Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Trying to see if somebody is trying to get in my network
- Log Name: System
- Source: Microsoft-Windows-DNS-Client
- Date: 10/16/2017 4:22:01 PM
- Event ID: 1014
- Task Category: (1014)
- Level: Warning
- Keywords: (268435456)
- User: NETWORK SERVICE
- Computer: Anonymous
- Description:
- Name resolution for the name wdcp.microsoft.com timed out after none of the configured DNS servers responded.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-DNS-Client" Guid="{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}" />
- <EventID>1014</EventID>
- <Version>0</Version>
- <Level>3</Level>
- <Task>1014</Task>
- <Opcode>0</Opcode>
- <Keywords>0x4000000010000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T21:22:01.862715000Z" />
- <EventRecordID>34847</EventRecordID>
- <Correlation />
- <Execution ProcessID="1076" ThreadID="5948" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-20" />
- </System>
- <EventData>
- <Data Name="QueryName">wdcp.microsoft.com</Data>
- <Data Name="AddressLength">128</Data>
- <Data Name="Address">020000000A080801000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: BROWSER
- Date: 10/16/2017 4:10:42 PM
- Event ID: 8033
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Anonymous
- Description:
- The browser has forced an election on network \Device\NetBT_Tcpip_{FDC350A4-00C1-4D17-B653-F2A12F37A11D} because a master browser was stopped.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="BROWSER" />
- <EventID Qualifiers="16384">8033</EventID>
- <Level>4</Level>
- <Task>0</Task>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T21:10:42.000000000Z" />
- <EventRecordID>34846</EventRecordID>
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security />
- </System>
- <EventData>
- <Data>\Device\NetBT_Tcpip_{FDC350A4-00C1-4D17-B653-F2A12F37A11D}</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-DNS-Client
- Date: 10/16/2017 3:38:49 PM
- Event ID: 1014
- Task Category: (1014)
- Level: Warning
- Keywords: (268435456)
- User: NETWORK SERVICE
- Computer: Anonymous
- Description:
- Name resolution for the name DB5SCH103082510.wns.windows.com timed out after none of the configured DNS servers responded.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-DNS-Client" Guid="{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}" />
- <EventID>1014</EventID>
- <Version>0</Version>
- <Level>3</Level>
- <Task>1014</Task>
- <Opcode>0</Opcode>
- <Keywords>0x4000000010000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T20:38:49.349801100Z" />
- <EventRecordID>34845</EventRecordID>
- <Correlation />
- <Execution ProcessID="1076" ThreadID="5476" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-20" />
- </System>
- <EventData>
- <Data Name="QueryName">DB5SCH103082510.wns.windows.com</Data>
- <Data Name="AddressLength">128</Data>
- <Data Name="Address">020000000A080801000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: BROWSER
- Date: 10/16/2017 1:42:38 PM
- Event ID: 8033
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Anonymous
- Description:
- The browser has forced an election on network \Device\NetBT_Tcpip_{FDC350A4-00C1-4D17-B653-F2A12F37A11D} because a master browser was stopped.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="BROWSER" />
- <EventID Qualifiers="16384">8033</EventID>
- <Level>4</Level>
- <Task>0</Task>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T18:42:38.000000000Z" />
- <EventRecordID>34844</EventRecordID>
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security />
- </System>
- <EventData>
- <Data>\Device\NetBT_Tcpip_{FDC350A4-00C1-4D17-B653-F2A12F37A11D}</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: EventLog
- Date: 10/16/2017 12:00:00 PM
- Event ID: 6013
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Anonymous
- Description:
- The system uptime is 139838 seconds.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="EventLog" />
- <EventID Qualifiers="32768">6013</EventID>
- <Level>4</Level>
- <Task>0</Task>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T17:00:00.000000000Z" />
- <EventRecordID>34843</EventRecordID>
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security />
- </System>
- <EventData>
- <Data>
- </Data>
- <Data>
- </Data>
- <Data>
- </Data>
- <Data>
- </Data>
- <Data>139838</Data>
- <Data>60</Data>
- <Data>360 Central Standard Time</Data>
- <Binary>31002E003100000030000000570069006E0064006F0077007300200038002E003100000036002E0033002E00390036003000300020004200750069006C006400200039003600300030002000200000004D0075006C0074006900700072006F0063006500730073006F00720020004600720065006500000039003600300030002E00770069006E0062006C00750065005F006C007400730062002E003100370030003900310034002D00300036003000300000003500340031003700330065003700650000004E006F007400200041007600610069006C00610062006C00650000004E006F007400200041007600610069006C00610062006C0065000000390000003400000038003100310032000000340030003900000041006E006F006E0079006D006F007500730000000000</Binary>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-DNS-Client
- Date: 10/16/2017 11:21:08 AM
- Event ID: 1014
- Task Category: (1014)
- Level: Warning
- Keywords: (268435456)
- User: NETWORK SERVICE
- Computer: Anonymous
- Description:
- Name resolution for the name shavar.services.mozilla.com timed out after none of the configured DNS servers responded.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-DNS-Client" Guid="{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}" />
- <EventID>1014</EventID>
- <Version>0</Version>
- <Level>3</Level>
- <Task>1014</Task>
- <Opcode>0</Opcode>
- <Keywords>0x4000000010000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T16:21:08.880099000Z" />
- <EventRecordID>34842</EventRecordID>
- <Correlation />
- <Execution ProcessID="1076" ThreadID="5536" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-20" />
- </System>
- <EventData>
- <Data Name="QueryName">shavar.services.mozilla.com</Data>
- <Data Name="AddressLength">128</Data>
- <Data Name="Address">020000000A080801000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-DistributedCOM
- Date: 10/16/2017 7:43:16 AM
- Event ID: 10010
- Task Category: None
- Level: Error
- Keywords: Classic
- User: ANONYMOUS\Anon&anonanon
- Computer: Anonymous
- Description:
- The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
- <EventID Qualifiers="0">10010</EventID>
- <Version>0</Version>
- <Level>2</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8080000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T12:43:16.306482800Z" />
- <EventRecordID>34841</EventRecordID>
- <Correlation />
- <Execution ProcessID="828" ThreadID="4772" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-21-1957288335-908928117-3208654089-1001" />
- </System>
- <EventData>
- <Data Name="param1">{1B1F472E-3221-4826-97DB-2C2324D389AE}</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-DNS-Client
- Date: 10/16/2017 7:10:24 AM
- Event ID: 1014
- Task Category: (1014)
- Level: Warning
- Keywords: (268435456)
- User: NETWORK SERVICE
- Computer: Anonymous
- Description:
- Name resolution for the name isatap.kc.rr.com timed out after none of the configured DNS servers responded.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-DNS-Client" Guid="{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}" />
- <EventID>1014</EventID>
- <Version>0</Version>
- <Level>3</Level>
- <Task>1014</Task>
- <Opcode>0</Opcode>
- <Keywords>0x4000000010000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T12:10:24.647481500Z" />
- <EventRecordID>34840</EventRecordID>
- <Correlation />
- <Execution ProcessID="1076" ThreadID="2996" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-20" />
- </System>
- <EventData>
- <Data Name="QueryName">isatap.kc.rr.com</Data>
- <Data Name="AddressLength">128</Data>
- <Data Name="Address">1700000000000000260560001A0C0004F299BFFFFE02B7740000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: BROWSER
- Date: 10/16/2017 7:10:17 AM
- Event ID: 8033
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Anonymous
- Description:
- The browser has forced an election on network \Device\NetBT_Tcpip_{FDC350A4-00C1-4D17-B653-F2A12F37A11D} because a master browser was stopped.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="BROWSER" />
- <EventID Qualifiers="16384">8033</EventID>
- <Level>4</Level>
- <Task>0</Task>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T12:10:17.000000000Z" />
- <EventRecordID>34839</EventRecordID>
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security />
- </System>
- <EventData>
- <Data>\Device\NetBT_Tcpip_{FDC350A4-00C1-4D17-B653-F2A12F37A11D}</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 3:00:08 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Users\default\ntuser.dat was cleared updating 5 keys and creating 1 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T08:00:08.174193200Z" />
- <EventRecordID>34838</EventRecordID>
- <Correlation />
- <Execution ProcessID="2036" ThreadID="204" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">72</Data>
- <Data Name="HiveName">\??\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Users\default\ntuser.dat</Data>
- <Data Name="KeysUpdated">5</Data>
- <Data Name="DirtyPages">1</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 3:00:07 AM
- Event ID: 15
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- Hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{904C2A30-6D08-419F-AA72-0CBED13E01D7} was reorganized with a starting size of 87166976 bytes and an ending size of 82034688 bytes.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>15</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T08:00:07.286070000Z" />
- <EventRecordID>34837</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{904C2A30-6D08-419F-AA72-0CBED13E01D7}</Data>
- <Data Name="OriginalSize">87166976</Data>
- <Data Name="NewSize">82034688</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 3:00:04 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{6FE205CA-CA08-4591-AE30-0AED525D0D1C} was cleared updating 335 keys and creating 49 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T08:00:04.751251900Z" />
- <EventRecordID>34836</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{6FE205CA-CA08-4591-AE30-0AED525D0D1C}</Data>
- <Data Name="KeysUpdated">335</Data>
- <Data Name="DirtyPages">49</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 3:00:04 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{E57E008F-E4D7-4B77-82EB-24271DD6B880} was cleared updating 0 keys and creating 0 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T08:00:04.299070800Z" />
- <EventRecordID>34835</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{E57E008F-E4D7-4B77-82EB-24271DD6B880}</Data>
- <Data Name="KeysUpdated">0</Data>
- <Data Name="DirtyPages">0</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 3:00:03 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{2087449F-85DF-4699-ABF7-C3E53115A41C} was cleared updating 146695 keys and creating 18625 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T08:00:03.102746000Z" />
- <EventRecordID>34834</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{2087449F-85DF-4699-ABF7-C3E53115A41C}</Data>
- <Data Name="KeysUpdated">146695</Data>
- <Data Name="DirtyPages">18625</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 3:00:01 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{4EB1E864-C797-4EBF-902B-273BECA7A3BC} was cleared updating 68 keys and creating 5 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T08:00:01.607772600Z" />
- <EventRecordID>34833</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{4EB1E864-C797-4EBF-902B-273BECA7A3BC}</Data>
- <Data Name="KeysUpdated">68</Data>
- <Data Name="DirtyPages">5</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 3:00:01 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{EBB400C8-0D14-433B-9A17-2F3F8F36A4B2} was cleared updating 48 keys and creating 5 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T08:00:01.090673800Z" />
- <EventRecordID>34832</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{EBB400C8-0D14-433B-9A17-2F3F8F36A4B2}</Data>
- <Data Name="KeysUpdated">48</Data>
- <Data Name="DirtyPages">5</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:59 AM
- Event ID: 15
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- Hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{BFBBF9FC-D0C0-4C1B-936C-7B1053C6FC56} was reorganized with a starting size of 14708736 bytes and an ending size of 12599296 bytes.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>15</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:59.978259100Z" />
- <EventRecordID>34831</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{BFBBF9FC-D0C0-4C1B-936C-7B1053C6FC56}</Data>
- <Data Name="OriginalSize">14708736</Data>
- <Data Name="NewSize">12599296</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:53 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\GLOBALROOT\Device\HarddiskVolumeShadowCopy2\Users\default\ntuser.dat was cleared updating 5 keys and creating 1 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:53.167428400Z" />
- <EventRecordID>34830</EventRecordID>
- <Correlation />
- <Execution ProcessID="2036" ThreadID="204" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">72</Data>
- <Data Name="HiveName">\??\GLOBALROOT\Device\HarddiskVolumeShadowCopy2\Users\default\ntuser.dat</Data>
- <Data Name="KeysUpdated">5</Data>
- <Data Name="DirtyPages">1</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:52 AM
- Event ID: 15
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- Hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{BD28871E-64D0-4C8F-8708-EEF402459E7F} was reorganized with a starting size of 87166976 bytes and an ending size of 81883136 bytes.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>15</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:52.254793700Z" />
- <EventRecordID>34829</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{BD28871E-64D0-4C8F-8708-EEF402459E7F}</Data>
- <Data Name="OriginalSize">87166976</Data>
- <Data Name="NewSize">81883136</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:49 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{223F783C-5777-4700-9745-03BCF41B766A} was cleared updating 336 keys and creating 49 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:49.599744300Z" />
- <EventRecordID>34828</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{223F783C-5777-4700-9745-03BCF41B766A}</Data>
- <Data Name="KeysUpdated">336</Data>
- <Data Name="DirtyPages">49</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:49 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{E80F92BA-F042-4137-8F25-40866FFD40C1} was cleared updating 0 keys and creating 0 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:49.112554500Z" />
- <EventRecordID>34827</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{E80F92BA-F042-4137-8F25-40866FFD40C1}</Data>
- <Data Name="KeysUpdated">0</Data>
- <Data Name="DirtyPages">0</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:48 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{4703D705-086E-4984-A7FF-D9D40F331E71} was cleared updating 146695 keys and creating 18625 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:48.072615800Z" />
- <EventRecordID>34826</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{4703D705-086E-4984-A7FF-D9D40F331E71}</Data>
- <Data Name="KeysUpdated">146695</Data>
- <Data Name="DirtyPages">18625</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:46 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{C96E97DE-DF15-4C98-BC99-B83774D3EEAF} was cleared updating 68 keys and creating 5 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:46.474533200Z" />
- <EventRecordID>34825</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{C96E97DE-DF15-4C98-BC99-B83774D3EEAF}</Data>
- <Data Name="KeysUpdated">68</Data>
- <Data Name="DirtyPages">5</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:46 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{9C4378C2-740C-4293-A75C-B115C69B4A64} was cleared updating 48 keys and creating 5 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:46.004963700Z" />
- <EventRecordID>34824</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{9C4378C2-740C-4293-A75C-B115C69B4A64}</Data>
- <Data Name="KeysUpdated">48</Data>
- <Data Name="DirtyPages">5</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:45 AM
- Event ID: 15
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- Hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{771190DE-4AC6-4A92-A865-49B31A504ED6} was reorganized with a starting size of 14708736 bytes and an ending size of 12574720 bytes.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>15</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:45.113700900Z" />
- <EventRecordID>34823</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{771190DE-4AC6-4A92-A865-49B31A504ED6}</Data>
- <Data Name="OriginalSize">14708736</Data>
- <Data Name="NewSize">12574720</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:39 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\GLOBALROOT\Device\HarddiskVolumeShadowCopy3\Users\default\ntuser.dat was cleared updating 5 keys and creating 1 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:39.813667000Z" />
- <EventRecordID>34822</EventRecordID>
- <Correlation />
- <Execution ProcessID="2036" ThreadID="204" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">72</Data>
- <Data Name="HiveName">\??\GLOBALROOT\Device\HarddiskVolumeShadowCopy3\Users\default\ntuser.dat</Data>
- <Data Name="KeysUpdated">5</Data>
- <Data Name="DirtyPages">1</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:38 AM
- Event ID: 15
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- Hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{38B90FC2-DC5A-44A2-A973-EA88C16014D4} was reorganized with a starting size of 87166976 bytes and an ending size of 82579456 bytes.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>15</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:38.903502400Z" />
- <EventRecordID>34821</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{38B90FC2-DC5A-44A2-A973-EA88C16014D4}</Data>
- <Data Name="OriginalSize">87166976</Data>
- <Data Name="NewSize">82579456</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:36 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{4BC01C60-A44B-431D-B4B3-ABE369F1FB4F} was cleared updating 317 keys and creating 47 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:36.195767000Z" />
- <EventRecordID>34820</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{4BC01C60-A44B-431D-B4B3-ABE369F1FB4F}</Data>
- <Data Name="KeysUpdated">317</Data>
- <Data Name="DirtyPages">47</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:35 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{5D05CE6C-28EE-4904-9383-F4FF4C635DFC} was cleared updating 0 keys and creating 0 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:35.748475800Z" />
- <EventRecordID>34819</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{5D05CE6C-28EE-4904-9383-F4FF4C635DFC}</Data>
- <Data Name="KeysUpdated">0</Data>
- <Data Name="DirtyPages">0</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:33 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{75B12FDC-4390-4A49-B01A-190F509FF153} was cleared updating 68 keys and creating 5 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:33.582284300Z" />
- <EventRecordID>34818</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{75B12FDC-4390-4A49-B01A-190F509FF153}</Data>
- <Data Name="KeysUpdated">68</Data>
- <Data Name="DirtyPages">5</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:33 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{23499330-07F7-43CF-A045-11C3C71C390A} was cleared updating 47 keys and creating 6 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:33.145940800Z" />
- <EventRecordID>34817</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{23499330-07F7-43CF-A045-11C3C71C390A}</Data>
- <Data Name="KeysUpdated">47</Data>
- <Data Name="DirtyPages">6</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:32 AM
- Event ID: 15
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- Hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{8B4C2587-633A-454F-8FE7-6C9DDCA15E6F} was reorganized with a starting size of 12587008 bytes and an ending size of 12562432 bytes.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>15</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:32.235424800Z" />
- <EventRecordID>34816</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{8B4C2587-633A-454F-8FE7-6C9DDCA15E6F}</Data>
- <Data Name="OriginalSize">12587008</Data>
- <Data Name="NewSize">12562432</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:26 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\GLOBALROOT\Device\HarddiskVolumeShadowCopy4\Users\default\ntuser.dat was cleared updating 5 keys and creating 1 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:26.812518900Z" />
- <EventRecordID>34815</EventRecordID>
- <Correlation />
- <Execution ProcessID="2036" ThreadID="204" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">72</Data>
- <Data Name="HiveName">\??\GLOBALROOT\Device\HarddiskVolumeShadowCopy4\Users\default\ntuser.dat</Data>
- <Data Name="KeysUpdated">5</Data>
- <Data Name="DirtyPages">1</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:25 AM
- Event ID: 15
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- Hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{CB1AA828-3F71-4A02-87FB-118322AB3330} was reorganized with a starting size of 87166976 bytes and an ending size of 84848640 bytes.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>15</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:25.740010700Z" />
- <EventRecordID>34814</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{CB1AA828-3F71-4A02-87FB-118322AB3330}</Data>
- <Data Name="OriginalSize">87166976</Data>
- <Data Name="NewSize">84848640</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:23 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{7207FB21-9330-44A0-9438-23EDC5A687FD} was cleared updating 326 keys and creating 49 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:23.314414000Z" />
- <EventRecordID>34813</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{7207FB21-9330-44A0-9438-23EDC5A687FD}</Data>
- <Data Name="KeysUpdated">326</Data>
- <Data Name="DirtyPages">49</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:20 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{97E7AE52-3F3B-4FB4-98FA-4F3956716B0D} was cleared updating 68 keys and creating 5 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:20.201322200Z" />
- <EventRecordID>34812</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{97E7AE52-3F3B-4FB4-98FA-4F3956716B0D}</Data>
- <Data Name="KeysUpdated">68</Data>
- <Data Name="DirtyPages">5</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:19 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{701A7F09-BB41-46B2-BE63-690D5B9C4539} was cleared updating 47 keys and creating 6 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:19.769751600Z" />
- <EventRecordID>34811</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{701A7F09-BB41-46B2-BE63-690D5B9C4539}</Data>
- <Data Name="KeysUpdated">47</Data>
- <Data Name="DirtyPages">6</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:59:18 AM
- Event ID: 15
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- Hive \??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{C62192AF-5DDC-42AE-8F0E-2D1EE6B426F8} was reorganized with a starting size of 12587008 bytes and an ending size of 12488704 bytes.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>15</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:59:18.852378000Z" />
- <EventRecordID>34810</EventRecordID>
- <Correlation />
- <Execution ProcessID="2696" ThreadID="5140" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">171</Data>
- <Data Name="HiveName">\??\Volume{f9d2b0da-705c-42df-9eb2-041ba73e7a55}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{C62192AF-5DDC-42AE-8F0E-2D1EE6B426F8}</Data>
- <Data Name="OriginalSize">12587008</Data>
- <Data Name="NewSize">12488704</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-DistributedCOM
- Date: 10/16/2017 2:48:21 AM
- Event ID: 10010
- Task Category: None
- Level: Error
- Keywords: Classic
- User: ANONYMOUS\Anon&anonanon
- Computer: Anonymous
- Description:
- The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
- <EventID Qualifiers="0">10010</EventID>
- <Version>0</Version>
- <Level>2</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8080000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:48:21.794192600Z" />
- <EventRecordID>34809</EventRecordID>
- <Correlation />
- <Execution ProcessID="828" ThreadID="3836" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-21-1957288335-908928117-3208654089-1001" />
- </System>
- <EventData>
- <Data Name="param1">{1B1F472E-3221-4826-97DB-2C2324D389AE}</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:48:05 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\c:\users\backoffice computer\AppData\Local\Microsoft\Windows\usrclass.dat was cleared updating 5 keys and creating 1 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:48:05.347527400Z" />
- <EventRecordID>34808</EventRecordID>
- <Correlation />
- <Execution ProcessID="2004" ThreadID="5208" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">77</Data>
- <Data Name="HiveName">\??\c:\users\backoffice computer\AppData\Local\Microsoft\Windows\usrclass.dat</Data>
- <Data Name="KeysUpdated">5</Data>
- <Data Name="DirtyPages">1</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:48:05 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\c:\users\backoffice computer\ntuser.dat was cleared updating 10 keys and creating 3 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:48:05.220438100Z" />
- <EventRecordID>34807</EventRecordID>
- <Correlation />
- <Execution ProcessID="2004" ThreadID="5208" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">43</Data>
- <Data Name="HiveName">\??\c:\users\backoffice computer\ntuser.dat</Data>
- <Data Name="KeysUpdated">10</Data>
- <Data Name="DirtyPages">3</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/16/2017 2:48:05 AM
- Event ID: 16
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Anonymous
- Description:
- The access history in hive \??\c:\users\guest\AppData\Local\Microsoft\Windows\usrclass.dat was cleared updating 1 keys and creating 1 modified pages.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>16</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:48:05.181410000Z" />
- <EventRecordID>34806</EventRecordID>
- <Correlation />
- <Execution ProcessID="2004" ThreadID="5208" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="HiveNameLength">63</Data>
- <Data Name="HiveName">\??\c:\users\guest\AppData\Local\Microsoft\Windows\usrclass.dat</Data>
- <Data Name="KeysUpdated">1</Data>
- <Data Name="DirtyPages">1</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-DistributedCOM
- Date: 10/16/2017 2:47:51 AM
- Event ID: 10010
- Task Category: None
- Level: Error
- Keywords: Classic
- User: ANONYMOUS\Anon&anonanon
- Computer: Anonymous
- Description:
- The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did not register with DCOM within the required timeout.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
- <EventID Qualifiers="0">10010</EventID>
- <Version>0</Version>
- <Level>2</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8080000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T07:47:51.766925900Z" />
- <EventRecordID>34805</EventRecordID>
- <Correlation />
- <Execution ProcessID="828" ThreadID="4560" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-21-1957288335-908928117-3208654089-1001" />
- </System>
- <EventData>
- <Data Name="param1">{BF6C1E47-86EC-4194-9CE5-13C15DCB2001}</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-DNS-Client
- Date: 10/15/2017 9:33:33 PM
- Event ID: 1014
- Task Category: (1014)
- Level: Warning
- Keywords: (268435456)
- User: NETWORK SERVICE
- Computer: Anonymous
- Description:
- Name resolution for the name client.wns.windows.com timed out after none of the configured DNS servers responded.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-DNS-Client" Guid="{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}" />
- <EventID>1014</EventID>
- <Version>0</Version>
- <Level>3</Level>
- <Task>1014</Task>
- <Opcode>0</Opcode>
- <Keywords>0x4000000010000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T02:33:33.147162500Z" />
- <EventRecordID>34804</EventRecordID>
- <Correlation />
- <Execution ProcessID="1076" ThreadID="5544" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-20" />
- </System>
- <EventData>
- <Data Name="QueryName">client.wns.windows.com</Data>
- <Data Name="AddressLength">128</Data>
- <Data Name="Address">020000000A080801000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Service Control Manager
- Date: 10/15/2017 9:22:47 PM
- Event ID: 7040
- Task Category: None
- Level: Information
- Keywords: Classic
- User: SYSTEM
- Computer: Anonymous
- Description:
- The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
- <EventID Qualifiers="16384">7040</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8080000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T02:22:47.510487800Z" />
- <EventRecordID>34803</EventRecordID>
- <Correlation />
- <Execution ProcessID="644" ThreadID="5352" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="param1">Background Intelligent Transfer Service</Data>
- <Data Name="param2">auto start</Data>
- <Data Name="param3">demand start</Data>
- <Data Name="param4">BITS</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-WindowsUpdateClient
- Date: 10/15/2017 8:23:08 PM
- Event ID: 19
- Task Category: Windows Update Agent
- Level: Information
- Keywords: Success,Installation
- User: SYSTEM
- Computer: Anonymous
- Description:
- Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.253.791.0)
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-WindowsUpdateClient" Guid="{945A8954-C147-4ACD-923F-40C45405A658}" />
- <EventID>19</EventID>
- <Version>1</Version>
- <Level>4</Level>
- <Task>1</Task>
- <Opcode>13</Opcode>
- <Keywords>0x8000000000000018</Keywords>
- <TimeCreated SystemTime="2017-10-16T01:23:08.622616700Z" />
- <EventRecordID>34802</EventRecordID>
- <Correlation />
- <Execution ProcessID="304" ThreadID="5200" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="updateTitle">Definition Update for Windows Defender - KB2267602 (Definition 1.253.791.0)</Data>
- <Data Name="updateGuid">{52DF0684-E6C8-4ACC-BE86-99E6CF8DEBA6}</Data>
- <Data Name="updateRevisionNumber">200</Data>
- <Data Name="serviceGuid">{9482F4B4-E343-43B6-B170-9A65BC822C77}</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Service Control Manager
- Date: 10/15/2017 8:23:07 PM
- Event ID: 7045
- Task Category: None
- Level: Information
- Keywords: Classic
- User: SYSTEM
- Computer: Anonymous
- Description:
- A service was installed in the system.
- Service Name: MpKsle4d59446
- Service File Name: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{37029531-18F6-4838-86C8-7CF53BD6B1B8}\MpKsle4d59446.sys
- Service Type: kernel mode driver
- Service Start Type: system start
- Service Account:
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
- <EventID Qualifiers="16384">7045</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8080000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T01:23:07.880477500Z" />
- <EventRecordID>34801</EventRecordID>
- <Correlation />
- <Execution ProcessID="644" ThreadID="5512" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="ServiceName">MpKsle4d59446</Data>
- <Data Name="ImagePath">C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{37029531-18F6-4838-86C8-7CF53BD6B1B8}\MpKsle4d59446.sys</Data>
- <Data Name="ServiceType">kernel mode driver</Data>
- <Data Name="StartType">system start</Data>
- <Data Name="AccountName">
- </Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-WindowsUpdateClient
- Date: 10/15/2017 8:22:52 PM
- Event ID: 43
- Task Category: Windows Update Agent
- Level: Information
- Keywords: Started,Installation
- User: SYSTEM
- Computer: Anonymous
- Description:
- Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.253.791.0)
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-WindowsUpdateClient" Guid="{945A8954-C147-4ACD-923F-40C45405A658}" />
- <EventID>43</EventID>
- <Version>1</Version>
- <Level>4</Level>
- <Task>1</Task>
- <Opcode>13</Opcode>
- <Keywords>0x8000000000002008</Keywords>
- <TimeCreated SystemTime="2017-10-16T01:22:52.863386700Z" />
- <EventRecordID>34800</EventRecordID>
- <Correlation />
- <Execution ProcessID="304" ThreadID="5200" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="updateTitle">Definition Update for Windows Defender - KB2267602 (Definition 1.253.791.0)</Data>
- <Data Name="updateGuid">{52DF0684-E6C8-4ACC-BE86-99E6CF8DEBA6}</Data>
- <Data Name="updateRevisionNumber">200</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-WindowsUpdateClient
- Date: 10/15/2017 8:22:52 PM
- Event ID: 17
- Task Category: Automatic Updates
- Level: Information
- Keywords: Success,Download
- User: SYSTEM
- Computer: Anonymous
- Description:
- Installation Ready: The following updates are downloaded and ready for installation:
- - Definition Update for Windows Defender - KB2267602 (Definition 1.253.791.0)
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-WindowsUpdateClient" Guid="{945A8954-C147-4ACD-923F-40C45405A658}" />
- <EventID>17</EventID>
- <Version>1</Version>
- <Level>4</Level>
- <Task>2</Task>
- <Opcode>12</Opcode>
- <Keywords>0x8000000000000014</Keywords>
- <TimeCreated SystemTime="2017-10-16T01:22:52.863386700Z" />
- <EventRecordID>34799</EventRecordID>
- <Correlation />
- <Execution ProcessID="304" ThreadID="5200" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <UserData>
- <updatelist xmlns="http://manifests.microsoft.com/win/2004/08/windows/eventlog">
- - Definition Update for Windows Defender - KB2267602 (Definition 1.253.791.0)</updatelist>
- </UserData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-WindowsUpdateClient
- Date: 10/15/2017 8:22:52 PM
- Event ID: 17
- Task Category: Automatic Updates
- Level: Information
- Keywords: Success,Download
- User: SYSTEM
- Computer: Anonymous
- Description:
- Installation Ready: The following updates are downloaded and ready for installation:
- - Microsoft.Reader
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-WindowsUpdateClient" Guid="{945A8954-C147-4ACD-923F-40C45405A658}" />
- <EventID>17</EventID>
- <Version>1</Version>
- <Level>4</Level>
- <Task>2</Task>
- <Opcode>12</Opcode>
- <Keywords>0x8000000000000014</Keywords>
- <TimeCreated SystemTime="2017-10-16T01:22:52.863386700Z" />
- <EventRecordID>34798</EventRecordID>
- <Correlation />
- <Execution ProcessID="304" ThreadID="5200" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <UserData>
- <updatelist xmlns="http://manifests.microsoft.com/win/2004/08/windows/eventlog">
- - Microsoft.Reader</updatelist>
- </UserData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-WindowsUpdateClient
- Date: 10/15/2017 8:20:46 PM
- Event ID: 44
- Task Category: Windows Update Agent
- Level: Information
- Keywords: Started,Download
- User: SYSTEM
- Computer: Anonymous
- Description:
- Windows Update started downloading an update.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-WindowsUpdateClient" Guid="{945A8954-C147-4ACD-923F-40C45405A658}" />
- <EventID>44</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>1</Task>
- <Opcode>12</Opcode>
- <Keywords>0x8000000000002004</Keywords>
- <TimeCreated SystemTime="2017-10-16T01:20:46.569554200Z" />
- <EventRecordID>34797</EventRecordID>
- <Correlation />
- <Execution ProcessID="304" ThreadID="5200" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="updateGuid">{52DF0684-E6C8-4ACC-BE86-99E6CF8DEBA6}</Data>
- <Data Name="updateRevisionNumber">200</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Service Control Manager
- Date: 10/15/2017 8:20:43 PM
- Event ID: 7040
- Task Category: None
- Level: Information
- Keywords: Classic
- User: SYSTEM
- Computer: Anonymous
- Description:
- The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
- <EventID Qualifiers="16384">7040</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8080000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-16T01:20:43.070861100Z" />
- <EventRecordID>34796</EventRecordID>
- <Correlation />
- <Execution ProcessID="644" ThreadID="5512" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="param1">Background Intelligent Transfer Service</Data>
- <Data Name="param2">demand start</Data>
- <Data Name="param3">auto start</Data>
- <Data Name="param4">BITS</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-DNS-Client
- Date: 10/15/2017 2:08:30 PM
- Event ID: 1014
- Task Category: (1014)
- Level: Warning
- Keywords: (268435456)
- User: NETWORK SERVICE
- Computer: Anonymous
- Description:
- Name resolution for the name isatap.kc.rr.com timed out after none of the configured DNS servers responded.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-DNS-Client" Guid="{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}" />
- <EventID>1014</EventID>
- <Version>0</Version>
- <Level>3</Level>
- <Task>1014</Task>
- <Opcode>0</Opcode>
- <Keywords>0x4000000010000000</Keywords>
- <TimeCreated SystemTime="2017-10-15T19:08:30.464874000Z" />
- <EventRecordID>34795</EventRecordID>
- <Correlation />
- <Execution ProcessID="1076" ThreadID="4820" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-20" />
- </System>
- <EventData>
- <Data Name="QueryName">isatap.kc.rr.com</Data>
- <Data Name="AddressLength">128</Data>
- <Data Name="Address">1700000000000000260560001A0C0004F299BFFFFE02B7740000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: BROWSER
- Date: 10/15/2017 2:08:18 PM
- Event ID: 8033
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Anonymous
- Description:
- The browser has forced an election on network \Device\NetBT_Tcpip_{FDC350A4-00C1-4D17-B653-F2A12F37A11D} because a master browser was stopped.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="BROWSER" />
- <EventID Qualifiers="16384">8033</EventID>
- <Level>4</Level>
- <Task>0</Task>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-15T19:08:18.000000000Z" />
- <EventRecordID>34794</EventRecordID>
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security />
- </System>
- <EventData>
- <Data>\Device\NetBT_Tcpip_{FDC350A4-00C1-4D17-B653-F2A12F37A11D}</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-DNS-Client
- Date: 10/15/2017 2:02:54 PM
- Event ID: 1014
- Task Category: (1014)
- Level: Warning
- Keywords: (268435456)
- User: NETWORK SERVICE
- Computer: Anonymous
- Description:
- Name resolution for the name win8.ipv6.microsoft.com. timed out after none of the configured DNS servers responded.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-DNS-Client" Guid="{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}" />
- <EventID>1014</EventID>
- <Version>0</Version>
- <Level>3</Level>
- <Task>1014</Task>
- <Opcode>0</Opcode>
- <Keywords>0x4000000010000000</Keywords>
- <TimeCreated SystemTime="2017-10-15T19:02:54.553079300Z" />
- <EventRecordID>34793</EventRecordID>
- <Correlation />
- <Execution ProcessID="1076" ThreadID="32" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-20" />
- </System>
- <EventData>
- <Data Name="QueryName">win8.ipv6.microsoft.com.</Data>
- <Data Name="AddressLength">128</Data>
- <Data Name="Address">020000000A080801000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: BROWSER
- Date: 10/15/2017 2:02:41 PM
- Event ID: 8033
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Anonymous
- Description:
- The browser has forced an election on network \Device\NetBT_Tcpip_{FDC350A4-00C1-4D17-B653-F2A12F37A11D} because a master browser was stopped.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="BROWSER" />
- <EventID Qualifiers="16384">8033</EventID>
- <Level>4</Level>
- <Task>0</Task>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-15T19:02:41.000000000Z" />
- <EventRecordID>34792</EventRecordID>
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security />
- </System>
- <EventData>
- <Data>\Device\NetBT_Tcpip_{FDC350A4-00C1-4D17-B653-F2A12F37A11D}</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-DNS-Client
- Date: 10/15/2017 1:54:44 PM
- Event ID: 1014
- Task Category: (1014)
- Level: Warning
- Keywords: (268435456)
- User: NETWORK SERVICE
- Computer: Anonymous
- Description:
- Name resolution for the name www.textnow.com timed out after none of the configured DNS servers responded.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-DNS-Client" Guid="{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}" />
- <EventID>1014</EventID>
- <Version>0</Version>
- <Level>3</Level>
- <Task>1014</Task>
- <Opcode>0</Opcode>
- <Keywords>0x4000000010000000</Keywords>
- <TimeCreated SystemTime="2017-10-15T18:54:44.423503000Z" />
- <EventRecordID>34791</EventRecordID>
- <Correlation />
- <Execution ProcessID="1076" ThreadID="4572" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-20" />
- </System>
- <EventData>
- <Data Name="QueryName">www.textnow.com</Data>
- <Data Name="AddressLength">128</Data>
- <Data Name="Address">020000000A080801000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-DistributedCOM
- Date: 10/15/2017 1:20:03 PM
- Event ID: 10010
- Task Category: None
- Level: Error
- Keywords: Classic
- User: ANONYMOUS\Anon&anonanon
- Computer: Anonymous
- Description:
- The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
- <EventID Qualifiers="0">10010</EventID>
- <Version>0</Version>
- <Level>2</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8080000000000000</Keywords>
- <TimeCreated SystemTime="2017-10-15T18:20:03.207030300Z" />
- <EventRecordID>34790</EventRecordID>
- <Correlation />
- <Execution ProcessID="828" ThreadID="5080" />
- <Channel>System</Channel>
- <Computer>Anonymous</Computer>
- <Security UserID="S-1-5-21-1957288335-908928117-3208654089-1001" />
- </System>
- <EventData>
- <Data Name="param1">{1B1F472E-3221-4826-97DB-2C2324D389AE}</Data>
- </EventData>
- </Event>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement