015, [14] 0.000, [15] 0.000.</Data><Data>0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>326</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:03:46.599077000Z’/><EventRecordID>4026</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>1</Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.016, [4] 0.000, [5] 0.047, [6] 0.094, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.</Data><Data>0 0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>105</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:03:46.445956000Z’/><EventRecordID>4025</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>0</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.000, [4] 0.485, [5] 0.000, [6] 0.000, [7] 0.015, [8] 0.000, [9] 0.000, [10] 0.000.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>102</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T18:03:45.945205500Z’/><EventRecordID>4024</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>CCleaner64</Data><Data>9388</Data><Data>testing: </Data><Data>0</Data><Data>10</Data><Data>00</Data><Data>14393</Data><Data>0000</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>903</EventID><Version>0</Version><Level>0</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:59:55.139738600Z’/><EventRecordID>4023</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>16384</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:59:55.127724000Z’/><EventRecordID>4022</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>2116-09-07T17:59:54Z</Data><Data>RulesEngine</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>902</EventID><Version>0</Version><Level>0</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:59:24.730971100Z’/><EventRecordID>4021</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>10.0.14393.206</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>1003</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:59:24.676935300Z’/><EventRecordID>4020</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>55c92734-d682-4d71-983e-d6ec3f16059f</Data><Data>
  3. 1: 0567073a-7d74-403b-b2d5-6b35da372d8d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  4. 2: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  5. 3: 1b750385-9fe2-49a8-ab55-149d0546395b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  6. 4: 1d873132-f09f-4eb2-bf5a-2e4fb48935e8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  7. 5: 2b1f36bb-c1cd-4306-bf5c-a0367c2d97d8, 1, 1 [(0 )(1 )(2 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)(?)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(3 )]
  8. 6: 30d469c6-a78f-4476-b5c8-af78d5b6a5fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  9. 7: 411b3d4f-be6d-4a06-baaa-9cabfc256cae, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  10. 8: 58e97c99-f377-4ef1-81d5-4ad5522b5fd8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  11. 9: 74436dbb-cc17-46de-867f-14906ba4a938, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  12. 10: 8db63db6-4f8f-46d6-a448-66444faaaa72, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  13. 11: 9e4b231b-3e45-41f4-967f-c914f178b6ac, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  14. 12: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  15. 13: c082c31b-2c4f-4e07-94d7-9181fa802c4b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  16. 14: e371d89a-73e8-4b24-a7ff-23a3641dd18e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  17.  
  18. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>1066</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:59:24.520834900Z’/><EventRecordID>4019</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>C:\WINDOWS\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
  19. C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/inherited/1.0, 0x00000000, 0x00000000
  20. C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
  21. C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
  22. C:\WINDOWS\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
  23. C:\WINDOWS\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
  24. C:\WINDOWS\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
  25. C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
  26. C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
  27. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>900</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:59:24.382239900Z’/><EventRecordID>4018</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>caller=wmiprvse.exe</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:19.297885500Z’/><EventRecordID>4017</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>c:\xampp\mysql\bin\mysqld.exe: ready for connections.
  28. Version: ‘10.1.16-MariaDB’ socket: ” port: 3307 mariadb.org binary distribution
  29.  
  30. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:16.500116000Z’/><EventRecordID>4016</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Server socket created on IP: ‘::’.
  31.  
  32. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:16.497114000Z’/><EventRecordID>4015</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Plugin ‘FEEDBACK’ is disabled.
  33.  
  34. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:16.496613700Z’/><EventRecordID>4014</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Dumping buffer pool(s) not yet started
  35.  
  36. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:15.419407600Z’/><EventRecordID>4013</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Percona XtraDB (http://www.percona.com) 5.6.30-76.3 started; log sequence number 4604859
  37.  
  38. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:15.105590800Z’/><EventRecordID>4012</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Waiting for purge to start
  39.  
  40. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:15.103586400Z’/><EventRecordID>4011</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: 128 rollback segment(s) are active.
  41.  
  42. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:09.877961400Z’/><EventRecordID>4010</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: from the doublewrite buffer…
  43.  
  44. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:09.876460400Z’/><EventRecordID>4009</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Restoring possible half-written data pages
  45.  
  46. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:09.859445000Z’/><EventRecordID>4008</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Reading tablespace information from the .ibd files…
  47.  
  48. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:09.858444400Z’/><EventRecordID>4007</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Starting crash recovery.
  49.  
  50. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:09.857443700Z’/><EventRecordID>4006</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Database was not shutdown normally!
  51.  
  52. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:09.856442500Z’/><EventRecordID>4005</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: The log sequence numbers 4597340 and 4597340 in ibdata files do not match the log sequence number 4604859 in the ib_logfiles!
  53.  
  54. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:09.688451700Z’/><EventRecordID>4004</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Highest supported file format is Barracuda.
  55.  
  56. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:08.353121100Z’/><EventRecordID>4003</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Completed initialization of buffer pool
  57.  
  58. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:08.351119800Z’/><EventRecordID>4002</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Initializing buffer pool, size = 16.0M
  59.  
  60. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:08.257191800Z’/><EventRecordID>4001</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Using generic crc32 instructions
  61.  
  62. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:08.255190500Z’/><EventRecordID>4000</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Compressed tables use zlib 1.2.3
  63.  
  64. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:08.254189900Z’/><EventRecordID>3999</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Memory barrier is not used
  65.  
  66. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:08.254189900Z’/><EventRecordID>3998</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Mutexes and rw_locks use Windows interlocked functions
  67.  
  68. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:08.252188500Z’/><EventRecordID>3997</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: The InnoDB memory heap is disabled
  69.  
  70. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:08.251187900Z’/><EventRecordID>3996</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Using mutexes to ref count buffer pool pages
  71.  
  72. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:08.227171900Z’/><EventRecordID>3995</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: innodb_empty_free_list_algorithm has been changed to legacy because of small buffer pool size. In order to use backoff, increase buffer pool at least up to 20MB.
  73.  
  74. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:08.148099500Z’/><EventRecordID>3994</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>c:\xampp\mysql\bin\mysqld.exe (mysqld 10.1.16-MariaDB) starting as process 11620 …
  75.  
  76. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:57:08.147098800Z’/><EventRecordID>3993</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Using unique option prefix ‘key_buffer’ is error-prone and can break in the future. Please use the full name ‘key_buffer_size’ instead.
  77.  
  78. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>903</EventID><Version>0</Version><Level>0</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:50.038555100Z’/><EventRecordID>3992</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>16384</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:50.028550000Z’/><EventRecordID>3991</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>2116-09-07T17:55:48Z</Data><Data>RulesEngine</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Perflib’ Guid='{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}’ EventSourceName=’Perflib’/><EventID Qualifiers=’49152′>1008</EventID><Version>0</Version><Level>2</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:41.435770800Z’/><EventRecordID>3990</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><UserData><EventXML xmlns=’Perflib’><param1>BITS</param1><param2>C:\Windows\System32\bitsperf.dll</param2><binaryDataSize>8</binaryDataSize><binaryData>0200000000000000</binaryData></EventXML></UserData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>326</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:32.892922100Z’/><EventRecordID>3989</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>8996</Data><Data>{63FB5B27-837F-49BD-9184-2E5336560ECE}: </Data><Data>1</Data><Data>C:\Users\dpme\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\5585baaf23cd7af2\EntClientDb.edb</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.031, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.</Data><Data>0 0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>105</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:32.861692200Z’/><EventRecordID>3988</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>8996</Data><Data>{63FB5B27-837F-49BD-9184-2E5336560ECE}: </Data><Data>0</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.484, [6] 0.172, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>302</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:32.861692200Z’/><EventRecordID>3987</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>8996</Data><Data>{63FB5B27-837F-49BD-9184-2E5336560ECE}: </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>301</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:32.205043400Z’/><EventRecordID>3986</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>8996</Data><Data>{63FB5B27-837F-49BD-9184-2E5336560ECE}: </Data><Data>C:\Users\dpme\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\5585baaf23cd7af2\edb.log</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>300</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:32.205043400Z’/><EventRecordID>3985</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>8996</Data><Data>{63FB5B27-837F-49BD-9184-2E5336560ECE}: </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>102</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:32.205043400Z’/><EventRecordID>3984</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>8996</Data><Data>{63FB5B27-837F-49BD-9184-2E5336560ECE}: </Data><Data>0</Data><Data>10</Data><Data>00</Data><Data>14393</Data><Data>0000</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>902</EventID><Version>0</Version><Level>0</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:18.347267500Z’/><EventRecordID>3983</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>10.0.14393.206</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>1003</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:16.299257700Z’/><EventRecordID>3982</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>55c92734-d682-4d71-983e-d6ec3f16059f</Data><Data>
  79. 1: 0567073a-7d74-403b-b2d5-6b35da372d8d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  80. 2: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  81. 3: 1b750385-9fe2-49a8-ab55-149d0546395b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  82. 4: 1d873132-f09f-4eb2-bf5a-2e4fb48935e8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  83. 5: 2b1f36bb-c1cd-4306-bf5c-a0367c2d97d8, 1, 0 [(0 )(1 )(2 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)(?)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(3 )]
  84. 6: 30d469c6-a78f-4476-b5c8-af78d5b6a5fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  85. 7: 411b3d4f-be6d-4a06-baaa-9cabfc256cae, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  86. 8: 58e97c99-f377-4ef1-81d5-4ad5522b5fd8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  87. 9: 74436dbb-cc17-46de-867f-14906ba4a938, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  88. 10: 8db63db6-4f8f-46d6-a448-66444faaaa72, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  89. 11: 9e4b231b-3e45-41f4-967f-c914f178b6ac, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  90. 12: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  91. 13: c082c31b-2c4f-4e07-94d7-9181fa802c4b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  92. 14: e371d89a-73e8-4b24-a7ff-23a3641dd18e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  93.  
  94. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>1033</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:16.268009800Z’/><EventRecordID>3981</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>(Security-SPP-Reserved-EnableNotificationMode) </Data><Data>55c92734-d682-4d71-983e-d6ec3f16059f</Data><Data>2b1f36bb-c1cd-4306-bf5c-a0367c2d97d8</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>1034</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:16.268009800Z’/><EventRecordID>3980</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Security-SPP-WriteWauMarker</Data><Data>500</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>1034</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:16.111751800Z’/><EventRecordID>3979</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Telnet-Client-EnableTelnetClient</Data><Data>100</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’SecurityCenter’/><EventID Qualifiers=’0′>15</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:08.753162300Z’/><EventRecordID>3978</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Norton Internet Security</Data><Data>SECURITY_PRODUCT_STATE_ON</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’SecurityCenter’/><EventID Qualifiers=’0′>15</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:08.737533900Z’/><EventRecordID>3977</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Norton Internet Security</Data><Data>SECURITY_PRODUCT_STATE_ON</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’SecurityCenter’/><EventID Qualifiers=’0′>15</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:08.737533900Z’/><EventRecordID>3976</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Norton Internet Security</Data><Data>SECURITY_PRODUCT_STATE_ON</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-LoadPerf’ Guid='{122EE297-BB47-41AE-B265-1CA8D1886D40}’/><EventID>1000</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:55:01.284666400Z’/><EventRecordID>3975</EventRecordID><Correlation/><Execution ProcessID=’6256′ ThreadID=’7456’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security UserID=’S-1-5-18’/></System><UserData><EventXML xmlns=’LoadPerf’><param1>WmiApRpl</param1><param2>WmiApRpl</param2><binaryDataSize>16</binaryDataSize><binaryData>6A2500001C2600006B2500001D260000</binaryData></EventXML></UserData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>1066</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:54:36.284967700Z’/><EventRecordID>3974</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>C:\WINDOWS\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
  95. C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/inherited/1.0, 0x00000000, 0x00000000
  96. C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
  97. C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
  98. C:\WINDOWS\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
  99. C:\WINDOWS\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
  100. C:\WINDOWS\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
  101. C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
  102. C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
  103. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’SecurityCenter’/><EventID Qualifiers=’0′>1</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:54:27.065650500Z’/><EventRecordID>3973</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:53:57.083543900Z’/><EventRecordID>3972</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>C:\Program Files\MySQL\MySQL Server 5.7\bin\mysqld.exe: Normal shutdown
  104. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>900</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:53:56.061865900Z’/><EventRecordID>3971</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data><none></Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Intuit Update Service’/><EventID Qualifiers=’0′>0</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:53:45.829161900Z’/><EventRecordID>3970</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Service started successfully.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’dbupdate’/><EventID Qualifiers=’0′>0</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:50:54.192851200Z’/><EventRecordID>3969</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Service stopped</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Winlogon’ Guid='{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}’ EventSourceName=’Wlclntfy’/><EventID Qualifiers=’32768′>6000</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:49:55.394768200Z’/><EventRecordID>3968</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SessionEnv</Data><Binary>D9060000</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Winlogon’ Guid='{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}’ EventSourceName=’Wlclntfy’/><EventID Qualifiers=’32768′>6003</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:49:53.200173000Z’/><EventRecordID>3967</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SessionEnv</Data><Binary>D9060000</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Search’ Guid='{CA4E628D-8567-4896-AB6B-835B221F373F}’ EventSourceName=’Windows Search Service’/><EventID Qualifiers=’16384′>1003</EventID><Version>0</Version><Level>4</Level><Task>1</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:49:48.902678800Z’/><EventRecordID>3966</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data Name=’ExtraInfo’>
  105. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>326</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:49:47.871379600Z’/><EventRecordID>3965</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SearchIndexer</Data><Data>5348</Data><Data>Windows: </Data><Data>1</Data><Data>C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb</Data><Data>0</Data><Data>[1] 0.000, [2] 0.079, [3] 0.015, [4] 0.000, [5] 0.094, [6] 0.031, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.</Data><Data>0 0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>105</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:49:47.636970300Z’/><EventRecordID>3964</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SearchIndexer</Data><Data>5348</Data><Data>Windows: </Data><Data>0</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.078, [4] 0.047, [5] 0.000, [6] 0.000, [7] 0.047, [8] 0.000, [9] 0.000, [10] 0.000.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>102</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:49:47.511984900Z’/><EventRecordID>3963</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SearchIndexer</Data><Data>5348</Data><Data>Windows: </Data><Data>0</Data><Data>10</Data><Data>00</Data><Data>14393</Data><Data>0000</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-User Profiles Service’ Guid='{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}’/><EventID>1530</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:49:10.713052600Z’/><EventRecordID>3962</EventRecordID><Correlation/><Execution ProcessID=’1488′ ThreadID=’3240’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security UserID=’S-1-5-18’/></System><EventData Name=’EVENT_HIVE_LEAK’><Data Name=’Detail’>3 user registry handles leaked from \Registry\User\S-1-5-21-2896401355-2610082804-351749565-1001:
  106. Process 1692 (\Device\HarddiskVolume3\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.82_none_5be7b69702339d1d\TiWorker.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001
  107. Process 576 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
  108. Process 2436 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Policies\Microsoft\Windows\DataCollection
  109. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-WMI’ Guid='{1EDEEE53-0AFE-4609-B846-D8C0B2075B1F}’/><EventID>63</EventID><Version>2</Version><Level>3</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:49:01.171773100Z’/><EventRecordID>3961</EventRecordID><Correlation/><Execution ProcessID=’1488′ ThreadID=’3240’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security UserID=’S-1-5-18’/></System><UserData><data_0x8000003F xmlns=’http://manifests.microsoft.com/win/2006/windows/WMI’><Provider>WsmAgent</Provider><Namespace>root\Microsoft\Windows\winrm</Namespace></data_0x8000003F></UserData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-WMI’ Guid='{1EDEEE53-0AFE-4609-B846-D8C0B2075B1F}’/><EventID>63</EventID><Version>2</Version><Level>3</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:49:01.157667800Z’/><EventRecordID>3960</EventRecordID><Correlation/><Execution ProcessID=’1488′ ThreadID=’1320’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security UserID=’S-1-5-18’/></System><UserData><data_0x8000003F xmlns=’http://manifests.microsoft.com/win/2006/windows/WMI’><Provider>WsmAgent</Provider><Namespace>root\Microsoft\Windows\winrm</Namespace></data_0x8000003F></UserData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’CTTaskerSvc’/><EventID Qualifiers=’0′>1</EventID><Level>2</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:50.366538700Z’/><EventRecordID>3959</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Service starting failed : “Access violation at address 004AA614 in module ‘CTTasker.Exe’. Read of address 00000008″</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:42.599785700Z’/><EventRecordID>3958</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>C:\Program Files\MySQL\MySQL Server 5.7\bin\mysqld.exe: ready for connections.
  110. Version: ‘5.7.10-log’ socket: ” port: 3306 MySQL Community Server (GPL)</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:42.599785700Z’/><EventRecordID>3957</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Event Scheduler: Loaded 0 events</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:41.427565300Z’/><EventRecordID>3956</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Server socket created on IP: ‘::’.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:41.427565300Z’/><EventRecordID>3955</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data> – ‘::’ resolves to ‘::’;</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:41.427565300Z’/><EventRecordID>3954</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>IPv6 is available.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:41.427565300Z’/><EventRecordID>3953</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Server hostname (bind-address): ‘*’; port: 3306</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>3</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:41.427565300Z’/><EventRecordID>3952</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Failed to set up SSL because of the following SSL library error: SSL context is not usable without certificate and private key</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:40.708781000Z’/><EventRecordID>3951</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Buffer pool(s) load completed at 161001 12:48:40</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:40.036694400Z’/><EventRecordID>3950</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Plugin ‘FEDERATED’ is disabled.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:39.552226500Z’/><EventRecordID>3949</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: not started</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:39.380134900Z’/><EventRecordID>3948</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Loading buffer pool(s) from C:\ProgramData\MySQL\MySQL Server 5.7\Data\ib_buffer_pool</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:39.364528700Z’/><EventRecordID>3947</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: 5.7.10 started; log sequence number 144276370</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:39.364528700Z’/><EventRecordID>3946</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: page_cleaner: 1000ms intended loop took 15617ms. The settings might not be optimal. (flushed=0 and evicted=0, during the time.)</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:39.302025700Z’/><EventRecordID>3945</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Waiting for purge to start</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:39.239449300Z’/><EventRecordID>3944</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Waiting for purge to start</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:39.161329300Z’/><EventRecordID>3943</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Waiting for purge to start</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:39.161329300Z’/><EventRecordID>3942</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: 32 non-redo rollback segment(s) are active.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:39.161329300Z’/><EventRecordID>3941</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: 96 redo rollback segment(s) found. 96 redo rollback segment(s) are active.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:39.114451000Z’/><EventRecordID>3940</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: File ‘.\ibtmp1′ size is now 12 MB.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:38.473796500Z’/><EventRecordID>3939</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Setting file ‘.\ibtmp1′ size to 12 MB. Physically writing the file full; Please wait …</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:38.473796500Z’/><EventRecordID>3938</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Creating shared tablespace for temporary tables</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:25.267832200Z’/><EventRecordID>3937</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Highest supported file format is Barracuda.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’CTTaskerSvc’/><EventID Qualifiers=’0′>0</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:24.591611500Z’/><EventRecordID>3936</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Captools/net Automatic Tasker Service starting.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’CTTaskerSvc’/><EventID Qualifiers=’0′>0</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:24.591611500Z’/><EventRecordID>3935</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Extended handler is registered</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’CTTaskerSvc’/><EventID Qualifiers=’0′>0</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:24.575700000Z’/><EventRecordID>3934</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Debug : NtServiceCreate – Done</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’PostgreSQL’/><EventID Qualifiers=’0′>0</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:23.997570000Z’/><EventRecordID>3933</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Server started and accepting connections
  111. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:23.747532900Z’/><EventRecordID>3932</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Completed initialization of buffer pool</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:23.638177300Z’/><EventRecordID>3931</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Initializing buffer pool, total size = 8M, instances = 1, chunk size = 8M</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:23.216280100Z’/><EventRecordID>3930</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Not using CPU crc32 instructions</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:22.403449300Z’/><EventRecordID>3929</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Number of pools: 1</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’PostgreSQL’/><EventID Qualifiers=’0′>0</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:22.294076300Z’/><EventRecordID>3928</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>2016-10-01 12:48:22 CDT LOG: redirecting log output to logging collector process
  112. 2016-10-01 12:48:22 CDT HINT: Future log output will appear in directory “pg_log”.
  113. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:21.700295900Z’/><EventRecordID>3927</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Adjusting innodb_buffer_pool_instances from 8 to 1 since innodb_buffer_pool_size is less than 1024 MiB</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:21.700295900Z’/><EventRecordID>3926</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Compressed tables use zlib 1.2.3</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:21.700295900Z’/><EventRecordID>3925</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: _mm_lfence() and _mm_sfence() are used for memory barrier</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:21.700295900Z’/><EventRecordID>3924</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Uses event mutexes</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:21.700295900Z’/><EventRecordID>3923</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Mutexes and rw_locks use Windows interlocked functions</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-WMI’ Guid='{1EDEEE53-0AFE-4609-B846-D8C0B2075B1F}’/><EventID>5617</EventID><Version>2</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:19.728667000Z’/><EventRecordID>3922</EventRecordID><Correlation/><Execution ProcessID=’1488′ ThreadID=’3760’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security UserID=’S-1-5-18’/></System><EventData></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’PostgreSQL’/><EventID Qualifiers=’0′>0</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:17.027752000Z’/><EventRecordID>3921</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Waiting for server startup…
  114. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:11.964264300Z’/><EventRecordID>3920</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>C:\Program Files\MySQL\MySQL Server 5.7\bin\mysqld.exe (mysqld 5.7.10-log) starting as process 3064 …</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’NIS’/><EventID Qualifiers=’16384′>35</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:07.576466600Z’/><EventRecordID>3919</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security UserID=’S-1-5-18’/></System><EventData><Data>NIS</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’AirPrint’/><EventID Qualifiers=’0′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:07.076172300Z’/><EventRecordID>3918</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Unable to remove “C:\WINDOWS\TEMP\/cupslite/cupslite” – No such file or directory</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’AirPrint’/><EventID Qualifiers=’0′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:07.076172300Z’/><EventRecordID>3917</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Listening for connections on [::1]:631…</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’AirPrint’/><EventID Qualifiers=’0′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:07.076172300Z’/><EventRecordID>3916</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Listening for connections on 0.0.0.0:631…</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’NIS’/><EventID Qualifiers=’16384′>34</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:01.466314100Z’/><EventRecordID>3915</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security UserID=’S-1-5-18’/></System><EventData><Data>NIS</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’AdobeARMservice’/><EventID Qualifiers=’0′>0</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:48:00.399707400Z’/><EventRecordID>3914</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Service started</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’SQLBrowser’/><EventID Qualifiers=’78’>12</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:47:55.181702300Z’/><EventRecordID>3913</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’SQLBrowser’/><EventID Qualifiers=’16462′>16</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:47:55.181702300Z’/><EventRecordID>3912</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Bonjour Service’/><EventID Qualifiers=’0′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:47:50.759618800Z’/><EventRecordID>3911</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Service started
  115. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Bonjour Service’/><EventID Qualifiers=’0′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:47:50.462744000Z’/><EventRecordID>3910</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Service initialized</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-WMI’ Guid='{1EDEEE53-0AFE-4609-B846-D8C0B2075B1F}’/><EventID>5615</EventID><Version>2</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:47:49.448944000Z’/><EventRecordID>3909</EventRecordID><Correlation/><Execution ProcessID=’1488′ ThreadID=’2608’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security UserID=’S-1-5-18’/></System><EventData></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Bonjour Service’/><EventID Qualifiers=’0′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:47:49.775202000Z’/><EventRecordID>3908</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Service initializing</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’DbxSvc’/><EventID Qualifiers=’16386′>258</EventID><Level>4</Level><Task>2</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:47:49.572066800Z’/><EventRecordID>3907</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’DbxSvc’/><EventID Qualifiers=’16386′>256</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:47:48.118871900Z’/><EventRecordID>3906</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-User Profiles Service’ Guid='{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}’/><EventID>1531</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:47:28.188280000Z’/><EventRecordID>3905</EventRecordID><Correlation/><Execution ProcessID=’1488′ ThreadID=’1564’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security UserID=’S-1-5-18’/></System><EventData></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-EventSystem’ Guid='{899daace-4868-4295-afcd-9eb8fb497561}’ EventSourceName=’EventSystem’/><EventID Qualifiers=’16384′>4625</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:47:33.965852500Z’/><EventRecordID>3904</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data Name=’param1′>86400</Data><Data Name=’param2′>SuppressDuplicateDuration</Data><Data Name=’param3′>Software\Microsoft\EventSystem\EventLog</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-User Profiles Service’ Guid='{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}’/><EventID>1532</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:46:06.639519600Z’/><EventRecordID>3903</EventRecordID><Correlation/><Execution ProcessID=’1036′ ThreadID=’1400’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security UserID=’S-1-5-18’/></System><EventData></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’SQLBrowser’/><EventID Qualifiers=’78’>13</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:46:06.124932000Z’/><EventRecordID>3902</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’VSS’/><EventID Qualifiers=’0′>8225</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:46:05.984277400Z’/><EventRecordID>3901</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data></Data><Binary>2D20436F64653A2020434F525356434330303030303735382D2043616C6C3A2020434F525356434330303030303734322D205049443A202030303030373434342D205449443A202030303030323937322D20434D443A2020433A5C57494E444F57535C73797374656D33325C76737376632E6578652020202D20557365723A204E616D653A204E5420415554484F524954595C53595354454D2C205349443A532D312D352D313820</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’NIS’/><EventID Qualifiers=’16384′>36</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:46:05.953026300Z’/><EventRecordID>3900</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security UserID=’S-1-5-18’/></System><EventData><Data>NIS</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MSSQL$CAPTOOLSDBINST’/><EventID Qualifiers=’16384′>17147</EventID><Level>4</Level><Task>2</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:46:05.640318700Z’/><EventRecordID>3899</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Binary>FB4200000A0000001D0000004D00450049004E004500520054004C004100500054004F0050005C0043004100500054004F004F004C0053004400420049004E0053005400000000000000</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-User Profiles Service’ Guid='{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}’/><EventID>1530</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:41:54.423215500Z’/><EventRecordID>3898</EventRecordID><Correlation/><Execution ProcessID=’1036′ ThreadID=’12348’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security UserID=’S-1-5-18’/></System><EventData Name=’EVENT_HIVE_LEAK’><Data Name=’Detail’>2 user registry handles leaked from \Registry\User\S-1-5-21-2896401355-2610082804-351749565-1001_Classes:
  116. Process 6108 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001_Classes
  117. Process 6108 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001_Classes
  118. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-User Profiles Service’ Guid='{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}’/><EventID>1530</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:41:53.299935100Z’/><EventRecordID>3897</EventRecordID><Correlation/><Execution ProcessID=’1036′ ThreadID=’12348’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security UserID=’S-1-5-18’/></System><EventData Name=’EVENT_HIVE_LEAK’><Data Name=’Detail’>70 user registry handles leaked from \Registry\User\S-1-5-21-2896401355-2610082804-351749565-1001:
  119. Process 1036 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001
  120. Process 816 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001
  121. Process 816 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001
  122. Process 816 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001
  123. Process 816 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001
  124. Process 1036 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001
  125. Process 1036 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001
  126. Process 1036 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001
  127. Process 1036 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001
  128. Process 1036 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\SystemCertificates\CA
  129. Process 816 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\SystemCertificates\CA
  130. Process 916 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\System\GameConfigStore\Parents
  131. Process 6108 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\CommsAPHost\Test
  132. Process 6108 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\CommsAPHost\Test
  133. Process 816 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Policies\Microsoft\SystemCertificates
  134. Process 816 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Policies\Microsoft\SystemCertificates
  135. Process 1036 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Policies\Microsoft\SystemCertificates
  136. Process 1036 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Policies\Microsoft\SystemCertificates
  137. Process 1036 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Policies\Microsoft\SystemCertificates
  138. Process 1036 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Policies\Microsoft\SystemCertificates
  139. Process 816 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Policies\Microsoft\SystemCertificates
  140. Process 816 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Policies\Microsoft\SystemCertificates
  141. Process 1036 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\SystemCertificates\trust
  142. Process 816 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\SystemCertificates\trust
  143. Process 916 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\System\GameConfigStore
  144. Process 596 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
  145. Process 6108 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
  146. Process 2944 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
  147. Process 1328 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
  148. Process 6876 (\Device\HarddiskVolume3\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
  149. Process 2312 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
  150. Process 6108 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
  151. Process 1036 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople
  152. Process 816 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople
  153. Process 6108 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Unified Store\HighWaterMarks\C:_Users_dpme_AppData_Local_Comms_UnistoreDB_store.vol
  154. Process 6876 (\Device\HarddiskVolume3\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Xerox\PrinterDriver\V5.0\NamedSettings\UNIV
  155. Process 2944 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl
  156. Process 1328 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl
  157. Process 6876 (\Device\HarddiskVolume3\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl
  158. Process 2312 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl
  159. Process 6108 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl
  160. Process 2312 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Policies\Microsoft\Windows\DataCollection
  161. Process 2944 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  162. Process 1328 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  163. Process 6876 (\Device\HarddiskVolume3\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  164. Process 2312 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  165. Process 6108 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  166. Process 2944 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Internet Explorer\Main
  167. Process 1328 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Internet Explorer\Main
  168. Process 6876 (\Device\HarddiskVolume3\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Internet Explorer\Main
  169. Process 2312 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Internet Explorer\Main
  170. Process 6108 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Internet Explorer\Main
  171. Process 6108 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\ActiveSync\JobDispatcher\JobRegistry\1.1
  172. Process 6108 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\ActiveSync\Partners
  173. Process 1036 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\SystemCertificates\Disallowed
  174. Process 816 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\SystemCertificates\Disallowed
  175. Process 1036 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\SystemCertificates\Root
  176. Process 816 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\SystemCertificates\Root
  177. Process 916 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\System\GameConfigStore\Children
  178. Process 2944 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Internet Explorer\Security
  179. Process 1328 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Internet Explorer\Security
  180. Process 6876 (\Device\HarddiskVolume3\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Internet Explorer\Security
  181. Process 2312 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Internet Explorer\Security
  182. Process 6108 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Internet Explorer\Security
  183. Process 816 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\SystemCertificates\MY
  184. Process 6108 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
  185. Process 1036 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
  186. Process 1036 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot
  187. Process 816 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot
  188. Process 6876 (\Device\HarddiskVolume3\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2896401355-2610082804-351749565-1001\SOFTWARE\Xerox\PrinterDriver\V5.0\ApplicationDefaults\UNIV
  189. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Winlogon’ Guid='{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}’ EventSourceName=’Wlclntfy’/><EventID Qualifiers=’32768′>6000</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:41:52.361317300Z’/><EventRecordID>3896</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SessionEnv</Data><Binary>D9060000</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Windows Error Reporting’/><EventID Qualifiers=’0′>1001</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:40:20.125801300Z’/><EventRecordID>3895</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>120515319193</Data><Data>4</Data><Data>APPCRASH</Data><Data>Not available</Data><Data>0</Data><Data>Explorer.EXE</Data><Data>10.0.14393.0</Data><Data>57899981</Data><Data>msvcrt.dll</Data><Data>7.0.14393.0</Data><Data>57899b47</Data><Data>40000015</Data><Data>000000000000c2c2</Data><Data></Data><Data></Data><Data>
  190. \\?\C:\Users\dpme\AppData\Local\Temp\WER3B99.tmp.appcompat.txt
  191. \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3C36.tmp.WERInternalMetadata.xml
  192. C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Explorer.EXE_e96413ae45ea21d96a967674a3a4edaebb61adb_92b00e4f_cab_0b743c63\memory.hdmp
  193. C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Explorer.EXE_e96413ae45ea21d96a967674a3a4edaebb61adb_92b00e4f_cab_0b743c63\triagedump.dmp</Data><Data>C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Explorer.EXE_e96413ae45ea21d96a967674a3a4edaebb61adb_92b00e4f_0a314289</Data><Data></Data><Data>0</Data><Data>1d61d3f3-08c6-401a-a0eb-79a0e402d853</Data><Data>0</Data><Data>c5f49c998213e779405eebe130d7c0e1</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Windows Error Reporting’/><EventID Qualifiers=’0′>1001</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:40:19.022479900Z’/><EventRecordID>3894</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data></Data><Data>0</Data><Data>APPCRASH</Data><Data>Not available</Data><Data>0</Data><Data>Explorer.EXE</Data><Data>10.0.14393.0</Data><Data>57899981</Data><Data>msvcrt.dll</Data><Data>7.0.14393.0</Data><Data>57899b47</Data><Data>40000015</Data><Data>000000000000c2c2</Data><Data></Data><Data></Data><Data>
  194. \\?\C:\Users\dpme\AppData\Local\Temp\WER3B99.tmp.appcompat.txt
  195. \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER3C36.tmp.WERInternalMetadata.xml
  196. C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Explorer.EXE_e96413ae45ea21d96a967674a3a4edaebb61adb_92b00e4f_cab_0b743c63\memory.hdmp
  197. C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Explorer.EXE_e96413ae45ea21d96a967674a3a4edaebb61adb_92b00e4f_cab_0b743c63\triagedump.dmp</Data><Data>C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Explorer.EXE_e96413ae45ea21d96a967674a3a4edaebb61adb_92b00e4f_cab_0b743c63</Data><Data></Data><Data>0</Data><Data>1d61d3f3-08c6-401a-a0eb-79a0e402d853</Data><Data>4</Data><Data></Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:40.209478800Z’/><EventRecordID>3893</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>c:\xampp\mysql\bin\mysqld.exe: ready for connections.
  198. Version: ‘10.1.16-MariaDB’ socket: ” port: 3307 mariadb.org binary distribution
  199.  
  200. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>2</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:39.893006100Z’/><EventRecordID>3892</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>mysql.procs_priv: 1 client is using or hasn’t closed the table properly
  201.  
  202. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>3</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:39.891506200Z’/><EventRecordID>3891</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Checking table: ‘.\mysql\procs_priv’
  203.  
  204. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>2</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:39.890006700Z’/><EventRecordID>3890</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>mysqld.exe: Table ‘.\mysql\procs_priv’ is marked as crashed and should be repaired
  205.  
  206. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>2</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:39.704032100Z’/><EventRecordID>3889</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>mysql.columns_priv: 1 client is using or hasn’t closed the table properly
  207.  
  208. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>3</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:39.703031400Z’/><EventRecordID>3888</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Checking table: ‘.\mysql\columns_priv’
  209.  
  210. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>2</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:39.700527200Z’/><EventRecordID>3887</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>mysqld.exe: Table ‘.\mysql\columns_priv’ is marked as crashed and should be repaired
  211.  
  212. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>2</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:39.538903200Z’/><EventRecordID>3886</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>mysql.tables_priv: 1 client is using or hasn’t closed the table properly
  213.  
  214. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>3</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:39.537902500Z’/><EventRecordID>3885</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Checking table: ‘.\mysql\tables_priv’
  215.  
  216. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>2</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:39.535901200Z’/><EventRecordID>3884</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>mysqld.exe: Table ‘.\mysql\tables_priv’ is marked as crashed and should be repaired
  217.  
  218. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>2</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:39.072319900Z’/><EventRecordID>3883</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>mysql.db: 1 client is using or hasn’t closed the table properly
  219.  
  220. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>3</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:39.070319100Z’/><EventRecordID>3882</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Checking table: ‘.\mysql\db’
  221.  
  222. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>2</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:39.068317200Z’/><EventRecordID>3881</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>mysqld.exe: Table ‘.\mysql\db’ is marked as crashed and should be repaired
  223.  
  224. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:38.913942700Z’/><EventRecordID>3880</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Server socket created on IP: ‘::’.
  225.  
  226. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:38.764716300Z’/><EventRecordID>3879</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Plugin ‘FEEDBACK’ is disabled.
  227.  
  228. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:38.649434600Z’/><EventRecordID>3878</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Dumping buffer pool(s) not yet started
  229.  
  230. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:37.973657500Z’/><EventRecordID>3877</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Percona XtraDB (http://www.percona.com) 5.6.30-76.3 started; log sequence number 4604849
  231.  
  232. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:37.825134600Z’/><EventRecordID>3876</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Waiting for purge to start
  233.  
  234. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:37.824132900Z’/><EventRecordID>3875</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: 128 rollback segment(s) are active.
  235.  
  236. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:35.279190600Z’/><EventRecordID>3874</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: from the doublewrite buffer…
  237.  
  238. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:35.278189400Z’/><EventRecordID>3873</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Restoring possible half-written data pages
  239.  
  240. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:33.064476200Z’/><EventRecordID>3872</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Reading tablespace information from the .ibd files…
  241.  
  242. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:33.062976200Z’/><EventRecordID>3871</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Starting crash recovery.
  243.  
  244. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:33.062474900Z’/><EventRecordID>3870</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Database was not shutdown normally!
  245.  
  246. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:33.060973900Z’/><EventRecordID>3869</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: The log sequence numbers 4597340 and 4597340 in ibdata files do not match the log sequence number 4604849 in the ib_logfiles!
  247.  
  248. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:33.012941200Z’/><EventRecordID>3868</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Highest supported file format is Barracuda.
  249.  
  250. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:32.517913800Z’/><EventRecordID>3867</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Completed initialization of buffer pool
  251.  
  252. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:32.505407500Z’/><EventRecordID>3866</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Initializing buffer pool, size = 16.0M
  253.  
  254. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:32.477887000Z’/><EventRecordID>3865</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Using generic crc32 instructions
  255.  
  256. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:32.255230900Z’/><EventRecordID>3864</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Compressed tables use zlib 1.2.3
  257.  
  258. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:32.254222100Z’/><EventRecordID>3863</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Memory barrier is not used
  259.  
  260. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:32.253221400Z’/><EventRecordID>3862</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Mutexes and rw_locks use Windows interlocked functions
  261.  
  262. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:32.252218700Z’/><EventRecordID>3861</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: The InnoDB memory heap is disabled
  263.  
  264. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:32.251220100Z’/><EventRecordID>3860</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: Using mutexes to ref count buffer pool pages
  265.  
  266. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:32.053608400Z’/><EventRecordID>3859</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>InnoDB: innodb_empty_free_list_algorithm has been changed to legacy because of small buffer pool size. In order to use backoff, increase buffer pool at least up to 20MB.
  267.  
  268. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:30.159659900Z’/><EventRecordID>3858</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>c:\xampp\mysql\bin\mysqld.exe (mysqld 10.1.16-MariaDB) starting as process 14144 …
  269.  
  270. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:30.142173300Z’/><EventRecordID>3857</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Using unique option prefix ‘key_buffer’ is error-prone and can break in the future. Please use the full name ‘key_buffer_size’ instead.
  271.  
  272. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Winlogon’ Guid='{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}’ EventSourceName=’Winlogon’/><EventID Qualifiers=’16384′>1002</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:14.589645300Z’/><EventRecordID>3856</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>explorer.exe</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Application Error’/><EventID Qualifiers=’0′>1000</EventID><Level>2</Level><Task>100</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:39:10.648469300Z’/><EventRecordID>3855</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Explorer.EXE</Data><Data>10.0.14393.0</Data><Data>57899981</Data><Data>msvcrt.dll</Data><Data>7.0.14393.0</Data><Data>57899b47</Data><Data>40000015</Data><Data>000000000000c2c2</Data><Data>180c</Data><Data>01d216dc04adab1b</Data><Data>C:\WINDOWS\Explorer.EXE</Data><Data>C:\WINDOWS\System32\msvcrt.dll</Data><Data>1d61d3f3-08c6-401a-a0eb-79a0e402d853</Data><Data></Data><Data></Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’MySQL’/><EventID Qualifiers=’49152′>100</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T17:34:34.899118400Z’/><EventRecordID>3854</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>C:\Program Files\MySQL\MySQL Server 5.7\bin\mysqld.exe: Normal shutdown
  273. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’dbupdate’/><EventID Qualifiers=’0′>0</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T16:59:03.312970600Z’/><EventRecordID>3853</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Service stopped</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’dbupdate’/><EventID Qualifiers=’0′>0</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T16:59:02.472057500Z’/><EventRecordID>3852</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Service started</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>326</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T16:21:04.440265400Z’/><EventRecordID>3851</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>9396</Data><Data>{EF1053A8-CC4F-443A-BF1B-359428F71F3A}: </Data><Data>1</Data><Data>C:\Users\dpme\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\5585baaf23cd7af2\EntClientDb.edb</Data><Data>0</Data><Data>[1] 0.000, [2] 0.016, [3] 0.062, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.</Data><Data>0 0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>105</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T16:21:04.373228300Z’/><EventRecordID>3850</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>9396</Data><Data>{EF1053A8-CC4F-443A-BF1B-359428F71F3A}: </Data><Data>0</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.015, [6] 0.438, [7] 0.031, [8] 0.000, [9] 0.000, [10] 0.000.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>302</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T16:21:04.339159400Z’/><EventRecordID>3849</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>9396</Data><Data>{EF1053A8-CC4F-443A-BF1B-359428F71F3A}: </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>301</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T16:21:03.890889900Z’/><EventRecordID>3848</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>9396</Data><Data>{EF1053A8-CC4F-443A-BF1B-359428F71F3A}: </Data><Data>C:\Users\dpme\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\5585baaf23cd7af2\edb.log</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>300</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T16:21:03.887887900Z’/><EventRecordID>3847</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>9396</Data><Data>{EF1053A8-CC4F-443A-BF1B-359428F71F3A}: </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>102</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T16:21:03.883384300Z’/><EventRecordID>3846</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>9396</Data><Data>{EF1053A8-CC4F-443A-BF1B-359428F71F3A}: </Data><Data>0</Data><Data>10</Data><Data>00</Data><Data>14393</Data><Data>0000</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Perflib’ Guid='{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}’ EventSourceName=’Perflib’/><EventID Qualifiers=’49152′>1023</EventID><Version>0</Version><Level>2</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T15:55:34.015667100Z’/><EventRecordID>3845</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><UserData><EventXML xmlns=’Perflib’><param1>W3SVC</param1><binaryDataSize>8</binaryDataSize><binaryData>7E00000000000000</binaryData></EventXML></UserData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Perflib’ Guid='{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}’ EventSourceName=’Perflib’/><EventID Qualifiers=’49152′>1008</EventID><Version>0</Version><Level>2</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T15:55:33.899589500Z’/><EventRecordID>3844</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><UserData><EventXML xmlns=’Perflib’><param1>aspnet_state</param1><param2>C:\Windows\System32\aspnet_counters.dll</param2><binaryDataSize>8</binaryDataSize><binaryData>5700078000000000</binaryData></EventXML></UserData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Perflib’ Guid='{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}’ EventSourceName=’Perflib’/><EventID Qualifiers=’49152′>1023</EventID><Version>0</Version><Level>2</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T15:55:33.898589900Z’/><EventRecordID>3843</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><UserData><EventXML xmlns=’Perflib’><param1>ASP.NET_64_2.0.50727</param1><binaryDataSize>8</binaryDataSize><binaryData>7E00000000000000</binaryData></EventXML></UserData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Perflib’ Guid='{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}’ EventSourceName=’Perflib’/><EventID Qualifiers=’49152′>1008</EventID><Version>0</Version><Level>2</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T15:55:33.898086000Z’/><EventRecordID>3842</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><UserData><EventXML xmlns=’Perflib’><param1>ASP.NET_4.0.30319</param1><param2>C:\Windows\System32\aspnet_counters.dll</param2><binaryDataSize>8</binaryDataSize><binaryData>5700078000000000</binaryData></EventXML></UserData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Perflib’ Guid='{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}’ EventSourceName=’Perflib’/><EventID Qualifiers=’49152′>1008</EventID><Version>0</Version><Level>2</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T15:55:33.896588000Z’/><EventRecordID>3841</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><UserData><EventXML xmlns=’Perflib’><param1>ASP.NET</param1><param2>C:\Windows\System32\aspnet_counters.dll</param2><binaryDataSize>8</binaryDataSize><binaryData>5700078000000000</binaryData></EventXML></UserData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Perflib’ Guid='{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}’ EventSourceName=’Perflib’/><EventID Qualifiers=’49152′>1023</EventID><Version>0</Version><Level>2</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T15:55:33.853125600Z’/><EventRecordID>3840</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><UserData><EventXML xmlns=’Perflib’><param1>ASP</param1><binaryDataSize>8</binaryDataSize><binaryData>7E00000000000000</binaryData></EventXML></UserData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’VSS’/><EventID Qualifiers=’0′>8224</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T15:36:42.933455800Z’/><EventRecordID>3839</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data></Data><Binary>2D20436F64653A2020434F525356434330303030303736302D2043616C6C3A2020434F525356434330303030303734322D205049443A202030303031363632382D205449443A202030303030383634382D20434D443A2020433A5C57494E444F57535C73797374656D33325C76737376632E6578652020202D20557365723A204E616D653A204E5420415554484F524954595C53595354454D2C205349443A532D312D352D313820</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’System Restore’/><EventID Qualifiers=’0′>8216</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T15:33:43.255073900Z’/><EventRecordID>3838</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>C:\WINDOWS\system32\svchost.exe -k netsvcs</Data><Data>Windows Update</Data><Binary>00000000550200004B0200000000000022CE28677C6DDA79E28C1C000000000000000000</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>326</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T13:21:04.421980400Z’/><EventRecordID>3837</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>15876</Data><Data>{B67B94CE-8696-494D-AD3D-5D710E3FCDC7}: </Data><Data>1</Data><Data>C:\Users\dpme\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\5585baaf23cd7af2\EntClientDb.edb</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.141, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.</Data><Data>0 0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>105</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T13:21:04.272739600Z’/><EventRecordID>3836</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>15876</Data><Data>{B67B94CE-8696-494D-AD3D-5D710E3FCDC7}: </Data><Data>0</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.109, [6] 0.516, [7] 0.015, [8] 0.000, [9] 0.000, [10] 0.000.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>302</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T13:21:04.264825600Z’/><EventRecordID>3835</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>15876</Data><Data>{B67B94CE-8696-494D-AD3D-5D710E3FCDC7}: </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>301</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T13:21:03.640169900Z’/><EventRecordID>3834</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>15876</Data><Data>{B67B94CE-8696-494D-AD3D-5D710E3FCDC7}: </Data><Data>C:\Users\dpme\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\5585baaf23cd7af2\edb.log</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>300</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T13:21:03.638167500Z’/><EventRecordID>3833</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>15876</Data><Data>{B67B94CE-8696-494D-AD3D-5D710E3FCDC7}: </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>102</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T13:21:03.633164700Z’/><EventRecordID>3832</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>15876</Data><Data>{B67B94CE-8696-494D-AD3D-5D710E3FCDC7}: </Data><Data>0</Data><Data>10</Data><Data>00</Data><Data>14393</Data><Data>0000</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’dbupdate’/><EventID Qualifiers=’0′>0</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T11:59:33.545132500Z’/><EventRecordID>3831</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Service stopped</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’dbupdate’/><EventID Qualifiers=’0′>0</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T11:59:32.805863300Z’/><EventRecordID>3830</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Service started</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>326</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T10:21:05.799702200Z’/><EventRecordID>3829</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>14144</Data><Data>{8AC30C4D-FEF0-47F2-A4A2-92D744869510}: </Data><Data>1</Data><Data>C:\Users\dpme\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\5585baaf23cd7af2\EntClientDb.edb</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.016, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.</Data><Data>0 0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>105</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T10:21:05.790195300Z’/><EventRecordID>3828</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>14144</Data><Data>{8AC30C4D-FEF0-47F2-A4A2-92D744869510}: </Data><Data>0</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.015, [4] 0.000, [5] 0.125, [6] 0.344, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>302</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T10:21:05.785192500Z’/><EventRecordID>3827</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>14144</Data><Data>{8AC30C4D-FEF0-47F2-A4A2-92D744869510}: </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>301</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T10:21:05.318881700Z’/><EventRecordID>3826</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>14144</Data><Data>{8AC30C4D-FEF0-47F2-A4A2-92D744869510}: </Data><Data>C:\Users\dpme\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\5585baaf23cd7af2\edb.log</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>300</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T10:21:05.316879300Z’/><EventRecordID>3825</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>14144</Data><Data>{8AC30C4D-FEF0-47F2-A4A2-92D744869510}: </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>102</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T10:21:05.312376300Z’/><EventRecordID>3824</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>14144</Data><Data>{8AC30C4D-FEF0-47F2-A4A2-92D744869510}: </Data><Data>0</Data><Data>10</Data><Data>00</Data><Data>14393</Data><Data>0000</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>903</EventID><Version>0</Version><Level>0</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T09:17:57.291153400Z’/><EventRecordID>3823</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>16384</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T09:17:57.284651600Z’/><EventRecordID>3822</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>2116-09-07T09:17:57Z</Data><Data>RulesEngine</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>902</EventID><Version>0</Version><Level>0</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T09:17:27.068514800Z’/><EventRecordID>3821</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>10.0.14393.187</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>1003</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T09:17:27.037494100Z’/><EventRecordID>3820</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>55c92734-d682-4d71-983e-d6ec3f16059f</Data><Data>
  274. 1: 0567073a-7d74-403b-b2d5-6b35da372d8d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  275. 2: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  276. 3: 1b750385-9fe2-49a8-ab55-149d0546395b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  277. 4: 1d873132-f09f-4eb2-bf5a-2e4fb48935e8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  278. 5: 2b1f36bb-c1cd-4306-bf5c-a0367c2d97d8, 1, 1 [(0 )(1 )(2 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)(?)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(3 )]
  279. 6: 30d469c6-a78f-4476-b5c8-af78d5b6a5fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  280. 7: 411b3d4f-be6d-4a06-baaa-9cabfc256cae, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  281. 8: 58e97c99-f377-4ef1-81d5-4ad5522b5fd8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  282. 9: 74436dbb-cc17-46de-867f-14906ba4a938, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  283. 10: 8db63db6-4f8f-46d6-a448-66444faaaa72, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  284. 11: 9e4b231b-3e45-41f4-967f-c914f178b6ac, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  285. 12: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  286. 13: c082c31b-2c4f-4e07-94d7-9181fa802c4b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  287. 14: e371d89a-73e8-4b24-a7ff-23a3641dd18e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  288.  
  289. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>1066</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T09:17:26.980455400Z’/><EventRecordID>3819</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>C:\WINDOWS\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
  290. C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/inherited/1.0, 0x00000000, 0x00000000
  291. C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
  292. C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
  293. C:\WINDOWS\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
  294. C:\WINDOWS\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
  295. C:\WINDOWS\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
  296. C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
  297. C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
  298. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>900</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T09:17:26.894397800Z’/><EventRecordID>3818</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>caller=devicecensus.exe</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>903</EventID><Version>0</Version><Level>0</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T08:28:46.582903400Z’/><EventRecordID>3817</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>16384</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T08:28:46.576394400Z’/><EventRecordID>3816</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>2116-09-07T08:28:46Z</Data><Data>RulesEngine</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>902</EventID><Version>0</Version><Level>0</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T08:28:16.305953600Z’/><EventRecordID>3815</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>10.0.14393.187</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>1003</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T08:28:16.270930700Z’/><EventRecordID>3814</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>55c92734-d682-4d71-983e-d6ec3f16059f</Data><Data>
  299. 1: 0567073a-7d74-403b-b2d5-6b35da372d8d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  300. 2: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  301. 3: 1b750385-9fe2-49a8-ab55-149d0546395b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  302. 4: 1d873132-f09f-4eb2-bf5a-2e4fb48935e8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  303. 5: 2b1f36bb-c1cd-4306-bf5c-a0367c2d97d8, 1, 1 [(0 )(1 )(2 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)(?)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(3 )]
  304. 6: 30d469c6-a78f-4476-b5c8-af78d5b6a5fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  305. 7: 411b3d4f-be6d-4a06-baaa-9cabfc256cae, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  306. 8: 58e97c99-f377-4ef1-81d5-4ad5522b5fd8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  307. 9: 74436dbb-cc17-46de-867f-14906ba4a938, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  308. 10: 8db63db6-4f8f-46d6-a448-66444faaaa72, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  309. 11: 9e4b231b-3e45-41f4-967f-c914f178b6ac, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  310. 12: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  311. 13: c082c31b-2c4f-4e07-94d7-9181fa802c4b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  312. 14: e371d89a-73e8-4b24-a7ff-23a3641dd18e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  313.  
  314. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>1066</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T08:28:16.213895100Z’/><EventRecordID>3813</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>C:\WINDOWS\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
  315. C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/inherited/1.0, 0x00000000, 0x00000000
  316. C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
  317. C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
  318. C:\WINDOWS\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
  319. C:\WINDOWS\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
  320. C:\WINDOWS\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
  321. C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
  322. C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
  323. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>900</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T08:28:16.126336500Z’/><EventRecordID>3812</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>caller=CompatTelRunner.exe</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>903</EventID><Version>0</Version><Level>0</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T07:45:18.122414900Z’/><EventRecordID>3811</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>16384</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T07:45:18.072211100Z’/><EventRecordID>3810</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>2116-09-07T07:45:17Z</Data><Data>RulesEngine</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>902</EventID><Version>0</Version><Level>0</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T07:44:47.715038900Z’/><EventRecordID>3809</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>10.0.14393.187</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>1003</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T07:44:47.682517200Z’/><EventRecordID>3808</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>55c92734-d682-4d71-983e-d6ec3f16059f</Data><Data>
  324. 1: 0567073a-7d74-403b-b2d5-6b35da372d8d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  325. 2: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  326. 3: 1b750385-9fe2-49a8-ab55-149d0546395b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  327. 4: 1d873132-f09f-4eb2-bf5a-2e4fb48935e8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  328. 5: 2b1f36bb-c1cd-4306-bf5c-a0367c2d97d8, 1, 1 [(0 )(1 )(2 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)(?)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(3 )]
  329. 6: 30d469c6-a78f-4476-b5c8-af78d5b6a5fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  330. 7: 411b3d4f-be6d-4a06-baaa-9cabfc256cae, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  331. 8: 58e97c99-f377-4ef1-81d5-4ad5522b5fd8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  332. 9: 74436dbb-cc17-46de-867f-14906ba4a938, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  333. 10: 8db63db6-4f8f-46d6-a448-66444faaaa72, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  334. 11: 9e4b231b-3e45-41f4-967f-c914f178b6ac, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  335. 12: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  336. 13: c082c31b-2c4f-4e07-94d7-9181fa802c4b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  337. 14: e371d89a-73e8-4b24-a7ff-23a3641dd18e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
  338.  
  339. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>1066</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T07:44:47.579951200Z’/><EventRecordID>3807</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>C:\WINDOWS\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
  340. C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/inherited/1.0, 0x00000000, 0x00000000
  341. C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
  342. C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
  343. C:\WINDOWS\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
  344. C:\WINDOWS\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
  345. C:\WINDOWS\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
  346. C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
  347. C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
  348. </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Security-SPP’ Guid='{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}’ EventSourceName=’Software Protection Platform Service’/><EventID Qualifiers=’16384′>900</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T07:44:47.475095400Z’/><EventRecordID>3806</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>caller=wmiprvse.exe</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>326</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T07:21:04.834700500Z’/><EventRecordID>3805</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>19628</Data><Data>{CA371399-AE31-4CFC-A043-BA53A41718AE}: </Data><Data>1</Data><Data>C:\Users\dpme\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\5585baaf23cd7af2\EntClientDb.edb</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.156, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.</Data><Data>0 0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>105</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T07:21:04.684600600Z’/><EventRecordID>3804</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>19628</Data><Data>{CA371399-AE31-4CFC-A043-BA53A41718AE}: </Data><Data>0</Data><Data>1</Data><Data>[1] 0.000, [2] 0.000, [3] 0.000, [4] 0.016, [5] 0.359, [6] 0.704, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>302</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T07:21:04.676592200Z’/><EventRecordID>3803</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>19628</Data><Data>{CA371399-AE31-4CFC-A043-BA53A41718AE}: </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>301</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T07:21:03.614146900Z’/><EventRecordID>3802</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>19628</Data><Data>{CA371399-AE31-4CFC-A043-BA53A41718AE}: </Data><Data>C:\Users\dpme\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\5585baaf23cd7af2\edb.log</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>300</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T07:21:03.611144800Z’/><EventRecordID>3801</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>19628</Data><Data>{CA371399-AE31-4CFC-A043-BA53A41718AE}: </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>102</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T07:21:03.606141500Z’/><EventRecordID>3800</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>19628</Data><Data>{CA371399-AE31-4CFC-A043-BA53A41718AE}: </Data><Data>0</Data><Data>10</Data><Data>00</Data><Data>14393</Data><Data>0000</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’dbupdate’/><EventID Qualifiers=’0′>0</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T06:59:19.515589700Z’/><EventRecordID>3799</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Service stopped</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’dbupdate’/><EventID Qualifiers=’0′>0</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T06:59:18.749490200Z’/><EventRecordID>3798</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Service started</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>326</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T04:21:05.662948200Z’/><EventRecordID>3797</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>260</Data><Data>{D374C5F0-244B-4084-B038-44708A5F52FA}: </Data><Data>1</Data><Data>C:\Users\dpme\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\5585baaf23cd7af2\EntClientDb.edb</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.016, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.</Data><Data>0 0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>105</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T04:21:05.653944200Z’/><EventRecordID>3796</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>260</Data><Data>{D374C5F0-244B-4084-B038-44708A5F52FA}: </Data><Data>0</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.015, [6] 0.250, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>302</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T04:21:05.647437800Z’/><EventRecordID>3795</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>260</Data><Data>{D374C5F0-244B-4084-B038-44708A5F52FA}: </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>301</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T04:21:05.385025900Z’/><EventRecordID>3794</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>260</Data><Data>{D374C5F0-244B-4084-B038-44708A5F52FA}: </Data><Data>C:\Users\dpme\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\5585baaf23cd7af2\edb.log</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>300</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T04:21:05.383523900Z’/><EventRecordID>3793</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>260</Data><Data>{D374C5F0-244B-4084-B038-44708A5F52FA}: </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>102</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T04:21:05.379020400Z’/><EventRecordID>3792</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>260</Data><Data>{D374C5F0-244B-4084-B038-44708A5F52FA}: </Data><Data>0</Data><Data>10</Data><Data>00</Data><Data>14393</Data><Data>0000</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’dbupdate’/><EventID Qualifiers=’0′>0</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T01:59:20.103880000Z’/><EventRecordID>3791</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Service stopped</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’dbupdate’/><EventID Qualifiers=’0′>0</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T01:59:19.386446400Z’/><EventRecordID>3790</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Service started</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>326</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T01:21:05.903457800Z’/><EventRecordID>3789</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>18276</Data><Data>{CE15A632-AC39-4D79-9161-6EB264A1E560}: </Data><Data>1</Data><Data>C:\Users\dpme\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\5585baaf23cd7af2\EntClientDb.edb</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.</Data><Data>0 0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>105</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T01:21:05.891947000Z’/><EventRecordID>3788</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>18276</Data><Data>{CE15A632-AC39-4D79-9161-6EB264A1E560}: </Data><Data>0</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.031, [6] 0.047, [7] 0.015, [8] 0.000, [9] 0.000, [10] 0.000.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>302</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T01:21:05.888444600Z’/><EventRecordID>3787</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>18276</Data><Data>{CE15A632-AC39-4D79-9161-6EB264A1E560}: </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>301</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T01:21:05.809391800Z’/><EventRecordID>3786</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>18276</Data><Data>{CE15A632-AC39-4D79-9161-6EB264A1E560}: </Data><Data>C:\Users\dpme\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\5585baaf23cd7af2\edb.log</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>300</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T01:21:05.807389900Z’/><EventRecordID>3785</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>18276</Data><Data>{CE15A632-AC39-4D79-9161-6EB264A1E560}: </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>102</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T01:21:05.802886900Z’/><EventRecordID>3784</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>18276</Data><Data>{CE15A632-AC39-4D79-9161-6EB264A1E560}: </Data><Data>0</Data><Data>10</Data><Data>00</Data><Data>14393</Data><Data>0000</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Defrag’/><EventID Qualifiers=’0′>258</EventID><Level>0</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T01:10:03.456670800Z’/><EventRecordID>3783</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>defragmentation</Data><Data>OS (C:)</Data><Binary>00000000DE010000C70100000000000022B651A2296BEDD85E9C8D030000000000000000</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Windows Error Reporting’/><EventID Qualifiers=’0′>1001</EventID><Level>4</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T00:46:46.692212900Z’/><EventRecordID>3782</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>129163447618</Data><Data>5</Data><Data>RADAR_PRE_LEAK_64</Data><Data>Not available</Data><Data>0</Data><Data>TiWorker.exe</Data><Data>10.0.14393.0</Data><Data>10.0.14393.2.0.0</Data><Data></Data><Data></Data><Data></Data><Data></Data><Data></Data><Data></Data><Data></Data><Data>
  349. \\?\C:\Users\dpme\AppData\Local\Temp\RDR4C3F.tmp\empty.txt
  350. \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER4C6F.tmp.WERInternalMetadata.xml</Data><Data></Data><Data></Data><Data>0</Data><Data>864c5eb4-8770-11e6-b364-848f69ae497a</Data><Data>0</Data><Data>4e648b57fc571e8a0898ca5e5c06e05f</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Defrag’/><EventID Qualifiers=’0′>258</EventID><Level>0</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-10-01T00:29:24.895721300Z’/><EventRecordID>3781</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>defragmentation</Data><Data>RECOVERY</Data><Binary>00000000DE010000C70100000000000022B651A2296BEDD85E9C8D030000000000000000</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Defrag’/><EventID Qualifiers=’0′>258</EventID><Level>0</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T23:22:39.691149600Z’/><EventRecordID>3780</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>defragmentation</Data><Data>RECOVERY</Data><Binary>00000000DE010000C70100000000000022B651A2296BEDD85E9C8D030000000000000000</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Perflib’ Guid='{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}’ EventSourceName=’Perflib’/><EventID Qualifiers=’49152′>1008</EventID><Version>0</Version><Level>2</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T22:52:14.474851700Z’/><EventRecordID>3779</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><UserData><EventXML xmlns=’Perflib’><param1>SQLAgent$CAPTOOLSDBINST</param1><param2>perf-MSSQL11.CAPTOOLSDBINST-sqlagtctr.dll</param2><binaryDataSize>8</binaryDataSize><binaryData>F303000000000000</binaryData></EventXML></UserData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Perflib’ Guid='{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}’ EventSourceName=’Perflib’/><EventID Qualifiers=’49152′>1008</EventID><Version>0</Version><Level>2</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T22:52:10.835383000Z’/><EventRecordID>3778</EventRecordID><Correlation/><Execution ProcessID=’0′ ThreadID=’0’/><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><UserData><EventXML xmlns=’Perflib’><param1>MSSQL$CAPTOOLSDBINST</param1><param2>perf-MSSQL$CAPTOOLSDBINST-sqlctr11.0.2100.60.dll</param2><binaryDataSize>8</binaryDataSize><binaryData>F303000000000000</binaryData></EventXML></UserData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Defrag’/><EventID Qualifiers=’0′>258</EventID><Level>0</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T22:51:23.760336900Z’/><EventRecordID>3777</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>defragmentation</Data><Data>WD Passport (F:)</Data><Binary>00000000DE010000C70100000000000022B651A2296BEDD85E9C8D030000000000000000</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Defrag’/><EventID Qualifiers=’0′>258</EventID><Level>0</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T22:51:17.868362000Z’/><EventRecordID>3776</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>defragmentation</Data><Data>MEINBACKUP (E:)</Data><Binary>00000000DE010000C70100000000000022B651A2296BEDD85E9C8D030000000000000000</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Defrag’/><EventID Qualifiers=’0′>258</EventID><Level>0</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T22:51:16.541517800Z’/><EventRecordID>3775</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>defragmentation</Data><Data>RECOVERY</Data><Binary>00000000DE010000C70100000000000022B651A2296BEDD85E9C8D030000000000000000</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Defrag’/><EventID Qualifiers=’0′>258</EventID><Level>0</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T22:41:15.559409700Z’/><EventRecordID>3774</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>defragmentation</Data><Data>WD Passport (F:)</Data><Binary>00000000DE010000C70100000000000022B651A2296BEDD85E9C8D030000000000000000</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Defrag’/><EventID Qualifiers=’0′>258</EventID><Level>0</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T22:40:54.358219300Z’/><EventRecordID>3773</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>defragmentation</Data><Data>MEINBACKUP (E:)</Data><Binary>00000000DE010000C70100000000000022B651A2296BEDD85E9C8D030000000000000000</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’Microsoft-Windows-Defrag’/><EventID Qualifiers=’0′>258</EventID><Level>0</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T22:40:53.013039200Z’/><EventRecordID>3772</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>defragmentation</Data><Data>RECOVERY</Data><Binary>00000000DE010000C70100000000000022B651A2296BEDD85E9C8D030000000000000000</Binary></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>326</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T22:21:08.181027000Z’/><EventRecordID>3771</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>5616</Data><Data>{46B3E4C4-D357-40C0-9426-6BA0316B8B55}: </Data><Data>1</Data><Data>C:\Users\dpme\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\5585baaf23cd7af2\EntClientDb.edb</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.063, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.</Data><Data>0 0</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>105</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T22:21:08.116594600Z’/><EventRecordID>3770</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>5616</Data><Data>{46B3E4C4-D357-40C0-9426-6BA0316B8B55}: </Data><Data>0</Data><Data>0</Data><Data>[1] 0.000, [2] 0.000, [3] 0.031, [4] 0.000, [5] 0.282, [6] 0.343, [7] 0.094, [8] 0.000, [9] 0.000, [10] 0.000.</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>302</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T22:21:08.026212700Z’/><EventRecordID>3769</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>5616</Data><Data>{46B3E4C4-D357-40C0-9426-6BA0316B8B55}: </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>301</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T22:21:07.407637000Z’/><EventRecordID>3768</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>5616</Data><Data>{46B3E4C4-D357-40C0-9426-6BA0316B8B55}: </Data><Data>C:\Users\dpme\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\5585baaf23cd7af2\edb.log</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>300</EventID><Level>4</Level><Task>3</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T22:21:07.405135300Z’/><EventRecordID>3767</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>5616</Data><Data>{46B3E4C4-D357-40C0-9426-6BA0316B8B55}: </Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>102</EventID><Level>4</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T22:21:07.375117800Z’/><EventRecordID>3766</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>Music.UI</Data><Data>5616</Data><Data>{46B3E4C4-D357-40C0-9426-6BA0316B8B55}: </Data><Data>0</Data><Data>10</Data><Data>00</Data><Data>14393</Data><Data>0000</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>533</EventID><Level>3</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:48:49.908405700Z’/><EventRecordID>3765</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1966080 (0x00000000001e0000)</Data><Data>16384 (0x00004000)</Data><Data>36</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>533</EventID><Level>3</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:48:49.907909400Z’/><EventRecordID>3764</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1982464 (0x00000000001e4000)</Data><Data>16384 (0x00004000)</Data><Data>36</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>510</EventID><Level>3</Level><Task>7</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:48:39.942183700Z’/><EventRecordID>3763</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1589248 (0x0000000000184000)</Data><Data>16384 (0x00004000)</Data><Data>96</Data><Data>10</Data><Data>32</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>510</EventID><Level>3</Level><Task>7</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:48:06.992041600Z’/><EventRecordID>3762</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1163264 (0x000000000011c000)</Data><Data>16384 (0x00004000)</Data><Data>63</Data><Data>7</Data><Data>21</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>533</EventID><Level>3</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:47:45.901751000Z’/><EventRecordID>3761</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1802240 (0x00000000001b8000)</Data><Data>16384 (0x00004000)</Data><Data>36</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>533</EventID><Level>3</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:47:45.901249100Z’/><EventRecordID>3760</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1818624 (0x00000000001bc000)</Data><Data>16384 (0x00004000)</Data><Data>36</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>510</EventID><Level>3</Level><Task>7</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:47:45.738059500Z’/><EventRecordID>3759</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1032192 (0x00000000000fc000)</Data><Data>16384 (0x00004000)</Data><Data>42</Data><Data>5</Data><Data>15</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>533</EventID><Level>3</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:47:45.260589900Z’/><EventRecordID>3758</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1556480 (0x000000000017c000)</Data><Data>16384 (0x00004000)</Data><Data>36</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>533</EventID><Level>3</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:47:45.260090600Z’/><EventRecordID>3757</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1572864 (0x0000000000180000)</Data><Data>16384 (0x00004000)</Data><Data>36</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>533</EventID><Level>3</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:47:45.259589800Z’/><EventRecordID>3756</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1589248 (0x0000000000184000)</Data><Data>16384 (0x00004000)</Data><Data>36</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>533</EventID><Level>3</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:47:45.259089400Z’/><EventRecordID>3755</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1605632 (0x0000000000188000)</Data><Data>16384 (0x00004000)</Data><Data>36</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>533</EventID><Level>3</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:47:45.258589100Z’/><EventRecordID>3754</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1490944 (0x000000000016c000)</Data><Data>16384 (0x00004000)</Data><Data>36</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>533</EventID><Level>3</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:47:45.258087700Z’/><EventRecordID>3753</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1507328 (0x0000000000170000)</Data><Data>16384 (0x00004000)</Data><Data>36</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>533</EventID><Level>3</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:47:45.257587400Z’/><EventRecordID>3752</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1523712 (0x0000000000174000)</Data><Data>16384 (0x00004000)</Data><Data>36</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>533</EventID><Level>3</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:47:45.257087600Z’/><EventRecordID>3751</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1540096 (0x0000000000178000)</Data><Data>16384 (0x00004000)</Data><Data>36</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>533</EventID><Level>3</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:47:45.256586700Z’/><EventRecordID>3750</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1212416 (0x0000000000128000)</Data><Data>16384 (0x00004000)</Data><Data>36</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>533</EventID><Level>3</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:47:45.256086400Z’/><EventRecordID>3749</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1441792 (0x0000000000160000)</Data><Data>16384 (0x00004000)</Data><Data>36</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>533</EventID><Level>3</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:47:45.255589600Z’/><EventRecordID>3748</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1458176 (0x0000000000164000)</Data><Data>16384 (0x00004000)</Data><Data>36</Data></EventData></Event><Event xmlns=’http://schemas.microsoft.com/win/2004/08/events/event’><System><Provider Name=’ESENT’/><EventID Qualifiers=’0′>533</EventID><Level>3</Level><Task>1</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime=’2016-09-30T21:47:45.255086700Z’/><EventRecordID>3747</EventRecordID><Channel>Application</Channel><Computer>meinertlaptop</Computer><Security/></System><EventData><Data>SettingSyncHost</Data><Data>12124</Data><Data>{E3532799-6B04-4F7B-9D47-F2E6B4093BF4}: </Data><Data>C:\Users\dpme\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb</Data><Data>1474560 (0x0000000000168000)</Data><Data>16384 (0x00004000)</Data><Data>36</Data></EventData></Event></Events>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement