--------[ AIDA64 Business ]---------------------------------------------------------------------------------------------

                                                AIDA64 v5.92.4300/RU
                                        4.3.759-x64
                                      http://www.aida64.com/
                                              : /CUSTOM WOT_aida64.rpf [ TRIAL VERSION ]
                                             BEST
                                             Pavel
                                   Microsoft Windows 7 Ultimate 6.1.7601.24024 (Win7 RTM)
                                                  2018-05-06
                                                 20:56


--------[   ]----------------------------------------------------------------------------------------

    :
                                           ACPI x64-based PC
                                     Microsoft Windows 7 Ultimate
                                       [ TRIAL VERSION ]
      Internet Explorer                                 11.0.9600.18920
      DirectX                                           DirectX 11.1
                                           BEST
                                         Pavel
                                              [ TRIAL VERSION ]
       /                                       2018-05-06 / 20:56

     :
                                                   QuadCore Intel Core 2 Quad Q6600, 2400 MHz (9 x 267)
                                          Gigabyte GA-EP35-DS3  (3 PCI, 3 PCI-E x1, 1 PCI-E x16, 4 DDR2 DIMM, Audio, Gigabit LAN)
                                    Intel Bearlake P35
                                         [ TRIAL VERSION ]
       BIOS                                          Award Modular (06/19/09)
                                      (COM1)
                                      (LPT1)

    :
                                            Radeon RX 560 Series  (4 )
                                            Radeon RX 560 Series  (4 )
                                            Radeon RX 560 Series  (4 )
                                            Radeon RX 560 Series  (4 )
                                            Radeon RX 560 Series  (4 )
      3D-                                    AMD Radeon RX 560 (Polaris 21)
                                                 LG W3000H  [30" LCD]  (1801107018)

    :
                                         ATI Radeon HDMI @ AMD Baffin/Lexa - High Definition Audio Controller
                                         C-Media CMI8788 Audio Chip
                                         Realtek ALC889A @ Intel 82801IB ICH9 - High Definition Audio Controller [A-2]

     :
      IDE-                                    Intel(R) ICH9 Family 2 port Serial ATA Storage Controller 1 - 2921
      IDE-                                    Intel(R) ICH9 Family 2 port Serial ATA Storage Controller 2 - 2926
      IDE-                                       PCI IDE
      -                                 
                                      RDP8 CF USB Device
                                      RDP8 MS/M2 USB Device
                                      RDP8 SD/microSD USB Device
                                      SAMSUNG HD501LJ ATA Device  (500 , 7200 RPM, SATA-II)
                                      TOSHIBA A100 ATA Device  (SATA-III)
                                    HL-DT-ST DVD-RAM GSA-H55N ATA Device  (DVD+R9:10x, DVD-R9:10x, DVD+RW:20x/8x, DVD-RW:20x/6x, DVD-RAM:12x, DVD-ROM:16x, CD:48x/32x/48x DVD+RW/DVD-RW/DVD-RAM)
      SMART-                         OK

    :
      C: (NTFS)                                         [ TRIAL VERSION ]
      D: (NTFS)                                         91965  (37749  )
      E: (NTFS)                                         384971  (224447  )
                                              [ TRIAL VERSION ]

    :
                                               HID
                                               HID
                                                    HID- 

    :
        IP                                [ TRIAL VERSION ]
        MAC                               00-1D-7D-D1-18-9E
                                          Realtek PCIe GBE Family Controller  (192. [ TRIAL VERSION ])

     :
       USB1                                   Intel 82801IB ICH9 - USB Universal Host Controller [A-2]
       USB1                                   Intel 82801IB ICH9 - USB Universal Host Controller [A-2]
       USB1                                   Intel 82801IB ICH9 - USB Universal Host Controller [A-2]
       USB1                                   Intel 82801IB ICH9 - USB Universal Host Controller [A-2]
       USB1                                   Intel 82801IB ICH9 - USB Universal Host Controller [A-2]
       USB1                                   Intel 82801IB ICH9 - USB Universal Host Controller [A-2]
       USB2                                   Intel 82801IB ICH9 - USB2 Enhanced Host Controller [A-2]
       USB2                                   Intel 82801IB ICH9 - USB2 Enhanced Host Controller [A-2]
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                    Vimicro USB2.0 Camera (Audio)
      USB-                                    Vimicro USB2.0 Camera
      USB-                                       USB
      USB-                                     USB 
      USB-                                     USB 
      USB-                                     USB 

    DMI:
      DMI  BIOS                                Award Software International, Inc.
      DMI  BIOS                                   F4
      DMI                           Gigabyte Technology Co., Ltd.
      DMI                                        EP35-DS3
      DMI                                
      DMI                         [ TRIAL VERSION ]
      DMI  UUID                                [ TRIAL VERSION ]
      DMI                    Gigabyte Technology Co., Ltd.
      DMI                                 EP35-DS3
      DMI                           
      DMI                    [ TRIAL VERSION ]
      DMI                             Gigabyte Technology Co., Ltd.
      DMI                                    
      DMI                             [ TRIAL VERSION ]
      DMI Asset-                                [ TRIAL VERSION ]
      DMI                                       Desktop Case
      DMI  /                 4 / 0


--------[   ]----------------------------------------------------------------------------------------------

          
     NetBIOS                 BEST
      DNS               BEST
      DNS              
      DNS              BEST
     NetBIOS                 BEST
      DNS               BEST
      DNS              
      DNS              BEST


--------[ DMI ]---------------------------------------------------------------------------------------------------------

  [ BIOS ]

     BIOS:
                                           Award Software International, Inc.
                                                  F4
                                             06/19/2009
                                                  1 
                                   Floppy Disk, Hard Disk, CD-ROM, ATAPI ZIP, LS-120
                                             Flash BIOS, Shadow BIOS, Selectable Boot, EDD, BBS
                                 DMI, APM, ACPI, PnP
                                   PCI, USB
                                       

     BIOS:
                                                   Phoenix Technologies Ltd.
                                     http://www.phoenix.com/products
       BIOS                                 http://www.aida64.com/bios-updates

  [  ]

     :
                                           Gigabyte Technology Co., Ltd.
                                                 EP35-DS3
                                           [ TRIAL VERSION ]
        ID                       [ TRIAL VERSION ]
                                           

  [   ]

      :
                                           Gigabyte Technology Co., Ltd.
                                                 EP35-DS3
                                           [ TRIAL VERSION ]
                                            [ TRIAL VERSION ]
                                            [ TRIAL VERSION ]
                                            [ TRIAL VERSION ]

      :
                                                   Gigabyte Technology Co., Ltd.
                                     http://www.gigabyte.com/Motherboard
        BIOS                          http://www.gigabyte.com/Support
                                     http://www.aida64.com/driver-updates
       BIOS                                 http://www.aida64.com/bios-updates

  [  ]

     :
                                           Gigabyte Technology Co., Ltd.
                                           [ TRIAL VERSION ]
                                            [ TRIAL VERSION ]
                                                

  [   ]

      :
                                  8-bit Parity
                                         
                              1-Way
                                1-Way
                   5V
                           1024 
                                           4

  [  / Intel(R) Core(TM)2 Quad CPU ]

     :
                                           Intel
                                                  Intel(R) Core(TM)2 Quad CPU
                                          266 
                                     4000 
                                          2400 
                                                     Central Processor
                                       1.3 V
                                                  
                                               Socket 478
                                              Socket 775

     :
                                                   Intel Corporation
                                     http://ark.intel.com/search.aspx?q=Intel%20Core%202%20Quad%20Q6600
                                     http://www.aida64.com/driver-updates

  [ - / Internal Cache ]

     :
                                                     
                                                  
                                             Write-Back
                                       64 
                                      64 
        SRAM                           Synchronous
        SRAM                                  Synchronous
                                               

  [ - / External Cache ]

     :
                                                     
                                                  
                                             Write-Back
                                       2 
                                      4 
        SRAM                           Synchronous
        SRAM                                  Synchronous
                                               

  [   / System Memory ]

      :
                                               
                                     
                                         
      .                                  4 
                                        4

  [   / A0 ]

      :
                                              A0
                                      1024 
                                         1024 

  [   / A1 ]

      :
                                              A1
                                      1024 
                                         1024 

  [   / A2 ]

      :
                                              A2
                                      1024 
                                         1024 

  [   / A3 ]

      :
                                              A3
                                      1024 
                                         1024 

  [   / A0 ]

      :
      -                                       DIMM
                                                  1 
      .                                      667 MT/s
                                             64 
                                            64 
                                              A0
                                                    Bank0/1

  [   / A1 ]

      :
      -                                       DIMM
                                                  1 
      .                                      667 MT/s
                                             64 
                                            64 
                                              A1
                                                    Bank2/3

  [   / A2 ]

      :
      -                                       DIMM
                                                  1 
      .                                      667 MT/s
                                             64 
                                            64 
                                              A2
                                                    Bank4/5

  [   / A3 ]

      :
      -                                       DIMM
                                                  1 
      .                                      667 MT/s
                                             64 
                                            64 
                                              A3
                                                    Bank6/7

  [   / PCI ]

      :
                                       PCI
                                                     PCI
                                           
                                        32-bit
                                                   

  [   / PCI ]

      :
                                       PCI
                                                     PCI
                                           
                                        32-bit
                                                   

  [   / PCI ]

      :
                                       PCI
                                                     PCI
                                           
                                        32-bit
                                                   

  [   / PCI ]

      :
                                       PCI
                                                     PCI
                                           
                                        32-bit
                                                   

  [   / PRIMARY IDE ]

      :
                                   PRIMARY IDE
                                    On-Board IDE
                                       

  [   / SECONDARY IDE ]

      :
                                   SECONDARY IDE
                                    On-Board IDE
                                       

  [   / FDD ]

      :
                                                8251 FIFO Compatible
                                   FDD
                                    On-Board Floppy
                                       

  [   / COM1 ]

      :
                                                Serial Port 16450 Compatible
                                   COM1
                                    9 Pin Dual Inline (pin 10 cut)
                                       DB-9 pin male

  [   / COM2 ]

      :
                                                Serial Port 16450 Compatible
                                   COM2
                                    9 Pin Dual Inline (pin 10 cut)
                                       DB-9 pin male

  [   / LPT1 ]

      :
                                                Parallel Port ECP/EPP
                                   LPT1
                                    DB-25 pin female
                                       DB-25 pin female

  [   / Keyboard ]

      :
                                                Keyboard Port
                                   
                                       PS/2

  [   / Detected ]

      :
                                                Mouse Port
                                   PS/2 Mouse
                                    PS/2
                                      Detected
                                       PS/2

  [   / USB ]

      :
                                                USB
                                   USB
                                    
                                       USB

  [   / USB ]

      :
                                                USB
                                   USB
                                    
                                       USB


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   QuadCore Intel Core 2 Quad Q6600
                                             Kentsfield
                                              G0
      Engineering Sample                                
        CPUID                                      Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
       CPUID                                      000006FBh
      CPU VID                                           1.1625 V

     :
                                               1600.0 MHz  (: [ TRIAL VERSION ] MHz)
                                             6x
      CPU FSB                                           266.7 MHz  (: 266 MHz)
                                              533.3 MHz
       DRAM:FSB                              16:8

     :
       L1                                        32  per core
       L1                                      [ TRIAL VERSION ]
       L2                                            2x 4   (On-Die, ECC, ASC, Full-Speed)

      :
      ID                                  06/19/2009-P35-ICH9-6A89OG0MC-00
                                          Gigabyte GA-EP35-DS3  (3 PCI, 3 PCI-E x1, 1 PCI-E x16, 4 DDR2 DIMM, Audio, Gigabit LAN)

       ():
                                    Intel Bearlake P35
                                          5-5-5-18  (CL-RCD-RP-RAS)
      Command Rate (CR)                                 [ TRIAL VERSION ]
      DIMM1: OCZ XTC SLI OCZ2N10661G                    1  DDR2-667 DDR2 SDRAM  (5-5-5-15 @ 333 )  (4-4-4-13 @ 270 )
      DIMM2: OCZ XTC SLI OCZ2N10661G                    [ TRIAL VERSION ]
      DIMM3: OCZ XTC SLI OCZ2N10661G                    [ TRIAL VERSION ]
      DIMM4: OCZ XTC SLI OCZ2N10661G                    [ TRIAL VERSION ]

     BIOS:
       BIOS                                  06/19/09
       BIOS                            04/26/17
       Award BIOS                                    Award Modular BIOS v6.00PG
       Award BIOS                              EP35-DS3 F4
      DMI  BIOS                                   F4

      :
                                            AMD Radeon RX 560 (Polaris 21)
                                       Polaris 21 XT  (PCI Express 3.0 x8 1002 / 67FF, Rev CF)
                                               214   (original: [ TRIAL VERSION ] MHz)
                                           300   (original: 1750 MHz)


--------[  ]----------------------------------------------------------------------------------------------

     :
                                  
                                         
                              
                          


--------[  ]-----------------------------------------------------------------------------------------------------

     :
                                              ITE IT8718F  (ISA 290h)
                                            Diode, Asus ASP1106  (ATI-Diode, 20h)
                                          Gigabyte EP31 / EP35 / G33 / P31 / P35 Series
                               

    :
                                          37 C  (99 F)
                                                      28 C  (82 F)
       1 /  1                                     27 C  (81 F)
       1 /  2                                     28 C  (82 F)
       1 /  3                                     23 C  (73 F)
       1 /  4                                     32 C  (90 F)
                                                  32 C  (90 F)
      SAMSUNG HD501LJ                                   [ TRIAL VERSION ]
      TOSHIBA A100                                      [ TRIAL VERSION ]

    :
                                                   910 RPM
                                         1929 RPM
                                    0%

    :
                                                  1.184 V
      CPU VID                                           1.163 V
      +3.3 V                                            3.392 V
      +12 V                                             [ TRIAL VERSION ]
      +5 V                                        5.376 V
       VBAT                                      3.296 V
      DIMM                                              2.128 V
                                                  [ TRIAL VERSION ]
                                                [ TRIAL VERSION ]

     :
                                                [ TRIAL VERSION ]
      GPU VRM                                           [ TRIAL VERSION ]

     :
                                    [ TRIAL VERSION ]
                                                [ TRIAL VERSION ]
      GPU VRM                                           [ TRIAL VERSION ]
      Debug Info F                                      FFFF 02E6 015E FFFF 0000
      Debug Info T                                      37 28 254
      Debug Info V                                      4A 85 D4 B9 14 02 06 C8 CE


--------[  ]----------------------------------------------------------------------------------------------------------

     :
                                                   QuadCore Intel Core 2 Quad Q6600, 2400 MHz (9 x 267)
                                             Kentsfield
                                              G0
                                        x86, x86-64, MMX, SSE, SSE2, SSE3, SSSE3
                                         [ TRIAL VERSION ]
      ./.                             6x / 9x
      Engineering Sample                                
       L1                                        32  per core
       L1                                      [ TRIAL VERSION ]
       L2                                            2x 4   (On-Die, ECC, ASC, Full-Speed)

       :
                                              775 Contact FC-LGA6
                                          37.5 mm x 37.5 mm
                                       [ TRIAL VERSION ] .
                                  8M, 65 nm, CMOS, Cu, Low-K Inter-Layer, 2nd Gen Strained Si
                                         [ TRIAL VERSION ] mm2
                                   1.325 V
       I/O                                    1.325 V
                                        95 / 105 W @ 2.40 GHz
                                    146.6 W @ 2.40 GHz

     :
                                                   Intel Corporation
                                     http://ark.intel.com/search.aspx?q=Intel%20Core%202%20Quad%20Q6600
                                     http://www.aida64.com/driver-updates

    Multi CPU:
      ID                                  OEM00000 PROD00000000
      CPU #1                                            Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz, 2400 
      CPU #2                                            Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz, 2400 
      CPU #3                                            Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz, 2400 
      CPU #4                                            Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz, 2400 

     :
       1 /  1                                     0%
       1 /  2                                     0%
       1 /  3                                     0%
       1 /  4                                     0%


--------[ CPUID ]-------------------------------------------------------------------------------------------------------

     CPUID:
       CPUID                               GenuineIntel
        CPUID                                      Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
       CPUID                                      000006FBh
        IA                            00h  ()
                                  3Eh / MC 10h  (LGA775)
                               B6h
      HTT / CMP                                         0 / 4
       Tjmax                                 90 C  (194 F)

     :
      64- x86- (AMD64, Intel64)            
      AMD 3DNow!                                         
      AMD 3DNow! Professional                            
      AMD 3DNowPrefetch                                  
      AMD Enhanced 3DNow!                                
      AMD Extended MMX                                   
      AMD FMA4                                           
      AMD MisAligned SSE                                 
      AMD SSE4A                                          
      AMD XOP                                            
      Cyrix Extended MMX                                 
      Enhanced REP MOVSB/STOSB                           
      Float-16 Conversion Instructions                   
      IA-64                                              
      IA AES Extensions                                  
      IA AVX                                             
      IA AVX2                                            
      IA AVX-512 (AVX512F)                               
      IA AVX-512 52-bit Integer Instructions (AVX512IFMA52) 
      IA AVX-512 Byte and Word Instructions (AVX512BW)   
      IA AVX-512 Conflict Detection Instructions (AVX512CD) 
      IA AVX-512 Doubleword and Quadword Instructions (AVX512DQ) 
      IA AVX-512 Exponential and Reciprocal Instructions (AVX512ER) 
      IA AVX-512 FMAPS (AVX512_4FMAPS)                   
      IA AVX-512 Neural Network Instructions (AVX512_4VNNIW) 
      IA AVX-512 Prefetch Instructions (AVX512PF)        
      IA AVX-512 Vector Bit Manipulation Instructions (AVX512VBMI) 
      IA AVX-512 Vector Length Extensions (AVX512VL)     
      IA AVX-512 VPOPCNTDQ                               
      IA BMI1                                            
      IA BMI2                                            
      IA FMA                                             
      IA MMX                                            
      IA SHA Extensions                                  
      IA SSE                                            
      IA SSE2                                           
      IA SSE3                                           
      IA Supplemental SSE3                              
      IA SSE4.1                                          
      IA SSE4.2                                          
      VIA Alternate Instruction Set                      
       ADCX / ADOX                             
       CLFLUSH                                
       CLFLUSHOPT                              
       CLWB                                    
       CMPXCHG8B                              
       CMPXCHG16B                             
       Conditional Move                       
       INVPCID                                 
       LAHF / SAHF                            
       LZCNT                                   
       MONITOR / MWAIT                        
       MONITORX / MWAITX                       
       MOVBE                                   
       PCLMULQDQ                               
       PCOMMIT                                 
       POPCNT                                  
       PREFETCHWT1                             
       RDFSBASE / RDGSBASE / WRFSBASE / WRGSBASE 
       RDRAND                                  
       RDSEED                                  
       RDTSCP                                  
       SKINIT / STGI                           
       SYSCALL / SYSRET                        
       SYSENTER / SYSEXIT                     
      Trailing Bit Manipulation Instructions             
       VIA FEMMS                               

     :
      Advanced Cryptography Engine (ACE)                 
      Advanced Cryptography Engine 2 (ACE2)              
      Control-flow Enforcement Technology (CET)          
         (DEP, NX, EDB)           
      Hardware Random Number Generator (RNG)             
      Hardware Random Number Generator 2 (RNG2)          
      Memory Protection Extensions (MPX)                 
      PadLock Hash Engine (PHE)                          
      PadLock Hash Engine 2 (PHE2)                       
      PadLock Montgomery Multiplier (PMM)                
      PadLock Montgomery Multiplier 2 (PMM2)             
         (PSN)                    
      Protection Keys for User-Mode Pages (PKU)          
      Read Processor ID (RDPID)                          
      Safer Mode Extensions (SMX)                        
      Secure Memory Encryption (SME)                     
      SGX Launch Configuration (SGX_LC)                  
      Software Guard Extensions (SGX)                    
      Supervisor Mode Access Prevention (SMAP)           
      Supervisor Mode Execution Protection (SMEP)        
      User-Mode Instruction Prevention (UMIP)            

     :
      APM Power Reporting                                
      Application Power Management (APM)                 
      Automatic Clock Control                           
      Configurable TDP (cTDP)                            
      Connected Standby                                  
      Core C6 State (CC6)                                
      Digital Thermometer                               
      Dynamic FSB Frequency Switching                    
      Enhanced Halt State (C1E)                         , 
      Enhanced SpeedStep Technology (EIST, ESS)         , 
      Frequency ID Control                               
      Hardware P-State Control                           
      Hardware Thermal Control (HTC)                     
      LongRun                                            
      LongRun Table Interface                            
      Overstress                                         
      Package C6 State (PC6)                             
      Parallax                                           
      PowerSaver 1.0                                     
      PowerSaver 2.0                                     
      PowerSaver 3.0                                     
      Processor Duty Cycle Control                      
      Running Average Power Limit (RAPL)                 
      Software Thermal Control                           
      SpeedShift (SST, HWP)                              
                                                
      Thermal Monitor 1                                 
      Thermal Monitor 2                                 
      Thermal Monitor 3                                  
      Thermal Monitoring                                 
      Thermal Trip                                       
      Voltage ID Control                                 

     :
      Encrypted State (SEV-ES)                           
      Extended Page Table (EPT)                          
      Hypervisor                                        
       INVEPT                                  
       INVVPID                                 
      Nested Paging (NPT, RVI)                           
      Secure Encrypted Virtualization (SEV)              
      Secure Virtual Machine (SVM, Pacifica)             
      Virtual Machine Extensions (VMX, Vanderpool)      
      Virtual Processor ID (VPID)                        

     CPUID:
      1 GB Page Size                                     
      36-bit Page Size Extension                        
      5-Level Paging                                     
      64-bit DS Area                                    
      Adaptive Overclocking                              
      Address Region Registers (ARR)                     
      Code and Data Prioritization Technology (CDP)      
      Core Performance Boost (CPB)                       
      Core Performance Counters                          
      CPL Qualified Debug Store                         
      Data Breakpoint Extension                          
      Debug Trace Store                                 
      Debugging Extension                               
      Deprecated FPU CS and FPU DS                       
      Direct Cache Access                                
      Dynamic Acceleration Technology (IDA)              
      Dynamic Configurable TDP (DcTDP)                   
      Extended APIC Register Space                       
      Fast Save & Restore                               
      Hardware Lock Elision (HLE)                        
      Hybrid Boost                                       
      Hyper-Threading Technology (HTT)                   
      Instruction Based Sampling                         
      Invariant Time Stamp Counter                      
      L1 Context ID                                      
      L2I Performance Counters                           
      Lightweight Profiling                              
      Local APIC On Chip                                
      Machine Check Architecture (MCA)                  
      Machine Check Exception (MCE)                     
      Memory Configuration Registers (MCR)               
      Memory Type Range Registers (MTRR)                
      Model Specific Registers (MSR)                    
      NB Performance Counters                            
      Page Attribute Table (PAT)                        
      Page Global Extension                             
      Page Size Extension (PSE)                         
      Pending Break Event (PBE)                         
      Performance Time Stamp Counter (PTSC)              
      Physical Address Extension (PAE)                  
      Platform Quality of Service Enforcement (PQE)      
      Platform Quality of Service Monitoring (PQM)       
      Process Context Identifiers (PCID)                 
      Processor Feedback Interface                       
      Processor Trace (PT)                               
      Restricted Transactional Memory (RTM)              
      Self-Snoop                                        
      Time Stamp Counter (TSC)                          
      Time Stamp Counter Adjust                          
      Turbo Boost                                        
      Virtual Mode Extension                            
      Watchdog Timer                                     
      x2APIC                                             
      XGETBV / XSETBV OS Enabled                         
      XSAVE / XRSTOR / XSETBV / XGETBV Extended States   
      XSAVEOPT                                           

    CPUID Registers (CPU #1):
      CPUID 00000000                                    0000000A-756E6547-6C65746E-49656E69 [GenuineIntel]
      CPUID 00000001                                    000006FB-00040800-0000E3BD-BFEBFBFF
      CPUID 00000002                                    05B0B101-005657F0-00000000-2CB43049
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000004                                    0C000121-01C0003F-0000003F-00000001 [SL 00]
      CPUID 00000004                                    0C000122-01C0003F-0000003F-00000001 [SL 01]
      CPUID 00000004                                    0C004143-03C0003F-00000FFF-00000001 [SL 02]
      CPUID 00000005                                    00000040-00000040-00000003-00000020
      CPUID 00000006                                    00000001-00000002-00000001-00000000
      CPUID 00000007                                    00000000-00000000-00000000-00000000
      CPUID 00000008                                    00000400-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    07280202-00000000-00000000-00000503
      CPUID 80000000                                    80000008-00000000-00000000-00000000
      CPUID 80000001                                    00000000-00000000-00000001-20100000
      CPUID 80000002                                    65746E49-2952286C-726F4320-4D542865 [Intel(R) Core(TM]
      CPUID 80000003                                    51203229-20646175-20555043-51202020 [)2 Quad CPU    Q]
      CPUID 80000004                                    30303636-20402020-30342E32-007A4847 [6600  @ 2.40GHz]
      CPUID 80000005                                    00000000-00000000-00000000-00000000
      CPUID 80000006                                    00000000-00000000-10008040-00000000
      CPUID 80000007                                    00000000-00000000-00000000-00000000
      CPUID 80000008                                    00003024-00000000-00000000-00000000

    CPUID Registers (CPU #2):
      CPUID 00000000                                    0000000A-756E6547-6C65746E-49656E69 [GenuineIntel]
      CPUID 00000001                                    000006FB-01040800-0000E3BD-BFEBFBFF
      CPUID 00000002                                    05B0B101-005657F0-00000000-2CB43049
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000004                                    0C000121-01C0003F-0000003F-00000001 [SL 00]
      CPUID 00000004                                    0C000122-01C0003F-0000003F-00000001 [SL 01]
      CPUID 00000004                                    0C004143-03C0003F-00000FFF-00000001 [SL 02]
      CPUID 00000005                                    00000040-00000040-00000003-00000020
      CPUID 00000006                                    00000001-00000002-00000001-00000000
      CPUID 00000007                                    00000000-00000000-00000000-00000000
      CPUID 00000008                                    00000400-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    07280202-00000000-00000000-00000503
      CPUID 80000000                                    80000008-00000000-00000000-00000000
      CPUID 80000001                                    00000000-00000000-00000001-20100000
      CPUID 80000002                                    65746E49-2952286C-726F4320-4D542865 [Intel(R) Core(TM]
      CPUID 80000003                                    51203229-20646175-20555043-51202020 [)2 Quad CPU    Q]
      CPUID 80000004                                    30303636-20402020-30342E32-007A4847 [6600  @ 2.40GHz]
      CPUID 80000005                                    00000000-00000000-00000000-00000000
      CPUID 80000006                                    00000000-00000000-10008040-00000000
      CPUID 80000007                                    00000000-00000000-00000000-00000000
      CPUID 80000008                                    00003024-00000000-00000000-00000000

    CPUID Registers (CPU #3):
      CPUID 00000000                                    0000000A-756E6547-6C65746E-49656E69 [GenuineIntel]
      CPUID 00000001                                    000006FB-02040800-0000E3BD-BFEBFBFF
      CPUID 00000002                                    05B0B101-005657F0-00000000-2CB43049
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000004                                    0C000121-01C0003F-0000003F-00000001 [SL 00]
      CPUID 00000004                                    0C000122-01C0003F-0000003F-00000001 [SL 01]
      CPUID 00000004                                    0C004143-03C0003F-00000FFF-00000001 [SL 02]
      CPUID 00000005                                    00000040-00000040-00000003-00000020
      CPUID 00000006                                    00000001-00000002-00000001-00000000
      CPUID 00000007                                    00000000-00000000-00000000-00000000
      CPUID 00000008                                    00000400-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    07280202-00000000-00000000-00000503
      CPUID 80000000                                    80000008-00000000-00000000-00000000
      CPUID 80000001                                    00000000-00000000-00000001-20100000
      CPUID 80000002                                    65746E49-2952286C-726F4320-4D542865 [Intel(R) Core(TM]
      CPUID 80000003                                    51203229-20646175-20555043-51202020 [)2 Quad CPU    Q]
      CPUID 80000004                                    30303636-20402020-30342E32-007A4847 [6600  @ 2.40GHz]
      CPUID 80000005                                    00000000-00000000-00000000-00000000
      CPUID 80000006                                    00000000-00000000-10008040-00000000
      CPUID 80000007                                    00000000-00000000-00000000-00000000
      CPUID 80000008                                    00003024-00000000-00000000-00000000

    CPUID Registers (CPU #4):
      CPUID 00000000                                    0000000A-756E6547-6C65746E-49656E69 [GenuineIntel]
      CPUID 00000001                                    000006FB-03040800-0000E3BD-BFEBFBFF
      CPUID 00000002                                    05B0B101-005657F0-00000000-2CB43049
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000004                                    0C000121-01C0003F-0000003F-00000001 [SL 00]
      CPUID 00000004                                    0C000122-01C0003F-0000003F-00000001 [SL 01]
      CPUID 00000004                                    0C004143-03C0003F-00000FFF-00000001 [SL 02]
      CPUID 00000005                                    00000040-00000040-00000003-00000020
      CPUID 00000006                                    00000001-00000002-00000001-00000000
      CPUID 00000007                                    00000000-00000000-00000000-00000000
      CPUID 00000008                                    00000400-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    07280202-00000000-00000000-00000503
      CPUID 80000000                                    80000008-00000000-00000000-00000000
      CPUID 80000001                                    00000000-00000000-00000001-20100000
      CPUID 80000002                                    65746E49-2952286C-726F4320-4D542865 [Intel(R) Core(TM]
      CPUID 80000003                                    51203229-20646175-20555043-51202020 [)2 Quad CPU    Q]
      CPUID 80000004                                    30303636-20402020-30342E32-007A4847 [6600  @ 2.40GHz]
      CPUID 80000005                                    00000000-00000000-00000000-00000000
      CPUID 80000006                                    00000000-00000000-10008040-00000000
      CPUID 80000007                                    00000000-00000000-00000000-00000000
      CPUID 80000008                                    00003024-00000000-00000000-00000000

    MSR Registers:
      MSR 00000017                                      0010-0000-8840-8928 [PlatID = 4]
      MSR 0000001B                                      0000-0000-FEE0-0900
      MSR 0000002A                                      0000-0000-4248-0000
      MSR 0000008B                                      0000-00B6-0000-0000
      MSR 000000CD                                      0000-0000-0000-0800
      MSR 000000CE                                      001B-0928-7F7F-071A
      MSR 000000E7                                      0000-0FD3-8D54-4586 [S200]
      MSR 000000E7                                      0000-0FD3-8D7B-DB08 [S200]
      MSR 000000E7                                      0000-0FD3-8DA1-4C3E
      MSR 000000E8                                      0000-0F4B-DBEB-F8DB [S200]
      MSR 000000E8                                      0000-0F4B-DC03-8321 [S200]
      MSR 000000E8                                      0000-0F4B-DD33-D9C6
      MSR 000000EE                                      0000-0000-837D-4B00
      MSR 0000011E                                      0000-0000-BE70-2109
      MSR 00000198                                      0928-0928-0632-0628
      MSR 00000198                                      0928-0928-0632-0628 [S200]
      MSR 00000198                                      0928-0928-0632-0628 [S200]
      MSR 00000199                                      0000-0000-0000-0928
      MSR 0000019A                                      0000-0000-0000-0008
      MSR 0000019B                                      0000-0000-0000-0000
      MSR 0000019C                                      0000-0000-8840-0000
      MSR 0000019C                                      0000-0000-8840-0000 [S200]
      MSR 0000019C                                      0000-0000-8840-0000 [S200]
      MSR 0000019D                                      0000-0000-0000-061B
      MSR 000001A0                                      0000-0040-6287-2489
      MSR 00000480                                      005A-0800-0000-000B
      MSR 00000481                                      0000-003F-0000-0016
      MSR 00000482                                      F7F9-FFFE-0401-E172
      MSR 00000483                                      0003-EFFF-0003-6DFF
      MSR 00000484                                      0000-1FFF-0000-11FF
      MSR 00000485                                      0000-0000-0004-03C0
      MSR 00000486                                      0000-0000-8000-0021
      MSR 00000487                                      0000-0000-FFFF-FFFF
      MSR 00000488                                      0000-0000-0000-2000
      MSR 00000489                                      0000-0000-0000-27FF
      MSR 0000048A                                      0000-0000-0000-002C
      MSR 0000048B                                      0000-0001-0000-0000


--------[   ]---------------------------------------------------------------------------------------------

      :
      ID                                  06/19/2009-P35-ICH9-6A89OG0MC-00
                                          Gigabyte GA-EP35-DS3

      FSB:
                                                 Intel AGTL+
                                              64 
                                         267  (QDR)
                                      1067 
                                   8533 /

      :
                                                 Dual DDR2 SDRAM
                                              128 
       DRAM:FSB                              16:8
                                         533  (DDR)
                                      1067 
                                   [ TRIAL VERSION ] /

      :
                                                 Intel Direct Media Interface

        :
                                         1 LGA775
                                       [ TRIAL VERSION ]
                                              4 DDR2 DIMM
                                    Audio, Gigabit LAN
      -                                       ATX
                                   210 mm x 300 mm
                                    P35
                                   [ TRIAL VERSION ]

      :
                                                   Gigabyte Technology Co., Ltd.
                                     http://www.gigabyte.com/Motherboard
        BIOS                          http://www.gigabyte.com/Support
                                     http://www.aida64.com/driver-updates
       BIOS                                 http://www.aida64.com/bios-updates


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   [ TRIAL VERSION ]
                                                  [ TRIAL VERSION ]
                                                1718 
                                                [ TRIAL VERSION ]

     :
                                                   10234 
                                                  4007 
                                                6226 
                                                39 %

     :
                                            C:\pagefile.sys
      /                       6141  / 6141 
                                           6141 
      /                           432  / 1346 
                                                7 %

    Physical Address Extension (PAE):
                                        
                                        
                                                


--------[ SPD ]---------------------------------------------------------------------------------------------------------

  [ DIMM1: OCZ XTC SLI OCZ2N10661G ]

      :
                                               OCZ XTC SLI OCZ2N10661G
                                           
                                            1  (2 ranks, 4 banks)
                                               Unbuffered DIMM
                                               DDR2 SDRAM
                                          DDR2-667 (333 )
                                            64 bit
                                        SSTL 1.8
                                  
                                       (7.8 us), Self-Refresh

     :
      @ 333                                          5-5-5-15  (CL-RCD-RP-RAS) / 19-35-3-5-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 270                                          4-4-4-13  (CL-RCD-RP-RAS) / 15-29-3-5-3-3  (RC-RFC-RRD-WR-WTR-RTP)

    Enhanced Performance Profile:
                                              High Frequency
                    
                                          DDR2-1066 (533 )
                                       2.1 V
                                          5-5-5-15  (CL-RCD-RP-RAS)
      Row Cycle Time (tRC)                              22T
      Command Rate (CR)                                 2T
      Write Recovery Time (tWR)                         6T

      :
      Analysis Probe                                    
      FET Switch External                               
      Weak Driver                                       

      :
                                                   OCZ Technology Group, Inc.
                                     http://www.ocztechnology.com/products/memory/

  [ DIMM2: [ TRIAL VERSION ] ]

      :
                                               [ TRIAL VERSION ]
                                           
                                            1  (2 ranks, 4 banks)
                                               [ TRIAL VERSION ]
                                               DDR2 SDRAM
                                          DDR2-667 (333 )
                                            64 bit
                                        SSTL 1.8
                                  
                                       (7.8 us), Self-Refresh

     :
      @ 333                                          5-5-5-15  (CL-RCD-RP-RAS) / 19-35-3-5-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 270                                          4-4-4-13  (CL-RCD-RP-RAS) / 15-29-3-5-3-3  (RC-RFC-RRD-WR-WTR-RTP)

    Enhanced Performance Profile:
                                              High Frequency
                    
                                          DDR2-1066 (533 )
                                       2.1 V
                                          5-5-5-15  (CL-RCD-RP-RAS)
      Row Cycle Time (tRC)                              22T
      Command Rate (CR)                                 2T
      Write Recovery Time (tWR)                         6T

      :
      Analysis Probe                                    
      FET Switch External                               
      Weak Driver                                       

      :
                                                   OCZ Technology Group, Inc.
                                     http://www.ocztechnology.com/products/memory/

  [ DIMM3: [ TRIAL VERSION ] ]

      :
                                               [ TRIAL VERSION ]
                                           
                                            1  (2 ranks, 4 banks)
                                               [ TRIAL VERSION ]
                                               DDR2 SDRAM
                                          DDR2-667 (333 )
                                            64 bit
                                        SSTL 1.8
                                  
                                       (7.8 us), Self-Refresh

     :
      @ 333                                          5-5-5-15  (CL-RCD-RP-RAS) / 19-35-3-5-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 270                                          4-4-4-13  (CL-RCD-RP-RAS) / 15-29-3-5-3-3  (RC-RFC-RRD-WR-WTR-RTP)

    Enhanced Performance Profile:
                                              High Frequency
                    
                                          DDR2-1066 (533 )
                                       2.1 V
                                          5-5-5-15  (CL-RCD-RP-RAS)
      Row Cycle Time (tRC)                              22T
      Command Rate (CR)                                 2T
      Write Recovery Time (tWR)                         6T

      :
      Analysis Probe                                    
      FET Switch External                               
      Weak Driver                                       

      :
                                                   OCZ Technology Group, Inc.
                                     http://www.ocztechnology.com/products/memory/

  [ DIMM4: [ TRIAL VERSION ] ]

      :
                                               [ TRIAL VERSION ]
                                           
                                            1  (2 ranks, 4 banks)
                                               [ TRIAL VERSION ]
                                               DDR2 SDRAM
                                          DDR2-667 (333 )
                                            64 bit
                                        SSTL 1.8
                                  
                                       (7.8 us), Self-Refresh

     :
      @ 333                                          5-5-5-15  (CL-RCD-RP-RAS) / 19-35-3-5-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 270                                          4-4-4-13  (CL-RCD-RP-RAS) / 15-29-3-5-3-3  (RC-RFC-RRD-WR-WTR-RTP)

    Enhanced Performance Profile:
                                              High Frequency
                    
                                          DDR2-1066 (533 )
                                       2.1 V
                                          5-5-5-15  (CL-RCD-RP-RAS)
      Row Cycle Time (tRC)                              22T
      Command Rate (CR)                                 2T
      Write Recovery Time (tWR)                         6T

      :
      Analysis Probe                                    
      FET Switch External                               
      Weak Driver                                       

      :
                                                   OCZ Technology Group, Inc.
                                     http://www.ocztechnology.com/products/memory/


--------[  ]------------------------------------------------------------------------------------------------------

  [  : Intel Bearlake P35 ]

      :
                                            Intel Bearlake P35
       Intel                                   Salt Creek
        FSB                       FSB800, FSB1066, FSB1333
                                DDR2-667, DDR2-800, DDR3-800, DDR3-1066, DDR3-1333 SDRAM
                                 8 
       / Stepping                                 02 / A2
                                              1226 Pin FC-BGA
                                          34 mm x 34 mm
                                  90 nm
                                   1.25 V
      TDP                                               18 W
      In-Order Queue Depth                              12

     :
                                                     Dual Channel  (128 )
                                           Dual Channel  (128 )

     :
      CAS Latency (CL)                                  5T
      RAS To CAS Delay (tRCD)                           5T
      RAS Precharge (tRP)                               5T
      RAS Active Time (tRAS)                            18T
      Row Refresh Cycle Time (tRFC)                     42T
      Command Rate (CR)                                 2T
      RAS To RAS Delay (tRRD)                           3T
      Write Recovery Time (tWR)                         6T
      Read To Read Delay (tRTR)                         Same Rank: 4T, Different Rank: 6T
      Read To Write Delay (tRTW)                        8T
      Write To Read Delay (tWTR)                        3T, Same Rank: 11T, Different Rank: 5T
      Write To Write Delay (tWTW)                       Same Rank: 4T, Different Rank: 6T
      Read To Precharge Delay (tRTP)                    3T
      Write To Precharge Delay (tWTP)                   14T
      Precharge To Precharge Delay (tPTP)               1T
      Write CAS Latency (tWCL)                          4T
      Write RAS To CAS Delay (tRCDW)                    5T
      CKE Min. Pulse Width (tCKE)                       Low Phase: 3T, High Phase: 3T
      Refresh Period (tREF)                             4160T
      DRAM Read ODT                                     3T
      DRAM Write ODT                                    6T
      MCH Read ODT                                      8T
      Performance Level                                 4
      Read Delay Phase Adjust                           Neutral
      DIMM1 Clock Fine Delay                            7T
      DIMM2 Clock Fine Delay                            5T
      DIMM3 Clock Fine Delay                            9T
      DIMM4 Clock Fine Delay                            5T
      Burst Length (BL)                                 8

     :
      ECC                                                
      ChipKill ECC                                       
      RAID                                               
      ECC Scrubbing                                      

     :
       DRAM 1                                     1   (DDR2 SDRAM)
       DRAM 2                                     1   (DDR2 SDRAM)
       DRAM 3                                     1   (DDR2 SDRAM)
       DRAM 4                                     1   (DDR2 SDRAM)

     PCI Express:
      PCI-E 1.0 x16 port #2                              @ x8  (AMD Baffin/Lexa - High Definition Audio Controller, AMD Radeon RX 560 (Polaris 21) Video Adapter)

     :
                                                   Intel Corporation
                                     http://www.intel.com/products/chipsets
                                       http://support.intel.com/support/chipsets
       BIOS                                 http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [  : [ TRIAL VERSION ] ]

      :
                                               [ TRIAL VERSION ]
       Intel                                   Salt Creek
       / Stepping                                 92 / A2
                                              676 Pin mBGA
                                          31 mm x 31 mm
                                  130 nm
                                   1.05 V
      TDP                                               4.3 W

    High Definition Audio:
                                               Realtek ALC889A
      ID                                          10EC0885h / 1458A002h
                                            1001h
                                               Audio

     PCI Express:
      PCI-E 1.0 x1 port #1                              
      PCI-E 1.0 x1 port #2                               @ x1  (PLX Technology ExpressLane PEX 8112 PCI Express-to-PCI Bridge --> C-Media CMI8788 Audio Chip)
      PCI-E 1.0 x1 port #4                               @ x1  (Gigabyte GBB363 SATA-II RAID Controller)
      PCI-E 1.0 x1 port #5                               @ x1  (Realtek RTL8168B/8111B PCI-E Gigabit Ethernet Adapter)

     :
                                                   Intel Corporation
                                     http://www.intel.com/products/chipsets
                                       http://support.intel.com/support/chipsets
       BIOS                                 http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates


--------[ BIOS ]--------------------------------------------------------------------------------------------------------

     BIOS:
       BIOS                                          Award Modular
       BIOS                                       F4
       Award BIOS                                    Award Modular BIOS v6.00PG
       Award BIOS                              EP35-DS3 F4
      SMBIOS Version                                    2.4
      UEFI Boot                                         
       BIOS                                  06/19/09
       BIOS                            04/26/17

     BIOS:
                                                   Phoenix Technologies Ltd.
                                     http://www.phoenix.com/products
       BIOS                                 http://www.aida64.com/bios-updates


--------[  ]----------------------------------------------------------------------------------------------------

    aida64.exe               C:\ProgramData\aida64business\aida64.exe                                      32         70892             69 
    amddvr.exe               C:\Program Files\AMD\CNext\CNext\amddvr.exe                                   64          4716            146 
    amdow.exe                C:\Program Files\AMD\CNext\CNext\amdow.exe                                    64           688              2 
    AsusAudioCenter.exe      C:\Program Files\ASUS Xonar Essence STX Audio\Customapp\ASUSAUDIOCENTER.EXE   32         20072             12 
    atieclxx.exe             C:\Windows\system32\atieclxx.exe                                              64          8884              2 
    atiesrxx.exe             C:\Windows\system32\atiesrxx.exe                                              64          5424              1 
    csrss.exe                C:\Windows\system32\csrss.exe                                                 64          4812              2 
    csrss.exe                C:\Windows\system32\csrss.exe                                                 64          9672              3 
    dwm.exe                  C:\Windows\system32\Dwm.exe                                                   64         47684             31 
    explorer.exe             C:\Windows\Explorer.EXE                                                       64         75860             45 
    HsMgr.exe                C:\Windows\SysWOW64\HsMgr.exe                                                 32          6576              1 
    HsMgr64.exe              C:\Windows\system\HsMgr64.exe                                                 64          7288              2 
    lsass.exe                C:\Windows\system32\lsass.exe                                                 64         13864              5 
    lsm.exe                  C:\Windows\system32\lsm.exe                                                   64          4824              2 
    RadeonSettings.exe       C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe                           64          3048            279 
    RAVCpl64.exe             C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe                               64         15168              9 
    SearchFilterHost.exe     C:\Windows\system32\SearchFilterHost.exe                                      64          7204              2 
    SearchIndexer.exe        C:\Windows\system32\SearchIndexer.exe                                         64         51584             56 
    SearchProtocolHost.exe   C:\Windows\system32\SearchProtocolHost.exe                                    64          8760              3 
    services.exe             C:\Windows\system32\services.exe                                              64         10960              5 
    smss.exe                                                                                               64          1320              0 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         11152              5 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64         24380             25 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64         15876              7 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         21420             11 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         14452              7 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         35828             21 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          7968              3 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         16412             13 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          8584              8 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64          8056              4 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          5768              1 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64         16876             12 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          9448              5 
    System Idle Process                                                                                                     24              0 
    System                                                                                                 64          2856              0 
    taskhost.exe             C:\Windows\system32\taskhost.exe                                              64         13844              8 
    TechReport.exe           D:\Users\pavel\Downloads\TechReport\TechReport.exe                            32         75156             77 
    vivaldi.exe              C:\Users\Pavel\AppData\Local\Vivaldi\Application\vivaldi.exe                  32         73544             42 
    vivaldi.exe              C:\Users\Pavel\AppData\Local\Vivaldi\Application\vivaldi.exe                  32           174            148 
    vivaldi.exe              C:\Users\Pavel\AppData\Local\Vivaldi\Application\vivaldi.exe                  32           116             79 
    vivaldi.exe              C:\Users\Pavel\AppData\Local\Vivaldi\Application\vivaldi.exe                  32         74024             38 
    vivaldi.exe              C:\Users\Pavel\AppData\Local\Vivaldi\Application\vivaldi.exe                  32           166            140 
    vivaldi.exe              C:\Users\Pavel\AppData\Local\Vivaldi\Application\vivaldi.exe                  32         88072             49 
    vivaldi.exe              C:\Users\Pavel\AppData\Local\Vivaldi\Application\vivaldi.exe                  32           111             77 
    vivaldi.exe              C:\Users\Pavel\AppData\Local\Vivaldi\Application\vivaldi.exe                  32           142            126 
    vivaldi.exe              C:\Users\Pavel\AppData\Local\Vivaldi\Application\vivaldi.exe                  32         89168             70 
    vivaldi.exe              C:\Users\Pavel\AppData\Local\Vivaldi\Application\vivaldi.exe                  32         63600             38 
    vivaldi.exe              C:\Users\Pavel\AppData\Local\Vivaldi\Application\vivaldi.exe                  32           136             86 
    vivaldi.exe              C:\Users\Pavel\AppData\Local\Vivaldi\Application\vivaldi.exe                  32           140            115 
    vivaldi.exe              C:\Users\Pavel\AppData\Local\Vivaldi\Application\vivaldi.exe                  32         89264             65 
    vivaldi.exe              C:\Users\Pavel\AppData\Local\Vivaldi\Application\vivaldi.exe                  32          7180              2 
    vivaldi.exe              C:\Users\Pavel\AppData\Local\Vivaldi\Application\vivaldi.exe                  32           107             76 
    vivaldi.exe              C:\Users\Pavel\AppData\Local\Vivaldi\Application\vivaldi.exe                  32         88988             75 
    vivaldi.exe              C:\Users\Pavel\AppData\Local\Vivaldi\Application\vivaldi.exe                  32           112             73 
    wininit.exe              C:\Windows\system32\wininit.exe                                               64          4976              1 
    winlogon.exe             C:\Windows\system32\winlogon.exe                                              64          8020              3 
    WmiPrvSE.exe             C:\Windows\system32\wbem\wmiprvse.exe                                         32          9620              3 
    wmpnetwk.exe             C:\Program Files\Windows Media Player\wmpnetwk.exe                            64         11700             10 
    WUDFHost.exe             C:\Windows\System32\WUDFHost.exe                                              32          6676              2 


--------[   ]------------------------------------------------------------------------------------------

    1394ohci         1394 OHCI Compliant Host Controller                                     1394ohci.sys          6.1.7601.17514                        
    ACPI              Microsoft ACPI                                                  ACPI.sys              6.1.7601.17514                        
    AcpiPmi          ACPI Power Meter Driver                                                 acpipmi.sys           6.1.7601.17514                        
    adp94xx          adp94xx                                                                 adp94xx.sys           1.6.6.4                               
    adpahci          adpahci                                                                 adpahci.sys           1.6.6.1                               
    adpu320          adpu320                                                                 adpu320.sys           7.2.0.0                               
    afcdp            afcdp                                                                   afcdp.sys             1.0.0.3596                 
    AFD              Ancillary Function Driver for Winsock                                   afd.sys               6.1.7601.23761                        
    agp440           Intel AGP Bus Filter                                                    agp440.sys            6.1.7600.16385                        
    AIDA64Driver     FinalWire AIDA64 Kernel Driver                                          kerneld.x64                                                 
    aliide           aliide                                                                  aliide.sys            1.2.0.0                               
    ALSysIO          ALSysIO                                                                 ALSysIO64.sys                                               
    amdide           amdide                                                                  amdide.sys            6.1.7600.16385                        
    AmdK8            AMD K8 Processor Driver                                                 amdk8.sys             6.1.7600.16385                        
    amdkmdag         amdkmdag                                                                atikmdag.sys          24.20.11001.5003                       
    amdkmdap         amdkmdap                                                                atikmpag.sys          24.20.11001.5003                       
    AmdPPM           AMD Processor Driver                                                    amdppm.sys            6.1.7600.16385                        
    amdsata          amdsata                                                                 amdsata.sys           1.1.2.5                               
    amdsbs           amdsbs                                                                  amdsbs.sys            3.6.1540.127                          
    amdxata          amdxata                                                                 amdxata.sys           1.1.2.5                               
    AppID             AppID                                                           appid.sys             6.1.7601.24024                        
    arc              arc                                                                     arc.sys               5.2.0.10384                           
    arcsas           arcsas                                                                  arcsas.sys            5.2.0.16119                           
    AsyncMac            RAS                                       asyncmac.sys          6.1.7600.16385                        
    atapi             IDE                                                               atapi.sys             6.1.7600.16385                        
    AtiHDAudioService  AMD Function Driver for HD Audio Service                                AtihdW76.sys          7.12.0.7727                           
    b06bdrv          Broadcom NetXtreme II VBD                                               bxvbda.sys            4.8.2.0                               
    b57nd60a         Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0                          b57nd60a.sys          10.100.4.0                            
    Beep             Beep                                                                                                                                
    blbdrive         blbdrive                                                                blbdrive.sys          6.1.7600.16385                        
    bowser                                                           bowser.sys            6.1.7601.23567             
    BrFiltLo         Brother USB Mass-Storage Lower Filter Driver                            BrFiltLo.sys          1.10.0.2                              
    BrFiltUp         Brother USB Mass-Storage Upper Filter Driver                            BrFiltUp.sys          1.4.0.1                               
    Brserid          Brother MFC Serial Port Interface Driver (WDM)                          Brserid.sys           1.0.1.6                               
    BrSerWdm         Brother WDM Serial driver                                               BrSerWdm.sys          1.0.0.20                              
    BrUsbMdm         Brother MFC USB Fax Only Modem                                          BrUsbMdm.sys          1.0.0.12                              
    BrUsbSer         Brother MFC USB Serial WDM Driver                                       BrUsbSer.sys          1.0.1.3                               
    BTHMODEM         Bluetooth Serial Communications Driver                                  bthmodem.sys          6.1.7600.16385                        
    cdfs             CD/DVD File System Reader                                               cdfs.sys              6.1.7600.16385             
    cdrom             CD-ROM                                                 cdrom.sys             6.1.7601.17514                        
    circlass         Consumer IR Devices                                                     circlass.sys          6.1.7600.16385                        
    CLFS               (CLFS)                                                     CLFS.sys              6.1.7601.24024                        
    cm_km            AO Kaspersky Lab Cryptographic Module x64 (56 bit)                      cm_km.sys             4.1.28.0                              
    CmBatt           Microsoft ACPI Control Method Battery Driver                            CmBatt.sys            6.1.7600.16385                        
    cmdide           cmdide                                                                  cmdide.sys            2.0.7.0                               
    cmudaxp          ASUS Xonar Essence STX Audio Interface                                  cmudaxp.sys           5.12.1.8                              
    CNG              CNG                                                                     cng.sys               6.1.7601.23600                        
    Compbatt         Compbatt                                                                compbatt.sys          6.1.7600.16385                        
    CompositeBus                                          CompositeBus.sys      6.1.7601.17514                        
    crcdisk          Crcdisk Filter Driver                                                   crcdisk.sys           6.1.7600.16385                        
    CSC                                                               csc.sys               6.1.7601.17514                        
    DfsC             DFS Namespace Client Driver                                             dfsc.sys              6.1.7601.24000             
    discache         System Attribute Cache                                                  discache.sys          6.1.7600.16385                        
    Disk                                                                         disk.sys              6.1.7601.19133                        
    dmvsc            dmvsc                                                                   dmvsc.sys             6.1.7601.17514                        
    drmkaud                                                 drmkaud.sys           6.1.7601.19091                        
    DXGKrnl          LDDM Graphics Subsystem                                                 dxgkrnl.sys           6.1.7601.23809                        
    ebdrv            Broadcom NetXtreme II 10 GigE VBD                                       evbda.sys             4.8.13.0                              
    elxstor          elxstor                                                                 elxstor.sys           7.2.10.211                            
    ErrDev           Microsoft Hardware Error Device Driver                                  errdev.sys            6.1.7600.16385                        
    exfat            exFAT File System Driver                                                                                                 
    fastfat          FAT12/16/32 File System Driver                                                                                           
    fdc                                                        fdc.sys               6.1.7600.16385                        
    FileInfo         File Information FS MiniFilter                                          fileinfo.sys          6.1.7600.16385             
    Filetrace        Filetrace                                                               filetrace.sys         6.1.7600.16385             
    flpydisk                                                     flpydisk.sys          6.1.7600.16385                        
    FltMgr                                                                  fltmgr.sys            6.1.7601.24000             
    fltsrv           Acronis Storage Filter Management                                       fltsrv.sys            1.3.0.2125                            
    FsDepends        File System Dependency Minifilter                                       FsDepends.sys         6.1.7600.16385             
    fvevol               Bitlocker                              fvevol.sys            6.1.7601.18062                        
    gagp30kx         Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms             gagp30kx.sys          6.1.7600.16385                        
    gdrv             gdrv                                                                    gdrv.sys              5.2.3790.1830                         
    hcw85cir         Hauppauge Consumer Infrared Receiver                                    hcw85cir.sys          1.31.27127.0                          
    HdAudAddService    UAA   High Definition Audio (Microsoft),  1.1  HdAudio.sys           6.1.7601.17514                        
    HDAudBus            UAA  High Definition Audio (Microsoft)              HDAudBus.sys          6.1.7601.17514                        
    HidBatt          HID UPS Battery Driver                                                  HidBatt.sys           6.1.7600.16385                        
    HidBth           Microsoft Bluetooth HID Miniport                                        hidbth.sys            6.1.7600.16385                        
    HidIr            Microsoft Infrared HID Driver                                           hidir.sys             6.1.7600.16385                        
    HidUsb             HID Microsoft                                            hidusb.sys            6.1.7601.24024                        
    HpSAMD           HpSAMD                                                                  HpSAMD.sys            6.12.6.64                             
    HTTP             HTTP                                                                    HTTP.sys              6.1.7601.24000                        
    hwpolicy         Hardware Policy Driver                                                  hwpolicy.sys          6.1.7601.17514                        
    i8042prt         i8042 Keyboard and PS/2 Mouse Port Driver                               i8042prt.sys          6.1.7600.16385                        
    iaStorV          RAID- Intel  Windows 7                                     iaStorV.sys           8.6.2.1014                            
    iirsp            iirsp                                                                   iirsp.sys             5.4.22.0                              
    IntcAzAudAddService  Service for Realtek HD Audio (WDM)                                      RTKVHD64.sys          6.0.1.6662                            
    intelide         intelide                                                                intelide.sys          6.1.7600.16385                        
    intelppm          Intel                                                 intelppm.sys          6.1.7600.16385                        
    IpFilterDriver     IP-                                              ipfltdrv.sys          6.1.7601.17514                        
    IPMIDRV          IPMIDRV                                                                 IPMIDrv.sys           6.1.7601.17514                        
    IPNAT            IP Network Address Translator                                           ipnat.sys             6.1.7600.16385                        
    IRENUM           IR Bus Enumerator                                                       irenum.sys            6.1.7600.16385                        
    isapnp           isapnp                                                                  isapnp.sys            6.1.7600.16385                        
    iScsiPrt          iScsiPort                                                       msiscsi.sys           6.1.7601.18386                        
    kbdclass                                                          kbdclass.sys          6.1.7600.16385                        
    kbdhid             HID                                                  kbdhid.sys            6.1.7601.17514                        
    kl1              kl1                                                                     kl1.sys               6.8.0.67                              
    klbackupdisk     Kaspersky Lab klbackupdisk                                              klbackupdisk.sys      14.0.0.9                              
    klbackupflt      Kaspersky Lab klbackupflt                                               klbackupflt.sys       14.0.0.24                  
    kldisk           kldisk                                                                  kldisk.sys            12.0.0.1                              
    klflt            Kaspersky Lab Kernel DLL                                                klflt.sys             13.0.60.0                             
    klhk             Kaspersky Lab service driver                                            klhk.sys              16.0.65.60                            
    KLIF             Kaspersky Lab Driver                                                    klif.sys              13.0.363.0                 
    KLIM6            Kaspersky Anti-Virus NDIS 6 Filter                                      klim6.sys             14.0.0.18                             
    klkbdflt         Kaspersky Lab KLKBDFLT                                                  klkbdflt.sys          13.0.0.8                              
    klmouflt         Kaspersky Lab KLMOUFLT                                                  klmouflt.sys          13.0.0.5                              
    klpd             Kaspersky Lab format recognizer driver                                  klpd.sys              13.0.0.9                   
    kltdi            kltdi                                                                   kltdi.sys             13.0.0.12                             
    Klwtp            KLwtp - WFP callout traffic inspector                                   klwtp.sys             13.0.0.43                             
    kneps            kneps                                                                   kneps.sys             13.0.0.40                             
    KSecDD           KSecDD                                                                  ksecdd.sys            6.1.7601.24024                        
    KSecPkg          KSecPkg                                                                 ksecpkg.sys           6.1.7601.24024                        
    ksthunk          Kernel Streaming Thunks                                                 ksthunk.sys           6.1.7600.16385                        
    lltdio           Link-Layer Topology Discovery Mapper I/O Driver                         lltdio.sys            6.1.7600.16385                        
    LSI_FC           LSI_FC                                                                  lsi_fc.sys            1.28.3.52                             
    LSI_SAS          LSI_SAS                                                                 lsi_sas.sys           1.28.3.52                             
    LSI_SAS2         LSI_SAS2                                                                lsi_sas2.sys          2.0.2.71                              
    LSI_SCSI         LSI_SCSI                                                                lsi_scsi.sys          1.28.3.67                             
    luafv                                            luafv.sys             6.1.7601.23930             
    megasas          megasas                                                                 megasas.sys           4.5.1.64                              
    MegaSR           MegaSR                                                                  MegaSR.sys            13.5.409.2009                         
    Modem            Modem                                                                   modem.sys             6.1.7600.16385                        
    monitor          Microsoft Monitor Class Function Driver Service                         monitor.sys           6.1.7600.16385                        
    mouclass                                                                mouclass.sys          6.1.7600.16385                        
    mouhid             HID                                                        mouhid.sys            6.1.7600.16385                        
    mountmgr                                                        mountmgr.sys          6.1.7601.23803                        
    mpio             mpio                                                                    mpio.sys              6.1.7601.17514                        
    mpsdrv              Windows                                 mpsdrv.sys            6.1.7601.24000                        
    MRxDAV              WebDav                                 mrxdav.sys            6.1.7601.23542             
    mrxsmb              - SMB                              mrxsmb.sys            6.1.7601.24024             
    mrxsmb10         - SMB 1.x                                            mrxsmb10.sys          6.1.7601.24024             
    mrxsmb20         - SMB 2.0                                            mrxsmb20.sys          6.1.7601.24024             
    msahci           msahci                                                                  msahci.sys            6.1.7601.17514                        
    msdsm            msdsm                                                                   msdsm.sys             6.1.7601.17514                        
    Msfs             Msfs                                                                                                                     
    mshidkmdf        Pass-through HID to KMDF Filter Driver                                  mshidkmdf.sys         6.1.7600.16385                        
    msisadrv         msisadrv                                                                msisadrv.sys          6.1.7600.16385                        
    MSKSSRV             Microsoft                                   MSKSSRV.sys           6.1.7600.16385                        
    MSPCLOCK            Microsoft                               MSPCLOCK.sys          6.1.7600.16385                        
    MSPQM                Microsoft                     MSPQM.sys             6.1.7600.16385                        
    MsRPC            MsRPC                                                                                                                               
    mssmbios         Microsoft System Management BIOS                                 mssmbios.sys          6.1.7600.16385                        
    MSTEE              Tee/Sink-to-Sink Microsoft                      MSTEE.sys             6.1.7600.16385                        
    MTConfig         Microsoft Input Configuration Driver                                    MTConfig.sys          6.1.7600.16385                        
    Mup              Mup                                                                     mup.sys               6.1.7600.16385             
    NativeWifiP      NativeWiFi Filter                                                       nwifi.sys             6.1.7601.23915                        
    NDIS               NDIS                                                  ndis.sys              6.1.7601.24000                        
    NdisCap          NDIS Capture LightWeight Filter                                         ndiscap.sys           6.1.7600.16385                        
    NdisTapi         NDIS- TAPI                                      ndistapi.sys          6.1.7601.24000                        
    Ndisuio          NDIS Usermode I/O Protocol                                              ndisuio.sys           6.1.7601.17514                        
    NdisWan          NDIS- WAN                                       ndiswan.sys           6.1.7601.17514                        
    NDProxy          NDIS Proxy                                                                                                                          
    NetBIOS          NetBIOS Interface                                                       netbios.sys           6.1.7601.24000             
    NetBT            NetBT                                                                   netbt.sys             6.1.7601.23889                        
    nfrd960          nfrd960                                                                 nfrd960.sys           7.10.0.0                              
    Npfs             Npfs                                                                                                                     
    nsiproxy         NSI proxy service driver.                                               nsiproxy.sys          6.1.7601.23889                        
    Ntfs             Ntfs                                                                                                                     
    Null             Null                                                                                                                                
    nv_agp           NVIDIA nForce AGP Bus Filter                                            nv_agp.sys            6.1.7600.16385                        
    nvraid           nvraid                                                                  nvraid.sys            10.6.0.18                             
    nvstor           nvstor                                                                  nvstor.sys            10.6.0.18                             
    ohci1394         1394 OHCI Compliant Host Controller (Legacy)                            ohci1394.sys          6.1.7600.16385                        
    Parport                                                         parport.sys           6.1.7600.16385                        
    partmgr                                                                 partmgr.sys           6.1.7601.17796                        
    pci               PCI                                                         pci.sys               6.1.7601.17514                        
    pciide           pciide                                                                  pciide.sys            6.1.7600.16385                        
    pcmcia           pcmcia                                                                  pcmcia.sys            6.1.7600.16385                        
    pcw              Performance Counters for Windows Driver                                 pcw.sys               6.1.7600.16385                        
    PEAUTH           PEAUTH                                                                  peauth.sys            6.1.7601.23471                        
    PptpMiniport     - WAN (PPTP)                                                    raspptp.sys           6.1.7601.17514                        
    Processor        Processor Driver                                                        processr.sys          6.1.7600.16385                        
    Psched             QoS                                                 pacer.sys             6.1.7601.24000                        
    ql2300           ql2300                                                                  ql2300.sys            9.1.8.6                               
    ql40xx           ql40xx                                                                  ql40xx.sys            2.1.3.20                              
    QWAVEdrv          QWAVE                                                           qwavedrv.sys          6.1.7600.16385                        
    RasAcd           Remote Access Auto Connection Driver                                    rasacd.sys            6.1.7600.16385                        
    RasAgileVpn      WAN Miniport (IKEv2)                                                    AgileVpn.sys          6.1.7600.16385                        
    Rasl2tp          - WAN (L2TP)                                                    rasl2tp.sys           6.1.7601.17514                        
    RasPppoe          PPPOE                                          raspppoe.sys          6.1.7600.16385                        
    RasSstp          - WAN (SSTP)                                                    rassstp.sys           6.1.7600.16385                        
    rdbss                                               rdbss.sys             6.1.7601.23930             
    rdpbus           Remote Desktop Device Redirector Bus Driver                             rdpbus.sys            6.1.7600.16385                        
    RDPCDD           RDPCDD                                                                  RDPCDD.sys            6.1.7600.16385                        
    RDPDR            Terminal Server Device Redirector Driver                                rdpdr.sys             6.1.7601.17514                        
    RDPENCDD         RDP Encoder Mirror Driver                                               rdpencdd.sys          6.1.7600.16385                        
    RDPREFMP         Reflector Display Driver used to gain access to graphics data           rdprefmp.sys          6.1.7600.16385                        
    RdpVideoMiniport  Remote Desktop Video Miniport Driver                                    rdpvideominiport.sys  6.2.9200.16398                        
    RDPWD            RDP Winstation Driver                                                                                                               
    rdyboost         ReadyBoost                                                              rdyboost.sys          6.1.7601.24000                        
    rspndr           Link-Layer Topology Discovery Responder                                 rspndr.sys            6.1.7600.16385                        
    RTHDMIAzAudService  Service for HDMI                                                        RtHDMIVX.sys          6.0.1.6650                            
    RTL8167          Realtek 8167 NT Driver                                                  Rt64win7.sys          7.88.617.2014                         
    s3cap            s3cap                                                                   vms3cap.sys           6.1.7601.17514                        
    sbp2port         sbp2port                                                                sbp2port.sys          6.1.7601.17514                        
    scfilter           -  PnP                                  scfilter.sys          6.1.7601.17514                        
    secdrv           Security Driver                                                                                                                     
    Serenum            Serenum                                                 serenum.sys           6.1.7600.16385                        
    Serial                                                      serial.sys            6.1.7600.16385                        
    sermouse         Serial Mouse Driver                                                     sermouse.sys          6.1.7600.16385                        
    sffdisk          SFF Storage Class Driver                                                sffdisk.sys           6.1.7600.16385                        
    sffp_mmc         SFF Storage Protocol Driver for MMC                                     sffp_mmc.sys          6.1.7600.16385                        
    sffp_sd          SFF Storage Protocol Driver for SDBus                                   sffp_sd.sys           6.1.7601.17514                        
    sfloppy          High-Capacity Floppy Disk Drive                                         sfloppy.sys           6.1.7600.16385                        
    SiSRaid2         SiSRaid2                                                                SiSRaid2.sys          5.1.1039.2600                         
    SiSRaid4         SiSRaid4                                                                sisraid4.sys          5.1.1039.3600                         
    Smb                TCP/IP  TCP/IPv6 ( SMB)                        smb.sys               6.1.7600.16385                        
    snapman          Acronis Snapshots Manager                                               snapman.sys           4.5.0.2133                            
    speedfan         speedfan                                                                speedfan.sys          1.0.0.0                               
    spldr            Security Processor Loader Driver                                                                                                    
    srv                Server SMB 1.xxx                                        srv.sys               6.1.7601.24000             
    srv2               Server SMB 2.xxx                                        srv2.sys              6.1.7601.24000             
    srvnet           srvnet                                                                  srvnet.sys            6.1.7601.24000             
    stexstor         stexstor                                                                stexstor.sys          5.0.1.1                               
    storflt                                   vmstorfl.sys          6.1.7601.17514                        
    storvsc          storvsc                                                                 storvsc.sys           6.1.7601.17514                        
    swenum                                                             swenum.sys            6.1.7600.16385                        
    Synth3dVsc       Synth3dVsc                                                              synth3dvsc.sys        6.1.7601.17514                        
    Tcpip              TCP/IP                                                tcpip.sys             6.1.7601.24024                        
    TCPIP6           Microsoft IPv6 Protocol Driver                                          tcpip.sys             6.1.7601.24024                        
    tcpipreg         TCP/IP Registry Compatibility                                           tcpipreg.sys          6.1.7601.23496                        
    TDPIPE           TDPIPE                                                                  tdpipe.sys            6.1.7600.16385                        
    tdrpman          Acronis Try&Decide and Restore Points filter                            tdrpman.sys           1.1.0.1107                            
    TDTCP            TDTCP                                                                   tdtcp.sys             6.1.7601.17779                        
    tdx                NetIO Legacy TDI                                      tdx.sys               6.1.7601.23880                        
    TermDD                                                         termdd.sys            6.1.7601.17514                        
    terminpt         Microsoft Remote Desktop Input Driver                                   terminpt.sys          6.2.9200.16398                        
    tib_mounter      Acronis TIB Mounter                                                     tib_mounter.sys       4.3.0.2118                            
    tib              Acronis TIB Manager                                                     tib.sys               1.0.0.1029                            
    tssecsrv         Remote Desktop Services Security Filter Driver                          tssecsrv.sys          6.1.7601.23892                        
    TsUsbFlt         TsUsbFlt                                                                tsusbflt.sys          6.3.9600.16415                        
    TsUsbGD          Remote Desktop Generic USB Device                                       TsUsbGD.sys           6.2.9200.16398                        
    tsusbhub         tsusbhub                                                                tsusbhub.sys          6.1.7601.17514                        
    tunnel                Microsoft                        tunnel.sys            6.1.7601.17514                        
    uagp35           Microsoft AGPv3.5 Filter                                                uagp35.sys            6.1.7600.16385                        
    udfs             udfs                                                                    udfs.sys              6.1.7601.17514             
    uliagpkx         Uli AGP Bus Filter                                                      uliagpkx.sys          6.1.7600.16385                        
    umbus            UMBus                                               umbus.sys             6.1.7601.17514                        
    UmPass           Microsoft UMPass Driver                                                 umpass.sys            6.1.7600.16385                        
    usbaudio           USB (WDM)                                                 usbaudio.sys          6.1.7601.18208                        
    usbccgp              USB (Microsoft)         usbccgp.sys           6.1.7601.23933                        
    usbcir           eHome   (USBCIR)                                     usbcir.sys            6.1.7601.18208                        
    usbehci            Microsoft USB 2.0  -       usbehci.sys           6.1.7601.23933                        
    usbhub             USB- ()                      usbhub.sys            6.1.7601.23933                        
    usbohci          Microsoft USB Open Host Controller Miniport Driver                      usbohci.sys           6.1.7600.16385                        
    usbprint         Microsoft USB PRINTER Class                                             usbprint.sys          6.1.7600.16385                        
    USBSTOR              USB                                  USBSTOR.SYS           6.1.7601.19144                        
    usbuhci            Microsoft USB  -         usbuhci.sys           6.1.7601.23933                        
    usbvideo         USB- (WDM)                                               usbvideo.sys          6.1.7601.18208                        
    vdrvroot             ()                   vdrvroot.sys          6.1.7600.16385                        
    vga              vga                                                                     vgapnp.sys            6.1.7600.16385                        
    VGAOCTool        VGAOCTool                                                               VGAOCTool.sys                                               
    VgaSave          VgaSave                                                                 vga.sys               6.1.7600.16385                        
    VGPU             VGPU                                                                    rdvgkmd.sys                                                 
    vhdmp            vhdmp                                                                   vhdmp.sys             6.1.7601.17514                        
    viaide           viaide                                                                  viaide.sys            6.0.6000.170                          
    vididr           Acronis Virtual Disk                                                    vididr.sys            1.1.0.2105                            
    vidsflt          Acronis Disk Storage Filter                                             vidsflt.sys           1.1.0.2105                            
    vmbus            vmbus                                                                   vmbus.sys             6.1.7601.17514                        
    VMBusHID         VMBusHID                                                                VMBusHID.sys          6.1.7601.17514                        
    volmgr                                                             volmgr.sys            6.1.7601.17514                        
    volmgrx                                                        volmgrx.sys           6.1.7601.23864                        
    volsnap                                                         volsnap.sys           6.1.7601.17514                        
    vsmraid          vsmraid                                                                 vsmraid.sys           6.0.6000.6210                         
    vwifibus           Virtual WiFi                                               vwifibus.sys          6.1.7600.16385                        
    WacomPen         Wacom Serial Pen HID Driver                                             wacompen.sys          6.1.7600.16385                        
    WANARP              IP ARP                                       wanarp.sys            6.1.7601.24000                        
    Wanarpv6            IPv6 ARP                                     wanarp.sys            6.1.7601.24000                        
    Wd               Wd                                                                      wd.sys                6.1.7600.16385                        
    Wdf01000                                                 Wdf01000.sys          1.11.9200.16648                       
    WfpLwf           WFP Lightweight Filter                                                  wfplwf.sys            6.1.7600.16385                        
    WIMMount         WIMMount                                                                wimmount.sys          6.1.7600.16385             
    WmiAcpi          Microsoft Windows Management Interface for ACPI                         wmiacpi.sys           6.1.7600.16385                        
    ws2ifsl           WinSock IFS                                                     ws2ifsl.sys           6.1.7600.16385                        
    WudfPf           User Mode Driver Frameworks Platform Driver                             WudfPf.sys            6.2.9200.16384                        
    WUDFRd           WUDFRd                                                                  WUDFRd.sys            6.2.9200.16384                        


--------[  ]------------------------------------------------------------------------------------------------------

    AcrSch2Svc                         Acronis Scheduler2 Service                                              schedul2.exe          8.0.0.8204                     LocalSystem
    AeLookupSvc                                                              svchost.exe           6.1.7600.16385                       localSystem
    afcdpsrv                           Acronis Nonstop Backup Service                                          afcdpsrv.exe          2.0.0.4041                     LocalSystem
    ALG                                                                             alg.exe               6.1.7600.16385                 NT AUTHORITY\LocalService
    AMD External Events Utility        AMD External Events Utility                                             atiesrxx.exe          24.20.11001.5003                LocalSystem
    AppIDSvc                                                                            svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Appinfo                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    AppMgmt                                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    aspnet_state                         ASP.NET                                                aspnet_state.exe      4.7.2558.0                     NT AUTHORITY\NetworkService
    AudioEndpointBuilder                   Windows Audio                        svchost.exe           6.1.7600.16385                       LocalSystem
    AudioSrv                           Windows Audio                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    AVP18.0.0                          Kaspersky Anti-Virus Service 18.0.0                                     avp.exe               18.0.0.405                     LocalSystem
    AxInstSV                            ActiveX (AxInstSV)                                           svchost.exe           6.1.7600.16385                       LocalSystem
    BDESVC                                BitLocker                                      svchost.exe           6.1.7600.16385                       localSystem
    BFE                                                                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    BITS                                   (BITS)                         svchost.exe           6.1.7600.16385                       LocalSystem
    Browser                                                                                  svchost.exe           6.1.7600.16385                       LocalSystem
    bthserv                              Bluetooth                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    CertPropSvc                                                                      svchost.exe           6.1.7600.16385                       LocalSystem
    clr_optimization_v2.0.50727_32     Microsoft .NET Framework NGEN v2.0.50727_X86                            mscorsvw.exe          2.0.50727.5483                 LocalSystem
    clr_optimization_v2.0.50727_64     Microsoft .NET Framework NGEN v2.0.50727_X64                            mscorsvw.exe          2.0.50727.5483                 LocalSystem
    clr_optimization_v4.0.30319_32     Microsoft .NET Framework NGEN v4.0.30319_X86                            mscorsvw.exe          4.7.2558.0                     LocalSystem
    clr_optimization_v4.0.30319_64     Microsoft .NET Framework NGEN v4.0.30319_X64                            mscorsvw.exe          4.7.2558.0                     LocalSystem
    COMSysApp                            COM+                                               dllhost.exe           6.1.7600.16385                 LocalSystem
    CryptSvc                                                                                 svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    CscService                                                                                  svchost.exe           6.1.7600.16385                       LocalSystem
    DcomLaunch                            DCOM-                                   svchost.exe           6.1.7600.16385                       LocalSystem
    defragsvc                                                                               svchost.exe           6.1.7600.16385                 localSystem
    Dhcp                               DHCP-                                                             svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    DiagTrack                          Diagnostics Tracking Service                                            svchost.exe           6.1.7600.16385                 LocalSystem
    Dnscache                           DNS-                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    dot3svc                                                                              svchost.exe           6.1.7600.16385                       localSystem
    DPS                                                                               svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    EapHost                                (EAP)                         svchost.exe           6.1.7600.16385                       localSystem
    EFS                                   (EFS)                                      lsass.exe             6.1.7601.24024                       LocalSystem
    ehRecvr                              Windows Media Center                                    ehRecvr.exe           6.1.7601.17514                 NT AUTHORITY\networkService
    ehSched                              Windows Media Center                                ehsched.exe           6.1.7600.16385                 NT AUTHORITY\networkService
    eventlog                             Windows                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    EventSystem                          COM+                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Fax                                                                                                    fxssvc.exe            6.1.7601.17514                 NT AUTHORITY\NetworkService
    fdPHost                                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FDResPub                                                               svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FontCache                             Windows                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FontCache3.0.0.0                     Windows Presentation Foundation 3.0.0.0                     PresentationFontCache.exe  3.0.6920.5011                  NT Authority\LocalService
    gpsvc                                                                               svchost.exe           6.1.7600.16385                 LocalSystem
    hidserv                              HID-                                                svchost.exe           6.1.7600.16385                       LocalSystem
    hkmsvc                                                      svchost.exe           6.1.7600.16385                       localSystem
    HomeGroupListener                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    HomeGroupProvider                                                                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    idsvc                              Windows CardSpace                                                       infocard.exe          3.0.4506.5464                        LocalSystem
    IEEtwCollectorService              Internet Explorer ETW Collector Service                                 IEEtwCollector.exe    11.0.9600.18921                LocalSystem
    IKEEXT                               IPsec        IP     svchost.exe           6.1.7600.16385                       LocalSystem
    IPBusEnum                           IP- PnP-X                                              svchost.exe           6.1.7600.16385                       LocalSystem
    iphlpsvc                             IP                                               svchost.exe           6.1.7600.16385                       LocalSystem
    KeyIso                               CNG                                                     lsass.exe             6.1.7601.24024                       LocalSystem
    klvssbridge64_18.0.0               klvssbridge64_18.0.0                                                    vssbridge64.exe       18.0.0.495                     LocalSystem
    KtmRm                              KtmRm                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    LanmanServer                                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    LanmanWorkstation                                                                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    lltdsvc                                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    lmhosts                              NetBIOS  TCP/IP                                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Mcx2Svc                              Media Center                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    MMCSS                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    MpsSvc                              Windows                                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    MSDTC                                                                   msdtc.exe             2001.12.8530.16385                NT AUTHORITY\NetworkService
    MSiSCSI                               iSCSI                                      svchost.exe           6.1.7600.16385                       LocalSystem
    msiserver                           Windows                                                      msiexec.exe           5.0.7601.23593                 LocalSystem
    napagent                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    Netlogon                                                                                lsass.exe             6.1.7601.24024                       LocalSystem
    Netman                                                                                   svchost.exe           6.1.7600.16385                       LocalSystem
    NetMsmqActivator                     Net.Msmq                                         SMSvcHost.exe         4.7.2558.0                           NT AUTHORITY\NetworkService
    NetPipeActivator                     Net.Pipe                                         SMSvcHost.exe         4.7.2558.0                           NT AUTHORITY\LocalService
    netprofm                                                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    NetTcpActivator                      Net.Tcp                                          SMSvcHost.exe         4.7.2558.0                           NT AUTHORITY\LocalService
    NetTcpPortSharing                       Net.Tcp                                  SMSvcHost.exe         4.7.2558.0                           NT AUTHORITY\LocalService
    NlaSvc                                                                     svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    nsi                                                                          svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    p2pimsvc                                                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    p2psvc                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PcaSvc                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    PeerDistSvc                        BranchCache                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    PerfHost                                                           perfhost.exe          6.1.7600.16385                 NT AUTHORITY\LocalService
    pla                                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PlugPlay                           Plug-and-Play                                                           svchost.exe           6.1.7600.16385                       LocalSystem
    PNRPAutoReg                            PNRP                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PNRPsvc                             PNRP                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PolicyAgent                          IPsec                                                    svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    Power                                                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    ProfSvc                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    ProtectedStorage                                                                        lsass.exe             6.1.7601.24024                       LocalSystem
    QWAVE                              Quality Windows Audio Video Experience                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    RasAuto                                                 svchost.exe           6.1.7600.16385                       localSystem
    RasMan                                                                svchost.exe           6.1.7600.16385                       localSystem
    RemoteAccess                                                                  svchost.exe           6.1.7600.16385                       localSystem
    RemoteRegistry                                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    RpcEptMapper                          RPC                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    RpcLocator                             (RPC)                                locator.exe           6.1.7600.16385                 NT AUTHORITY\NetworkService
    RpcSs                                 (RPC)                                          svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    SamSs                                                                   lsass.exe             6.1.7601.24024                       LocalSystem
    SCardSvr                           -                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Schedule                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    SCPolicySvc                          -                                            svchost.exe           6.1.7600.16385                       LocalSystem
    SDRSVC                              Windows                                                       svchost.exe           6.1.7600.16385                 localSystem
    seclogon                                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    SENS                                                                    svchost.exe           6.1.7600.16385                       LocalSystem
    SensrSvc                                                                       svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SessionEnv                                                           svchost.exe           6.1.7600.16385                       localSystem
    SharedAccess                             (ICS)                            svchost.exe           6.1.7600.16385                       LocalSystem
    ShellHWDetection                                                            svchost.exe           6.1.7600.16385                       LocalSystem
    SNMPTRAP                            SNMP                                                            snmptrap.exe          6.1.7600.16385                 NT AUTHORITY\LocalService
    Spooler                                                                                     spoolsv.exe           6.1.7601.24000                 LocalSystem
    sppsvc                                                                        sppsvc.exe            6.1.7601.17514                 NT AUTHORITY\NetworkService
    sppuinotify                          SPP                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SSDPSRV                             SSDP                                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SstpSvc                             SSTP                                                             svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    stisvc                                Windows (WIA)                               svchost.exe           6.1.7600.16385                 NT Authority\LocalService
    swprv                                  (Microsoft)                  svchost.exe           6.1.7600.16385                 LocalSystem
    syncagentsrv                       Acronis Sync Agent Service                                              syncagentsrv.exe      16.0.0.6683                    LocalSystem
    SysMain                            Superfetch                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    TabletInputService                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    TapiSrv                                                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    TermService                                                                    svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    Themes                                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    THREADORDER                                                                       svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    TrinityService                     TrinityService                                                          TrinityService.exe    1.0.1.42                       LocalSystem
    TrkWks                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    TrustedInstaller                     Windows                                              TrustedInstaller.exe  6.1.7601.17514                 localSystem
    UI0Detect                                                                     UI0Detect.exe         6.1.7600.16385                 LocalSystem
    UmRdpService                                svchost.exe           6.1.7600.16385                       localSystem
    upnphost                             PNP-                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    UxSms                                                           svchost.exe           6.1.7600.16385                       localSystem
    VaultSvc                                                                             lsass.exe             6.1.7601.24024                       LocalSystem
    vds                                                                                         vds.exe               6.1.7601.17514                 LocalSystem
    VSS                                                                                  vssvc.exe             6.1.7601.17514                 LocalSystem
    W32Time                              Windows                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WatAdminSvc                           Windows                                     WatAdminSvc.exe       7.1.7600.16395                 LocalSystem
    wbengine                                                                wbengine.exe          6.1.7601.17514                 localSystem
    WbioSrvc                             Windows                                           svchost.exe           6.1.7600.16385                       LocalSystem
    wcncsvc                              Windows -                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WcsPlugInService                     Windows (WCS)                                          svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WdiServiceHost                                                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WdiSystemHost                                                                        svchost.exe           6.1.7600.16385                       LocalSystem
    WebClient                          -                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Wecsvc                               Windows                                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    wercplsupport                          "     "  svchost.exe           6.1.7600.16385                       localSystem
    WerSvc                                Windows                                       svchost.exe           6.1.7600.16385                       localSystem
    WinDefend                           Windows                                                        svchost.exe           6.1.7600.16385                       LocalSystem
    WinHttpAutoProxySvc                   - WinHTTP                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Winmgmt                              Windows                                       svchost.exe           6.1.7600.16385                       localSystem
    WinRM                                 Windows (WS-Management)                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    Wlansvc                              WLAN                                               svchost.exe           6.1.7600.16385                       LocalSystem
    wmiApSrv                           WMI Performance Adapter                                                 WmiApSrv.exe          6.1.7600.16385                 localSystem
    WMPNetworkSvc                           Windows Media               wmpnetwk.exe                                         NT AUTHORITY\NetworkService
    WPCSvc                             Parental Controls                                                       svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    WPDBusEnum                                                           svchost.exe           6.1.7600.16385                       LocalSystem
    wscsvc                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WSearch                            Windows Search                                                          SearchIndexer.exe     7.0.7601.23930                 LocalSystem
    wuauserv                             Windows                                                svchost.exe           6.1.7600.16385                       LocalSystem
    wudfsvc                            Windows Driver Foundation - User-mode Driver Framework                  svchost.exe           6.1.7600.16385                       LocalSystem
    WwanSvc                             WWAN                                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService


--------[  DLL ]---------------------------------------------------------------------------------------------------

    accessibilitycpl.dll       6.1.7601.17514                 
    acctres.dll                6.1.7600.16385                     (Microsoft)
    acledit.dll                6.1.7600.16385                 ACL
    aclui.dll                  6.1.7600.16385                
    acppage.dll                6.1.7601.17514                  ""
    actioncenter.dll           6.1.7601.17514               
    actioncentercpl.dll        6.1.7601.17514                 
    activeds.dll               6.1.7601.17514               DLL   AD
    actxprxy.dll               6.1.7601.24000              ActiveX Interface Marshaling Library
    admtmpl.dll                6.1.7601.17514               " "
    adprovider.dll             6.1.7601.18409               DLL adprovider
    adsldp.dll                 6.1.7601.17514              ADs LDAP Provider DLL
    adsldpc.dll                6.1.7600.16385               DLL  LDAP AD
    adsmsext.dll               6.1.7601.23545              ADs LDAP Provider DLL
    adsnt.dll                  6.1.7600.16385               DLL    Windows NT
    adtschema.dll              6.1.7601.24024                 
    advapi32.dll               6.1.7601.24024                API Windows 32
    advpack.dll                8.0.7600.16385              ADVPACK
    aecache.dll                6.1.7600.16385              AECache Sysprep Plugin
    aeevts.dll                 6.1.7600.16385                  
    alttab.dll                 6.1.7600.16385              Windows Shell Alt Tab
    amdave32.dll               24.20.11001.5003            Radeon AMD AVE Driver Component
    amdgfxinfo32.dll                                       
    amdhcp32.dll               24.20.11001.5003            Universal Adapter for Adobe
    amdihk32.dll               1.0.0.0                     AMD DVR
    amdlvr32.dll               1.0.13.0                    LiquidVR SDK 1.0
    amdmantle32.dll            24.20.11001.5003            Mantle driver, support for SI family and above
    amdmcl32.dll               1.6.0.0                     Radeon MCL Universal Driver
    amdmmcl.dll                24.20.11001.5003            Radeon MMOCL Universal Driver
    amdocl.dll                 24.20.11001.5003            AMD Accelerated Parallel Processing OpenCL 2.0 Runtime
    amdocl12cl.dll             24.20.11001.5003            AMD COMPILER OpenCL 1.1 Compiler
    amdpcom32.dll              24.20.11001.5003            Radeon PCOM Universal Driver
    amduve32.dll               16.5.6.0                    Radeon AMD AVE Driver Component
    amdvlk32.dll               9.2.10.20                   Vulkan driver, support for SI family and above
    amfrt32.dll                1.4.7.0                     Advanced Media Framework
    amstream.dll               6.6.7601.17514              DirectShow Runtime.
    amxread.dll                6.1.7600.16385              API Tracing Manifest Read Library
    apds.dll                   6.1.7600.16385                  Microsoft
    apilogen.dll               6.1.7600.16385                 API
    api-ms-win-core-console-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-datetime-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-debug-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-delayload-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-errorhandling-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-fibers-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-file-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-file-l1-2-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-core-file-l2-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-core-handle-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-heap-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-interlocked-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-io-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-libraryloader-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-localization-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-localization-l1-2-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-core-localregistry-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-memory-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-misc-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-namedpipe-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-processenvironment-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-processthreads-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-processthreads-l1-1-1.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-core-profile-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-rtlsupport-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-string-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-synch-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-synch-l1-2-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-core-sysinfo-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-threadpool-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-timezone-l1-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-core-util-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-xstate-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-core-xstate-l2-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-crt-conio-l1-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-crt-convert-l1-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-crt-environment-l1-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-crt-filesystem-l1-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-crt-heap-l1-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-crt-locale-l1-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-crt-math-l1-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-crt-multibyte-l1-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-crt-private-l1-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-crt-process-l1-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-crt-runtime-l1-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-crt-stdio-l1-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-crt-string-l1-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-crt-time-l1-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-crt-utility-l1-1-0.dll  10.0.10586.1171             ApiSet Stub DLL
    api-ms-win-downlevel-advapi32-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-advapi32-l2-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-normaliz-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-ole32-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-shell32-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-shlwapi-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-shlwapi-l2-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-user32-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-version-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-security-base-l1-1-0.dll  6.1.7601.24024              ApiSet Stub DLL
    api-ms-win-security-lsalookup-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-security-sddl-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-core-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-management-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-management-l2-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-winsvc-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    apircl.dll                 6.1.7600.16385              Microsoft InfoTech IR Local DLL
    apisetschema.dll           6.1.7601.24024              ApiSet Schema DLL
    apphelp.dll                6.1.7601.19050                 
    apphlpdm.dll               6.1.7600.16385                 
    appidapi.dll               6.1.7601.24024               API-  
    appidpolicyengineapi.dll   6.1.7600.16385              AppId Policy Engine API Module
    appmgmts.dll               6.1.7600.16385                
    appmgr.dll                 6.1.7601.17514                 
    apss.dll                   6.1.7600.16385              Microsoft InfoTech Storage System Library
    asferror.dll               12.0.7600.16385               ASF
    aspnet_counters.dll        4.7.2558.0                  Microsoft ASP.NET Performance Counter Shim DLL
    asycfilt.dll               6.1.7601.23713              
    atiadlxx.dll               24.20.11001.5003            ADL
    atiadlxy.dll               24.20.11001.5003            ADL
    aticalcl.dll               23.20.15033.5003            ATI CAL compiler runtime
    aticaldd.dll               23.20.15033.5003            ATI CAL DD
    aticalrt.dll               23.20.15033.5003            ATI CAL runtime
    aticfx32.dll               24.20.11001.5003            aticfx32.dll
    atidxx32.dll               24.20.11001.5003            atidxx32.dll
    atigktxx.dll               24.20.11001.5003            atigktxx.dll
    atiglpxx.dll               24.20.11001.5003            atiglpxx.dll
    atimpc32.dll               24.20.11001.5003            Radeon PCOM Universal Driver
    atioglxx.dll               24.20.11001.5003            AMD OpenGL driver
    atisamu32.dll              24.20.11001.5003            Radeon spu api dll
    atiu9pag.dll               24.20.11001.5003            atiu9pag.dll
    atiumdag.dll               24.20.11001.5003            atiumdag.dll
    atiumdva.dll               24.20.11001.5003            Radeon Video Acceleration Universal Driver
    atiumdvt.dll               8.14.10.609                 Radeon Video Acceleration Universal Driver
    atiuxpag.dll               24.20.11001.5003            atiuxpag.dll
    atl.dll                    3.5.2284.0                  ATL Module for Windows XP (Unicode)
    atmfd.dll                  5.1.2.253                   Windows NT OpenType/Type 1 Font Driver
    atmlib.dll                 5.1.2.253                   Windows NT OpenType/Type 1 API Library.
    audiodev.dll               6.1.7601.17514                   
    audioeng.dll               6.1.7601.23471              Audio Engine
    audiokse.dll               6.1.7601.23471              Audio Ks Endpoint
    audioses.dll               6.1.7601.23471                
    auditnativesnapin.dll      6.1.7600.16385                    
    auditpolicygpinterop.dll   6.1.7600.16385                 
    auditpolmsg.dll            6.1.7600.16385                MMC  
    authfwcfg.dll              6.1.7600.16385               Windows      
    authfwgp.dll               6.1.7600.16385               Windows c      
    authfwsnapin.dll           6.1.7601.17514              Microsoft.WindowsFirewall.SnapIn
    authfwwizfwk.dll           6.1.7600.16385              Wizard Framework
    authui.dll                 6.1.7601.24000                
    authz.dll                  6.1.7600.16385              Authorization Framework
    autoplay.dll               6.1.7601.17514               ( )
    auxiliarydisplayapi.dll    6.1.7600.16385              Microsoft Windows SideShow API
    auxiliarydisplaycpl.dll    6.1.7601.17514                Microsoft Windows SideShow
    avicap32.dll               6.1.7600.16385                 AVI
    avifil32.dll               6.1.7601.17514                 AVI
    avrt.dll                   6.1.7600.16385              Multimedia Realtime Runtime
    azroles.dll                6.1.7601.17514              azroles Module
    azroleui.dll               6.1.7601.17514               
    azsqlext.dll               6.1.7601.17514              AzMan Sql Audit Extended Stored Procedures Dll
    basecsp.dll                6.1.7601.17514                 - (Microsoft)
    batmeter.dll               6.1.7601.17514              Battery Meter Helper DLL
    bcrypt.dll                 6.1.7601.24024              Windows Cryptographic Primitives Library (Wow64)
    bcryptprimitives.dll       6.1.7601.23451              Windows Cryptographic Primitives Library
    bidispl.dll                6.1.7600.16385              Bidispl DLL
    biocredprov.dll            6.1.7600.16385                 WinBio
    bitsperf.dll               7.5.7601.17514              Perfmon Counter Access
    bitsprx2.dll               7.5.7600.16385              Background Intelligent Transfer Service Proxy
    bitsprx3.dll               7.5.7600.16385              Background Intelligent Transfer Service 2.0 Proxy
    bitsprx4.dll               7.5.7600.16385              Background Intelligent Transfer Service 2.5 Proxy
    bitsprx5.dll               7.5.7600.16385              Background Intelligent Transfer Service 3.0 Proxy
    bitsprx6.dll               7.5.7600.16385              Background Intelligent Transfer Service 4.0 Proxy
    blackbox.dll               11.0.7601.23471             BlackBox DLL
    bootvid.dll                6.1.7600.16385              VGA Boot Driver
    browcli.dll                6.1.7601.17887              Browser Service Client DLL
    browseui.dll               6.1.7601.17514              Shell Browser UI Library
    btpanui.dll                6.1.7600.16385                Bluetooth   
    bwcontexthandler.dll       1.0.0.1                      ContextH
    bwunpairelevated.dll       6.1.7600.16385              BWUnpairElevated Proxy Dll
    c_g18030.dll               6.1.7600.16385              GB18030 DBCS-Unicode Conversion DLL
    c_is2022.dll               6.1.7600.16385              ISO-2022 Code Page Translation DLL
    c_iscii.dll                6.1.7601.17514              ISCII Code Page Translation DLL
    cabinet.dll                6.1.7601.17514              Microsoft Cabinet File API
    cabview.dll                6.1.7601.17514                 CAB-
    capiprovider.dll           6.1.7601.18409               DLL capiprovider
    capisp.dll                 6.1.7600.16385              Sysprep cleanup dll for CAPI
    catsrv.dll                 2001.12.8530.16385          COM+ Configuration Catalog Server
    catsrvps.dll               2001.12.8530.16385          COM+ Configuration Catalog Server Proxy/Stub
    catsrvut.dll               2001.12.8531.19062          COM+ Configuration Catalog Server Utilities
    cca.dll                    6.6.7601.17514              CCA DirectShow Filter.
    cdosys.dll                 6.6.7601.24023              Microsoft CDO for Windows Library
    certcli.dll                6.1.7601.24024                 Microsoft Active Directory
    certcredprovider.dll       6.1.7600.16385                 
    certenc.dll                6.1.7601.18151              Active Directory Certificate Services Encoding
    certenroll.dll             6.1.7601.17514                  Active Directory Microsoft
    certenrollui.dll           6.1.7600.16385                  X509
    certmgr.dll                6.1.7601.17514                
    certpoleng.dll             6.1.7601.17514                
    cewmdm.dll                 12.0.7601.18872               Windows CE WMDM
    cfgbkend.dll               6.1.7600.16385              Configuration Backend Interface
    cfgmgr32.dll               6.1.7601.17621              Configuration Manager DLL
    chsbrkr.dll                6.1.7600.16385              Simplified Chinese Word Breaker
    chtbrkr.dll                6.1.7600.16385              Chinese Traditional Word Breaker
    chxreadingstringime.dll    6.1.7600.16385              CHxReadingStringIME
    cic.dll                    6.1.7601.23892                CIC - MMC   
    clb.dll                    6.1.7600.16385                
    clbcatq.dll                2001.12.8530.16385          COM+ Configuration Catalog
    clfsw32.dll                6.1.7601.18777              Common Log Marshalling Win32 DLL
    cliconfg.dll               6.1.7600.16385              SQL Client Configuration Utility DLL
    clusapi.dll                6.1.7601.17514               API 
    cm_oal.dll                 1.0.0.1                     CMedia OpenAL(TM) Implementation
    cmasiop.dll                2.0.0.12                    C-Media Universal ASIO Driver
    cmcfg32.dll                7.2.7600.16385                  Microsoft
    cmdial32.dll               7.2.7600.16385               
    cmicnfgp.dll               2.0.1.28                    CmiCnfg DLL
    cmicryptinstall.dll        6.1.7600.16385              Installers for cryptographic elements of CMI objects
    cmifltr.dll                1.0.0.0                     CmiFltr
    cmifw.dll                  6.1.7600.16385              Windows Firewall rule configuration plug-in
    cmipnpinstall.dll          6.1.7600.16385              PNP plugin installer for CMI
    cmlua.dll                  7.2.7600.16385                API   
    cmpaoxy.dll                1.0.0.2                     CmPaput
    cmpbk32.dll                7.2.7600.16385              Microsoft Connection Manager Phonebook
    cmstplua.dll               7.2.7600.16385                API      
    cmutil.dll                 7.2.7600.16385                  (Microsoft)
    cngaudit.dll               6.1.7600.16385              Windows Cryptographic Next Generation audit library
    cngprovider.dll            6.1.7601.18409               DLL cngprovider
    cnvfat.dll                 6.1.7600.16385              FAT File System Conversion Utility DLL
    colbact.dll                2001.12.8530.16385          COM+
    colorcnv.dll               6.1.7601.19091              Windows Media Color Conversion
    colorui.dll                6.1.7600.16385                 
    comcat.dll                 6.1.7601.24000              Microsoft Component Category Manager Library
    comctl32.dll               5.82.7601.18837                  
    comdlg32.dll               6.1.7601.17514                 
    compobj.dll                2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    compstui.dll               6.1.7600.16385                   
    comrepl.dll                2001.12.8530.16385          COM+
    comres.dll                 2001.12.8530.16385           COM+
    comsnap.dll                2001.12.8530.16385          COM+ Explorer MMC Snapin
    comsvcs.dll                2001.12.8531.19062          COM+ Services
    comuid.dll                 2001.12.8530.16385          COM+ Explorer UI
    concrt140.dll              14.0.24123.0                Microsoft Concurrency Runtime Library
    connect.dll                6.1.7600.16385               
    console.dll                6.1.7600.16385                 
    cpfilters.dll              6.6.7601.19135               PTFilter & Encypter/Decrypter Tagger Filters.
    credssp.dll                6.1.7601.24024              Credential Delegation Security Package
    credui.dll                 6.1.7601.18276                 
    crtdll.dll                 4.0.1183.1                  Microsoft C Runtime Library
    crypt32.dll                6.1.7601.23971              API32 
    cryptbase.dll              6.1.7601.24024              Base cryptographic API DLL
    cryptdlg.dll               6.1.7601.18150                
    cryptdll.dll               6.1.7600.16385              Cryptography Manager
    cryptext.dll               6.1.7600.16385                
    cryptnet.dll               6.1.7601.23971              Crypto Network Related API
    cryptsp.dll                6.1.7601.23471              Cryptographic Service Provider API
    cryptsvc.dll               6.1.7601.23971               
    cryptui.dll                6.1.7601.23471                
    cryptxml.dll               6.1.7600.16385              API- XML DigSig
    cscapi.dll                 6.1.7601.17514              Offline Files Win32 API
    cscdll.dll                 6.1.7601.17514              Offline Files Temporary Shim
    cscobj.dll                 6.1.7601.17514               COM-   CSC API
    csver.dll                  9.1.2.1007                  CSVer
    ctl3d32.dll                2.31.0.0                    Ctl3D 3D Windows Controls
    d2d1.dll                   6.2.9200.16765               Microsoft D2D
    d3d10.dll                  6.2.9200.16492              Direct3D 10 Runtime
    d3d10_1.dll                6.2.9200.16492              Direct3D 10.1 Runtime
    d3d10_1core.dll            6.2.9200.16492              Direct3D 10.1 Runtime
    d3d10core.dll              6.2.9200.16492              Direct3D 10 Runtime
    d3d10level9.dll            6.2.9200.21830              Direct3D 10 to Direct3D9 Translation Runtime
    d3d10warp.dll              6.2.9200.17033              Direct3D 10 Rasterizer
    d3d11.dll                  6.2.9200.16570              Direct3D 11 Runtime
    d3d8.dll                   6.1.7600.16385              Microsoft Direct3D
    d3d8thk.dll                6.1.7600.16385              Microsoft Direct3D OS Thunk Layer
    d3d9.dll                   6.1.7601.17514              Direct3D 9 Runtime
    d3dcompiler_33.dll         9.18.904.15                 Microsoft Direct3D
    d3dcompiler_34.dll         9.19.949.46                 Microsoft Direct3D
    d3dcompiler_35.dll         9.19.949.1104               Microsoft Direct3D
    d3dcompiler_36.dll         9.19.949.2111               Microsoft Direct3D
    d3dcompiler_37.dll         9.22.949.2248               Microsoft Direct3D
    d3dcompiler_38.dll         9.23.949.2378               Microsoft Direct3D
    d3dcompiler_39.dll         9.24.949.2307               Microsoft Direct3D
    d3dcompiler_40.dll         9.24.950.2656               Direct3D HLSL Compiler
    d3dcompiler_41.dll         9.26.952.2844               Direct3D HLSL Compiler
    d3dcompiler_42.dll         9.27.952.3022               Direct3D HLSL Compiler
    d3dcompiler_43.dll         9.29.952.3111               Direct3D HLSL Compiler
    d3dcompiler_47.dll         6.3.9600.18611              Direct3D HLSL Compiler for Redistribution
    d3dcsx_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dcsx_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dim.dll                  6.1.7600.16385              Microsoft Direct3D
    d3dim700.dll               6.1.7600.16385              Microsoft Direct3D
    d3dramp.dll                6.1.7600.16385              Microsoft Direct3D
    d3dx10.dll                 9.16.843.0                  Microsoft Direct3D
    d3dx10_33.dll              9.18.904.21                 Microsoft Direct3D
    d3dx10_34.dll              9.19.949.46                 Microsoft Direct3D
    d3dx10_35.dll              9.19.949.1104               Microsoft Direct3D
    d3dx10_36.dll              9.19.949.2009               Microsoft Direct3D
    d3dx10_37.dll              9.19.949.2187               Microsoft Direct3D
    d3dx10_38.dll              9.23.949.2378               Microsoft Direct3D
    d3dx10_39.dll              9.24.949.2307               Microsoft Direct3D
    d3dx10_40.dll              9.24.950.2656               Direct3D 10.1 Extensions
    d3dx10_41.dll              9.26.952.2844               Direct3D 10.1 Extensions
    d3dx10_42.dll              9.27.952.3001               Direct3D 10.1 Extensions
    d3dx10_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx11_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dx11_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx9_24.dll               9.5.132.0                   Microsoft DirectX for Windows
    d3dx9_25.dll               9.6.168.0                   Microsoft DirectX for Windows
    d3dx9_26.dll               9.7.239.0                   Microsoft DirectX for Windows
    d3dx9_27.dll               9.8.299.0                   Microsoft DirectX for Windows
    d3dx9_28.dll               9.10.455.0                  Microsoft DirectX for Windows
    d3dx9_29.dll               9.11.519.0                  Microsoft DirectX for Windows
    d3dx9_30.dll               9.12.589.0                  Microsoft DirectX for Windows
    d3dx9_31.dll               9.15.779.0                  Microsoft DirectX for Windows
    d3dx9_32.dll               9.16.843.0                  Microsoft DirectX for Windows
    d3dx9_33.dll               9.18.904.15                 Microsoft DirectX for Windows
    d3dx9_34.dll               9.19.949.46                 Microsoft DirectX for Windows
    d3dx9_35.dll               9.19.949.1104               Microsoft DirectX for Windows
    d3dx9_36.dll               9.19.949.2111               Microsoft DirectX for Windows
    d3dx9_37.dll               9.22.949.2248               Microsoft DirectX for Windows
    d3dx9_38.dll               9.23.949.2378               Microsoft DirectX for Windows
    d3dx9_39.dll               9.24.949.2307               Microsoft DirectX for Windows
    d3dx9_40.dll               9.24.950.2656               Direct3D 9 Extensions
    d3dx9_41.dll               9.26.952.2844               Direct3D 9 Extensions
    d3dx9_42.dll               9.27.952.3001               Direct3D 9 Extensions
    d3dx9_43.dll               9.29.952.3111               Direct3D 9 Extensions
    d3dxof.dll                 6.1.7600.16385              DirectX Files DLL
    dataclen.dll               6.1.7600.16385                 Windows
    davclnt.dll                6.1.7601.23542              Web DAV Client DLL
    davhlpr.dll                6.1.7600.16385              DAV Helper DLL
    dbgeng.dll                 6.1.7601.17514              Windows Symbolic Debugger Engine
    dbghelp.dll                6.1.7601.17514              Windows Image Helper
    dbnetlib.dll               6.1.7600.16385              Winsock Oriented Net DLL for SQL Clients
    dbnmpntw.dll               6.1.7600.16385              Named Pipes Net DLL for SQL Clients
    dciman32.dll               6.1.7601.24007              DCI Manager
    ddaclsys.dll               6.1.7600.16385              SysPrep module for Reseting Data Drive ACL 
    ddoiproxy.dll              6.1.7600.16385              DDOI Interface Proxy
    ddores.dll                 6.1.7600.16385                  
    ddraw.dll                  6.1.7600.16385              Microsoft DirectDraw
    ddrawex.dll                6.1.7600.16385              Direct Draw Ex
    defaultlocationcpl.dll     6.1.7601.17514               :   
    deskadp.dll                6.1.7600.16385                 
    deskmon.dll                6.1.7600.16385                
    deskperf.dll               6.1.7600.16385                
    detoured.dll               24.20.11001.5003            Marks process modified by Detours technology.
    devenum.dll                6.6.7601.19091               .
    devicecenter.dll           6.1.7601.17514                
    devicedisplaystatusmanager.dll  6.1.7600.16385              Device Display Status Manager
    devicemetadataparsers.dll  6.1.7600.16385              Common Device Metadata parsers
    devicepairing.dll          6.1.7600.16385               ,   
    devicepairingfolder.dll    6.1.7601.17514                 
    devicepairinghandler.dll   6.1.7600.16385              Device Pairing Handler Dll
    devicepairingproxy.dll     6.1.7600.16385              Device Pairing Proxy Dll
    deviceuxres.dll            6.1.7600.16385              Windows Device User Experience Resource File
    devmgr.dll                 6.1.7600.16385                 
    devobj.dll                 6.1.7601.17621              Device Information Set DLL
    devrtl.dll                 6.1.7601.17621              Device Management Run Time Library
    dfscli.dll                 6.1.7600.16385              Windows NT Distributed File System Client DLL
    dfshim.dll                 4.0.41210.0                     ClickOnce
    dfsshlex.dll               6.1.7600.16385                   DFS
    dhcpcmonitor.dll           6.1.7600.16385               (DLL)   DHCP
    dhcpcore.dll               6.1.7601.17514               DHCP-
    dhcpcore6.dll              6.1.7601.17970               DHCPv6
    dhcpcsvc.dll               6.1.7600.16385               DHCP-
    dhcpcsvc6.dll              6.1.7601.17970               DHCPv6
    dhcpqec.dll                6.1.7600.16385                   Microsoft DHCP
    dhcpsapi.dll               6.1.7600.16385               API  DHCP-c
    difxapi.dll                2.1.0.0                     Driver Install Frameworks for API library module
    dimsjob.dll                6.1.7600.16385               DLL  DIMS
    dimsroam.dll               6.1.7601.18409               DLL  DIMS  
    dinput.dll                 6.1.7600.16385              Microsoft DirectInput
    dinput8.dll                6.1.7600.16385              Microsoft DirectInput
    directdb.dll               6.1.7600.16385              Microsoft Direct Database API
    diskcopy.dll               6.1.7600.16385              Windows DiskCopy
    dispex.dll                 5.8.7600.16385              Microsoft  DispEx
    display.dll                6.1.7601.17514                
    dmband.dll                 6.1.7600.16385              Microsoft DirectMusic Band
    dmcompos.dll               6.1.7600.16385              Microsoft DirectMusic Composer
    dmdlgs.dll                 6.1.7600.16385              Disk Management Snap-in Dialogs
    dmdskmgr.dll               6.1.7600.16385              Disk Management Snap-in Support Library
    dmdskres.dll               6.1.7600.16385                 
    dmdskres2.dll              6.1.7600.16385                 
    dmime.dll                  6.1.7600.16385              Microsoft DirectMusic Interactive Engine
    dmintf.dll                 6.1.7600.16385              Disk Management DCOM Interface Stub
    dmloader.dll               6.1.7600.16385              Microsoft DirectMusic Loader
    dmocx.dll                  6.1.7600.16385              TreeView OCX
    dmrc.dll                   6.1.7600.16385              Windows MRC
    dmscript.dll               6.1.7600.16385              Microsoft DirectMusic Scripting
    dmstyle.dll                6.1.7600.16385              Microsoft DirectMusic Style Engline
    dmsynth.dll                6.1.7600.16385              Microsoft DirectMusic Software Synthesizer
    dmusic.dll                 6.1.7600.16385                Microsoft DirectMusic
    dmutil.dll                 6.1.7600.16385                 
    dmvdsitf.dll               6.1.7600.16385              Disk Management Snap-in Support Library
    dnsapi.dll                 6.1.7601.17570                API DNS-
    dnscmmc.dll                6.1.7601.17514               DLL  DNS  MMC
    docprop.dll                6.1.7600.16385                OLE
    dot3api.dll                6.1.7601.17514              802.3 Autoconfiguration API
    dot3cfg.dll                6.1.7601.17514               Netsh  802.3
    dot3dlg.dll                6.1.7600.16385                UI  802.3
    dot3gpclnt.dll             6.1.7600.16385                   802.3
    dot3gpui.dll               6.1.7600.16385               "   802.3"
    dot3hc.dll                 6.1.7600.16385                 Dot3
    dot3msm.dll                6.1.7601.17514                   802.3
    dot3ui.dll                 6.1.7601.17514                802.3
    dpapiprovider.dll          6.1.7601.18409               DLL dpapiprovider
    dplayx.dll                 6.1.7600.16385              Microsoft DirectPlay
    dpmodemx.dll               6.1.7600.16385                      DirectPlay
    dpnaddr.dll                6.1.7601.17514              Microsoft DirectPlay8 Address
    dpnathlp.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper UPnP
    dpnet.dll                  6.1.7601.17989              Microsoft DirectPlay
    dpnhpast.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper PAST
    dpnhupnp.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper UPNP
    dpnlobby.dll               6.1.7600.16385              Microsoft DirectPlay8 Lobby
    dpwsockx.dll               6.1.7600.16385                  TCP/IP  IPX  DirectPlay
    dpx.dll                    6.1.7601.17514              Microsoft(R) Delta Package Expander
    drmmgrtn.dll               11.0.7601.23471             DRM Migration DLL
    drmv2clt.dll               11.0.7601.23471             DRMv2 Client DLL
    drprov.dll                 6.1.7600.16385                   ,        ()
    drt.dll                    6.1.7600.16385                
    drtprov.dll                6.1.7600.16385              Distributed Routing Table Providers
    drttransport.dll           6.1.7600.16385              Distributed Routing Table Transport Provider
    drvstore.dll               6.1.7601.17514              Driver Store API
    ds32gt.dll                 6.1.7600.16385              ODBC Driver Setup Generic Thunk
    dsauth.dll                 6.1.7601.17514              DS Authorization for Services
    dsdmo.dll                  6.1.7600.16385              DirectSound Effects
    dshowrdpfilter.dll         1.0.0.0                           ()
    dskquota.dll               6.1.7600.16385               DLL    Windows
    dskquoui.dll               6.1.7601.17514               DLL   
    dsound.dll                 6.1.7600.16385              DirectSound
    dsprop.dll                 6.1.7600.16385                Active Directory
    dsquery.dll                6.1.7600.16385                 
    dsrole.dll                 6.1.7600.16385              DS Role Client DLL
    dssec.dll                  6.1.7600.16385                 
    dssenh.dll                 6.1.7600.16385              Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider
    dsuiext.dll                6.1.7601.17514                 
    dswave.dll                 6.1.7600.16385              Microsoft DirectMusic Wave
    dtsh.dll                   6.1.7600.16385               API     
    dui70.dll                  6.1.7600.16385               DirectUI Windows
    duser.dll                  6.1.7600.16385              Windows DirectUser Engine
    dwmapi.dll                 6.1.7601.18917               API     ()
    dwmcore.dll                6.1.7601.18917                Microsoft DWM
    dwrite.dll                 6.2.9200.22164               Microsoft DirectX Typography
    dxdiagn.dll                6.1.7601.17514                Microsoft DirectX
    dxgi.dll                   6.2.9200.16492              DirectX Graphics Infrastructure
    dxmasf.dll                 12.0.7601.23930             Microsoft Windows Media Component Removal File.
    dxptaskringtone.dll        6.1.7601.23864                 Microsoft
    dxptasksync.dll            6.1.7601.17514               Microsoft Windows DXP
    dxtmsft.dll                11.0.9600.18921             DirectX Media -- Image DirectX Transforms
    dxtrans.dll                11.0.9600.18921             DirectX Media -- DirectX Transform Core
    dxva2.dll                  6.1.7600.16385              DirectX Video Acceleration 2.0 DLL
    eapp3hst.dll               6.1.7601.17514              Microsoft ThirdPartyEapDispatcher
    eappcfg.dll                6.1.7600.16385                EAP
    eappgnui.dll               6.1.7601.17514                 EAP
    eapphost.dll               6.1.7601.17514                 EAPHost 
    eappprxy.dll               6.1.7600.16385              Microsoft EAPHost Peer Client DLL
    eapqec.dll                 6.1.7600.16385                   Microsoft EAP
    efsadu.dll                 6.1.7600.16385                
    efscore.dll                6.1.7601.17514              EFS Core Library
    efsutil.dll                6.1.7600.16385              EFS Utility Library
    ehstorapi.dll              6.1.7601.17514              Windows Enhanced Storage API
    ehstorpwdmgr.dll           6.1.7600.16385                Windows Enhanced Storage
    ehstorshell.dll            6.1.7600.16385               DLL   Windows Enhanced Storage
    els.dll                    6.1.7601.19054                
    elscore.dll                6.1.7600.16385               DLL   Els
    elshyph.dll                6.3.9600.16428              ELS Hyphenation Service
    elslad.dll                 6.1.7600.16385              ELS Language Detection
    elstrans.dll               6.1.7601.17514              ELS Transliteration Service
    encapi.dll                 6.1.7600.16385              Encoder API
    encdec.dll                 6.6.7601.19135                XDS     .
    eqossnap.dll               6.1.7600.16385                EQoS
    es.dll                     2001.12.8530.16385          COM+
    esent.dll                  6.1.7601.17577                  ESE  Microsoft(R) Windows(R)
    esentprf.dll               6.1.7600.16385              Extensible Storage Engine Performance Monitoring Library for Microsoft(R) Windows(R)
    eventcls.dll               6.1.7600.16385              Microsoft Volume Shadow Copy Service event class
    evr.dll                    6.1.7601.23471                DLL   
    explorerframe.dll          6.1.7601.24000              ExplorerFrame
    expsrv.dll                 6.0.72.9589                 Visual Basic for Applications Runtime - Expression Service
    f3ahvoas.dll               6.1.7600.16385              JP Japanese Keyboard Layout for Fujitsu FMV oyayubi-shift keyboard
    faultrep.dll               6.1.7601.17514                     Windows
    fdbth.dll                  6.1.7600.16385              Function Discovery Bluetooth Provider Dll
    fdbthproxy.dll             6.1.7600.16385              Bluetooth Provider Proxy Dll
    fde.dll                    6.1.7601.17514                 
    fdeploy.dll                6.1.7601.17514                  
    fdpnp.dll                  6.1.7600.16385              Pnp Provider Dll
    fdproxy.dll                6.1.7600.16385              Function Discovery Proxy Dll
    fdssdp.dll                 6.1.7600.16385              Function Discovery SSDP Provider Dll
    fdwcn.dll                  6.1.7601.24000              Windows Connect Now - Config Function Discovery Provider DLL
    fdwnet.dll                 6.1.7600.16385              Function Discovery WNet Provider Dll
    fdwsd.dll                  6.1.7600.16385              Function Discovery WS Discovery Provider Dll
    feclient.dll               6.1.7600.16385              Windows NT File Encryption Client Interfaces
    filemgmt.dll               6.1.7600.16385                 
    findnetprinters.dll        6.1.7600.16385              Find Network Printers COM Component
    firewallapi.dll            6.1.7601.24000              API  Windows
    firewallcontrolpanel.dll   6.1.7601.17514                -  Windows
    fltlib.dll                 6.1.7600.16385               
    fmifs.dll                  6.1.7600.16385              FM IFS Utility DLL
    fms.dll                    1.1.6000.16384                
    fontext.dll                6.1.7601.17514                Windows
    fontsub.dll                6.1.7601.24007              Font Subsetting DLL
    fphc.dll                   6.1.7601.17514               Filtering Platform Helper
    framedyn.dll               6.1.7601.17514              WMI SDK Provider Framework
    framedynos.dll             6.1.7601.17514              WMI SDK Provider Framework
    fthsvc.dll                 6.1.7600.16385                  Microsoft Windows
    fundisc.dll                6.1.7600.16385              DLL  
    fwcfg.dll                  6.1.7600.16385                  Windows
    fwpuclnt.dll               6.1.7601.24000              API   FWP/IPsec
    fwremotesvr.dll            6.1.7601.23452              Windows Firewall Remote APIs Server
    fxsapi.dll                 6.1.7600.16385              Microsoft  Fax API Support DLL
    fxscom.dll                 6.1.7600.16385              Microsoft Fax Server COM Client Interface
    fxscomex.dll               6.1.7600.16385              Microsoft Fax Server Extended COM Client Interface
    fxsext32.dll               6.1.7600.16385              Microsoft  Fax Exchange Command Extension
    fxsresm.dll                6.1.7600.16385               DLL   (Microsoft)
    fxsxp32.dll                6.1.7600.16385              Microsoft  Fax Transport Provider
    gamemanager32.dll                                      
    gameux.dll                 6.1.7601.18020               
    gameuxlegacygdfs.dll       1.0.0.1                     Legacy GDF resource DLL
    gcdef.dll                  6.1.7600.16385                   
    gdi32.dll                  6.1.7601.23914              GDI Client DLL
    getuname.dll               6.1.7600.16385                   UCE
    glmf32.dll                 6.1.7600.16385              OpenGL Metafiling DLL
    glu32.dll                  6.1.7600.16385                OpenGL
    gpapi.dll                  6.1.7601.23452                API  
    gpedit.dll                 6.1.7601.23932              GPEdit
    gpprefcl.dll               6.1.7601.23452                 
    gpprnext.dll               6.1.7600.16385                 
    gpscript.dll               6.1.7601.23452                
    gptext.dll                 6.1.7600.16385              GPTExt
    hbaapi.dll                 6.1.7601.17514              HBA API data interface dll for HBA_API_Rev_2-18_2002MAR1.doc
    hcproviders.dll            6.1.7600.16385                
    helppaneproxy.dll          6.1.7600.16385              Microsoft Help Proxy
    hgcpl.dll                  6.1.7601.17514                 
    hhsetup.dll                6.1.7600.16385              Microsoft HTML Help
    hid.dll                    6.1.7600.16385                HID
    hidserv.dll                6.1.7600.16385               HID
    hlink.dll                  6.1.7601.23601               Microsoft Office 2000
    hnetcfg.dll                6.1.7600.16385                 
    hnetmon.dll                6.1.7600.16385              DLL   
    hssrv.dll                  1.0.12.106                  HsSrv Dynamic Link Library
    hssrv2.dll                 1.0.12.106                  HsSrv Dynamic Link Library
    httpapi.dll                6.1.7601.17514              HTTP Protocol Stack API
    htui.dll                   6.1.7600.16385                  
    ias.dll                    6.1.7600.16385                 (NPS)
    iasacct.dll                6.1.7601.17514                NPS
    iasads.dll                 6.1.7600.16385                Active Directory NPS
    iasdatastore.dll           6.1.7600.16385              NPS Datastore server
    iashlpr.dll                6.1.7600.16385                NPS
    iasmigplugin.dll           6.1.7600.16385              NPS Migration DLL
    iasnap.dll                 6.1.7600.16385              NPS NAP Provider
    iaspolcy.dll               6.1.7600.16385              NPS Pipeline
    iasrad.dll                 6.1.7601.17514                RADIUS NPS
    iasrecst.dll               6.1.7601.17514              NPS XML Datastore Access
    iassam.dll                 6.1.7600.16385              NPS NT SAM Provider
    iassdo.dll                 6.1.7600.16385               SDO NPS
    iassvcs.dll                6.1.7600.16385                NPS
    icardie.dll                11.0.9600.16428             Microsoft Information Card IE Helper
    icardres.dll               3.0.4506.5464               Windows CardSpace
    iccvid.dll                 1.10.0.13                    Cinepak
    icm32.dll                  6.1.7601.23971              Microsoft Color Management Module (CMM)
    icmp.dll                   6.1.7600.16385              ICMP DLL
    icmui.dll                  6.1.7600.16385                  
    iconcodecservice.dll       6.1.7600.16385              Converts a PNG part of the icon to a legacy bmp icon
    icsigd.dll                 6.1.7600.16385                 
    idndl.dll                  6.1.7600.16385              Downlevel DLL
    idstore.dll                6.1.7600.16385              Identity Store
    ieadvpack.dll              11.0.9600.16428             ADVPACK
    ieapfltr.dll               11.0.9600.18921             Microsoft SmartScreen Filter
    iedkcs32.dll               18.0.9600.18921               IEAK
    ieetwproxystub.dll         11.0.9600.18921             IE ETW Collector Proxy Stub Resources
    ieframe.dll                11.0.9600.18921             
    iepeers.dll                11.0.9600.16428             Peer- Internet Explorer
    iernonce.dll               11.0.9600.18921               RunOnce   
    iertutil.dll               11.0.9600.18921             Run time utility for Internet Explorer
    iesetup.dll                11.0.9600.18921               IOD
    iesysprep.dll              11.0.9600.16428             IE Sysprep Provider
    ieui.dll                   11.0.9600.18921                Internet Explorer
    ifmon.dll                  6.1.7600.16385                IF
    ifsutil.dll                6.1.7601.17514              IFS Utility DLL
    ifsutilx.dll               6.1.7600.16385              IFS Utility Extension DLL
    imagehlp.dll               6.1.7601.18288              Windows NT Image Helper
    imageres.dll               6.1.7600.16385              Windows Image Resource
    imagesp1.dll               6.1.7600.16385              Windows SP1 Image Resource
    imapi.dll                  6.1.7600.16385               Image Mastering API
    imapi2.dll                 6.1.7601.17514              IMAPI  2
    imapi2fs.dll               6.1.7601.17514              Image Mastering File System Imaging API v2
    imgutil.dll                11.0.9600.16428             IE plugin image decoder support DLL
    imjp10k.dll                10.1.7601.23572             Microsoft IME
    imm32.dll                  6.1.7601.17514              Multi-User Windows IMM32 API Client DLL
    inetcomm.dll               6.1.7601.24000              Microsoft Internet Messaging API Resources
    inetmib1.dll               6.1.7601.17514              Microsoft MIB-II subagent
    inetres.dll                6.1.7601.24000               API  
    infocardapi.dll            3.0.4506.5461               Microsoft InfoCards
    inked.dll                  6.1.7601.23375              Microsoft Tablet PC InkEdit Control
    input.dll                  6.1.7601.23572               DLL  
    inseng.dll                 11.0.9600.18921              
    iologmsg.dll               6.1.7601.18386                /
    ipbusenumproxy.dll         6.1.7600.16385              Associated Device Presence Proxy Dll
    iphlpapi.dll               6.1.7601.17514              IP Helper API
    iprop.dll                  6.1.7600.16385              OLE PropertySet Implementation
    iprtprio.dll               6.1.7601.23947              IP Routing Protocol Priority DLL
    iprtrmgr.dll               6.1.7601.23947               IP-
    ipsecsnp.dll               6.1.7600.16385                 IP-
    ipsmsnap.dll               6.1.7601.17514                IP-
    ir32_32.dll                3.24.15.3                   32-  Intel Indeo(R) Video R3.2
    ir41_qc.dll                4.30.62.2                   Intel Indeo Video Interactive Quick Compressor
    ir41_qcx.dll               4.30.62.2                   Intel Indeo Video Interactive Quick Compressor
    ir50_32.dll                5.2562.15.55                Intel Indeo video 5.10
    ir50_qc.dll                5.0.63.48                   Intel Indeo video 5.10 Quick Compressor
    ir50_qcx.dll               5.0.63.48                   Intel Indeo video 5.10 Quick Compressor
    irclass.dll                6.1.7600.16385                 
    iscsicpl.dll               5.2.3790.1830                   iSCSI
    iscsidsc.dll               6.1.7600.16385              API-  iSCSI
    iscsied.dll                6.1.7600.16385              iSCSI Extension DLL
    iscsium.dll                6.1.7601.17514              iSCSI Discovery api
    iscsiwmi.dll               6.1.7600.16385              MS iSCSI Initiator WMI Provider
    itircl.dll                 6.1.7601.23948              Microsoft InfoTech IR Local DLL
    itss.dll                   6.1.7601.23948              Microsoft InfoTech Storage System Library
    itvdata.dll                6.6.7601.17514              iTV Data Filters.
    iyuv_32.dll                6.1.7601.17514              Intel Indeo(R) Video YUV 
    javascriptcollectionagent.dll  11.0.9600.18921             JavaScript Performance Collection Agent
    jscript.dll                5.8.9600.18921              Microsoft  JScript
    jscript9.dll               11.0.9600.18921             Microsoft  JScript
    jscript9diag.dll           11.0.9600.18921             Microsoft  JScript Diagnostics
    jsintl.dll                 6.3.9600.16428              Windows Globalization
    jsproxy.dll                11.0.9600.18921             JScript Proxy Auto-Configuration
    kbd101.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for 101
    kbd101a.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101 (Type A)
    kbd101b.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101(Type B)
    kbd101c.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101(Type C)
    kbd103.dll                 6.1.7600.16385              KO Hangeul Keyboard Layout for 103
    kbd106.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for 106
    kbd106n.dll                6.1.7600.16385              JP Japanese Keyboard Layout for 106
    kbda1.dll                  6.1.7600.16385              Arabic_English_101 Keyboard Layout
    kbda2.dll                  6.1.7600.16385              Arabic_2 Keyboard Layout
    kbda3.dll                  6.1.7600.16385              Arabic_French_102 Keyboard Layout
    kbdal.dll                  6.1.7600.16385              Albania Keyboard Layout
    kbdarme.dll                6.1.7600.16385              Eastern Armenian Keyboard Layout
    kbdarmw.dll                6.1.7600.16385              Western Armenian Keyboard Layout
    kbdax2.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for AX2
    kbdaze.dll                 6.1.7601.19106              Azerbaijan_Cyrillic Keyboard Layout
    kbdazel.dll                6.1.7601.19106              Azeri-Latin Keyboard Layout
    kbdbash.dll                6.1.7601.18528              Bashkir Keyboard Layout
    kbdbe.dll                  6.1.7600.16385              Belgian Keyboard Layout
    kbdbene.dll                6.1.7600.16385              Belgian Dutch Keyboard Layout
    kbdbgph.dll                6.1.7600.16385              Bulgarian Phonetic Keyboard Layout
    kbdbgph1.dll               6.1.7600.16385              Bulgarian (Phonetic Traditional) Keyboard Layout
    kbdbhc.dll                 6.1.7600.16385              Bosnian (Cyrillic) Keyboard Layout
    kbdblr.dll                 6.1.7601.17514              Belarusian Keyboard Layout
    kbdbr.dll                  6.1.7600.16385              Brazilian Keyboard Layout
    kbdbu.dll                  6.1.7600.16385              Bulgarian (Typewriter) Keyboard Layout
    kbdbulg.dll                6.1.7601.17514              Bulgarian Keyboard Layout
    kbdca.dll                  6.1.7600.16385              Canadian Multilingual Keyboard Layout
    kbdcan.dll                 6.1.7600.16385              Canadian Multilingual Standard Keyboard Layout
    kbdcr.dll                  6.1.7600.16385              Croatian/Slovenian Keyboard Layout
    kbdcz.dll                  6.1.7600.16385              Czech Keyboard Layout
    kbdcz1.dll                 6.1.7601.17514              Czech_101 Keyboard Layout
    kbdcz2.dll                 6.1.7600.16385              Czech_Programmer's Keyboard Layout
    kbdda.dll                  6.1.7600.16385              Danish Keyboard Layout
    kbddiv1.dll                6.1.7600.16385              Divehi Phonetic Keyboard Layout
    kbddiv2.dll                6.1.7600.16385              Divehi Typewriter Keyboard Layout
    kbddv.dll                  6.1.7600.16385              Dvorak US English Keyboard Layout
    kbdes.dll                  6.1.7600.16385              Spanish Alernate Keyboard Layout
    kbdest.dll                 6.1.7600.16385              Estonia Keyboard Layout
    kbdfa.dll                  6.1.7600.16385              Persian Keyboard Layout
    kbdfc.dll                  6.1.7600.16385              Canadian French Keyboard Layout
    kbdfi.dll                  6.1.7600.16385              Finnish Keyboard Layout
    kbdfi1.dll                 6.1.7600.16385              Finnish-Swedish with Sami Keyboard Layout
    kbdfo.dll                  6.1.7600.16385              F?roese Keyboard Layout
    kbdfr.dll                  6.1.7600.16385              French Keyboard Layout
    kbdgae.dll                 6.1.7600.16385              Gaelic Keyboard Layout
    kbdgeo.dll                 6.1.7601.17514              Georgian Keyboard Layout
    kbdgeoer.dll               6.1.7600.16385              Georgian (Ergonomic) Keyboard Layout
    kbdgeoqw.dll               6.1.7601.19106              Georgian (QWERTY) Keyboard Layout
    kbdgkl.dll                 6.1.7601.17514              Greek_Latin Keyboard Layout
    kbdgr.dll                  6.1.7600.16385              German Keyboard Layout
    kbdgr1.dll                 6.1.7601.17514              German_IBM Keyboard Layout
    kbdgrlnd.dll               6.1.7600.16385              Greenlandic Keyboard Layout
    kbdhau.dll                 6.1.7600.16385              Hausa Keyboard Layout
    kbdhe.dll                  6.1.7600.16385              Greek Keyboard Layout
    kbdhe220.dll               6.1.7600.16385              Greek IBM 220 Keyboard Layout
    kbdhe319.dll               6.1.7600.16385              Greek IBM 319 Keyboard Layout
    kbdheb.dll                 6.1.7600.16385              KBDHEB Keyboard Layout
    kbdhela2.dll               6.1.7600.16385              Greek IBM 220 Latin Keyboard Layout
    kbdhela3.dll               6.1.7600.16385              Greek IBM 319 Latin Keyboard Layout
    kbdhept.dll                6.1.7600.16385              Greek_Polytonic Keyboard Layout
    kbdhu.dll                  6.1.7600.16385              Hungarian Keyboard Layout
    kbdhu1.dll                 6.1.7600.16385              Hungarian 101-key Keyboard Layout
    kbdibm02.dll               6.1.7600.16385              JP Japanese Keyboard Layout for IBM 5576-002/003
    kbdibo.dll                 6.1.7600.16385              Igbo Keyboard Layout
    kbdic.dll                  6.1.7600.16385              Icelandic Keyboard Layout
    kbdinasa.dll               6.1.7600.16385              Assamese (Inscript) Keyboard Layout
    kbdinbe1.dll               6.1.7600.16385              Bengali - Inscript (Legacy) Keyboard Layout
    kbdinbe2.dll               6.1.7600.16385              Bengali (Inscript) Keyboard Layout
    kbdinben.dll               6.1.7601.17514              Bengali Keyboard Layout
    kbdindev.dll               6.1.7600.16385              Devanagari Keyboard Layout
    kbdinguj.dll               6.1.7600.16385              Gujarati Keyboard Layout
    kbdinhin.dll               6.1.7601.17514              Hindi Keyboard Layout
    kbdinkan.dll               6.1.7601.17514              Kannada Keyboard Layout
    kbdinmal.dll               6.1.7600.16385              Malayalam Keyboard Layout Keyboard Layout
    kbdinmar.dll               6.1.7601.17514              Marathi Keyboard Layout
    kbdinori.dll               6.1.7601.17514              Oriya Keyboard Layout
    kbdinpun.dll               6.1.7600.16385              Punjabi/Gurmukhi Keyboard Layout
    kbdintam.dll               6.1.7601.17514              Tamil Keyboard Layout
    kbdintel.dll               6.1.7601.17514              Telugu Keyboard Layout
    kbdinuk2.dll               6.1.7600.16385              Inuktitut Naqittaut Keyboard Layout
    kbdir.dll                  6.1.7600.16385              Irish Keyboard Layout
    kbdit.dll                  6.1.7600.16385              Italian Keyboard Layout
    kbdit142.dll               6.1.7600.16385              Italian 142 Keyboard Layout
    kbdiulat.dll               6.1.7600.16385              Inuktitut Latin Keyboard Layout
    kbdjpn.dll                 6.1.7600.16385              JP Japanese Keyboard Layout Stub driver
    kbdkaz.dll                 6.1.7600.16385              Kazak_Cyrillic Keyboard Layout
    kbdkhmr.dll                6.1.7600.16385              Cambodian Standard Keyboard Layout
    kbdkor.dll                 6.1.7600.16385              KO Hangeul Keyboard Layout Stub driver
    kbdkyr.dll                 6.1.7600.16385              Kyrgyz Keyboard Layout
    kbdla.dll                  6.1.7600.16385              Latin-American Spanish Keyboard Layout
    kbdlao.dll                 6.1.7600.16385              Lao Standard Keyboard Layout
    kbdlk41a.dll               6.1.7601.17514              DEC LK411-AJ Keyboard Layout
    kbdlt.dll                  6.1.7600.16385              Lithuania Keyboard Layout
    kbdlt1.dll                 6.1.7601.17514              Lithuanian Keyboard Layout
    kbdlt2.dll                 6.1.7600.16385              Lithuanian Standard Keyboard Layout
    kbdlv.dll                  6.1.7600.16385              Latvia Keyboard Layout
    kbdlv1.dll                 6.1.7600.16385              Latvia-QWERTY Keyboard Layout
    kbdmac.dll                 6.1.7600.16385              Macedonian (FYROM) Keyboard Layout
    kbdmacst.dll               6.1.7600.16385              Macedonian (FYROM) - Standard Keyboard Layout
    kbdmaori.dll               6.1.7601.17514              Maori Keyboard Layout
    kbdmlt47.dll               6.1.7600.16385              Maltese 47-key Keyboard Layout
    kbdmlt48.dll               6.1.7600.16385              Maltese 48-key Keyboard Layout
    kbdmon.dll                 6.1.7601.17514              Mongolian Keyboard Layout
    kbdmonmo.dll               6.1.7600.16385              Mongolian (Mongolian Script) Keyboard Layout
    kbdne.dll                  6.1.7600.16385              Dutch Keyboard Layout
    kbdnec.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800)
    kbdnec95.dll               6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800 Windows 95)
    kbdnecat.dll               6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800 on PC98-NX)
    kbdnecnt.dll               6.1.7600.16385              JP Japanese NEC PC-9800 Keyboard Layout
    kbdnepr.dll                6.1.7601.17514              Nepali Keyboard Layout
    kbdno.dll                  6.1.7600.16385              Norwegian Keyboard Layout
    kbdno1.dll                 6.1.7600.16385              Norwegian with Sami Keyboard Layout
    kbdnso.dll                 6.1.7600.16385              Sesotho sa Leboa Keyboard Layout
    kbdpash.dll                6.1.7600.16385              Pashto (Afghanistan) Keyboard Layout
    kbdpl.dll                  6.1.7600.16385              Polish Keyboard Layout
    kbdpl1.dll                 6.1.7600.16385              Polish Programmer's Keyboard Layout
    kbdpo.dll                  6.1.7601.17514              Portuguese Keyboard Layout
    kbdro.dll                  6.1.7600.16385              Romanian (Legacy) Keyboard Layout
    kbdropr.dll                6.1.7600.16385              Romanian (Programmers) Keyboard Layout
    kbdrost.dll                6.1.7600.16385              Romanian (Standard) Keyboard Layout
    kbdru.dll                  6.1.7601.18528              Russian Keyboard Layout
    kbdru1.dll                 6.1.7601.18528              Russia(Typewriter) Keyboard Layout
    kbdsf.dll                  6.1.7601.17514              Swiss French Keyboard Layout
    kbdsg.dll                  6.1.7601.17514              Swiss German Keyboard Layout
    kbdsl.dll                  6.1.7600.16385              Slovak Keyboard Layout
    kbdsl1.dll                 6.1.7600.16385              Slovak(QWERTY) Keyboard Layout
    kbdsmsfi.dll               6.1.7600.16385              Sami Extended Finland-Sweden Keyboard Layout
    kbdsmsno.dll               6.1.7600.16385              Sami Extended Norway Keyboard Layout
    kbdsn1.dll                 6.1.7600.16385              Sinhala Keyboard Layout
    kbdsorex.dll               6.1.7600.16385              Sorbian Extended Keyboard Layout
    kbdsors1.dll               6.1.7600.16385              Sorbian Standard Keyboard Layout
    kbdsorst.dll               6.1.7600.16385              Sorbian Standard (Legacy) Keyboard Layout
    kbdsp.dll                  6.1.7600.16385              Spanish Keyboard Layout
    kbdsw.dll                  6.1.7600.16385              Swedish Keyboard Layout
    kbdsw09.dll                6.1.7600.16385              Sinhala - Wij 9 Keyboard Layout
    kbdsyr1.dll                6.1.7600.16385              Syriac Standard Keyboard Layout
    kbdsyr2.dll                6.1.7600.16385              Syriac Phoenetic Keyboard Layout
    kbdtajik.dll               6.1.7601.17514              Tajik Keyboard Layout
    kbdtat.dll                 6.1.7601.18528              Tatar (Legacy) Keyboard Layout
    kbdth0.dll                 6.1.7600.16385              Thai Kedmanee Keyboard Layout
    kbdth1.dll                 6.1.7600.16385              Thai Pattachote Keyboard Layout
    kbdth2.dll                 6.1.7600.16385              Thai Kedmanee (non-ShiftLock) Keyboard Layout
    kbdth3.dll                 6.1.7600.16385              Thai Pattachote (non-ShiftLock) Keyboard Layout
    kbdtiprc.dll               6.1.7600.16385              Tibetan (PRC) Keyboard Layout
    kbdtuf.dll                 6.1.7601.17514              Turkish F Keyboard Layout
    kbdtuq.dll                 6.1.7601.17514              Turkish Q Keyboard Layout
    kbdturme.dll               6.1.7601.17514              Turkmen Keyboard Layout
    kbdughr.dll                6.1.7600.16385              Uyghur (Legacy) Keyboard Layout
    kbdughr1.dll               6.1.7601.17514              Uyghur Keyboard Layout
    kbduk.dll                  6.1.7600.16385              United Kingdom Keyboard Layout
    kbdukx.dll                 6.1.7600.16385              United Kingdom Extended Keyboard Layout
    kbdur.dll                  6.1.7600.16385              Ukrainian Keyboard Layout
    kbdur1.dll                 6.1.7600.16385              Ukrainian (Enhanced) Keyboard Layout
    kbdurdu.dll                6.1.7600.16385              Urdu Keyboard Layout
    kbdus.dll                  6.1.7601.17514              United States Keyboard Layout
    kbdusa.dll                 6.1.7600.16385              US IBM Arabic 238_L Keyboard Layout
    kbdusl.dll                 6.1.7600.16385              Dvorak Left-Hand US English Keyboard Layout
    kbdusr.dll                 6.1.7600.16385              Dvorak Right-Hand US English Keyboard Layout
    kbdusx.dll                 6.1.7600.16385              US Multinational Keyboard Layout
    kbduzb.dll                 6.1.7600.16385              Uzbek_Cyrillic Keyboard Layout
    kbdvntc.dll                6.1.7600.16385              Vietnamese Keyboard Layout
    kbdwol.dll                 6.1.7600.16385              Wolof Keyboard Layout
    kbdyak.dll                 6.1.7601.18528              Sakha - Russia Keyboard Layout
    kbdyba.dll                 6.1.7600.16385              Yoruba Keyboard Layout
    kbdycc.dll                 6.1.7600.16385              Serbian (Cyrillic) Keyboard Layout
    kbdycl.dll                 6.1.7600.16385              Serbian (Latin) Keyboard Layout
    kerberos.dll               6.1.7601.24024                Kerberos
    kernel32.dll               6.1.7601.24024                Windows NT BASE API
    kernelbase.dll             6.1.7601.24024                Windows NT BASE API
    keyiso.dll                 6.1.7600.16385                 CNG
    keymgr.dll                 6.1.7600.16385                  
    korwbrkr.dll               6.1.7600.16385              korwbrkr
    ksuser.dll                 6.1.7601.19091              User CSA Library
    ktmw32.dll                 6.1.7600.16385              Windows KTM Win32 Client DLL
    l2gpstore.dll              6.1.7600.16385              Policy Storage dll
    l2nacp.dll                 6.1.7600.16385                 Onex Windows
    l2sechc.dll                6.1.7600.16385                    2
    laprxy.dll                 12.0.7600.16385             Windows Media Logagent Proxy
    licmgr10.dll               11.0.9600.16428              (DLL)    Microsoft
    linkinfo.dll               6.1.7600.16385              Windows Volume Tracking
    loadperf.dll               6.1.7600.16385                  
    localsec.dll               6.1.7601.17514               MMC "   "
    locationapi.dll            6.1.7600.16385              Microsoft Windows Location API
    loghours.dll               6.1.7600.16385               
    logoncli.dll               6.1.7601.17514              Net Logon Client DLL
    lpk.dll                    6.1.7601.24007              Language Pack
    lsmproxy.dll               6.1.7601.17514              LSM interfaces proxy Dll
    luainstall.dll             6.1.7601.17514              Lua manifest install
    lz32.dll                   6.1.7600.16385              LZ Expand/Compress API DLL
    magnification.dll          6.1.7600.16385               API  ()
    mantle32.dll               24.20.11001.5003            Mantle loader
    mantleaxl32.dll            24.20.11001.5003            Mantle extension library
    mapi32.dll                 1.0.2536.0                   MAPI 1.0  Windows NT
    mapistub.dll               1.0.2536.0                   MAPI 1.0  Windows NT
    mbapo32.dll                1.0.62.0                    Creative Audio Processing Object Module
    mcewmdrmndbootstrap.dll    1.3.2302.0                  Windows Media Center WMDRM-ND Receiver Bridge Bootstrap DLL
    mciavi32.dll               6.1.7601.17514               MCI Video  Windows
    mcicda.dll                 6.1.7600.16385               MCI   cdaudio
    mciqtz32.dll               6.6.7601.17514               MCI DirectShow
    mciseq.dll                 6.1.7600.16385               MCI   MIDI
    mciwave.dll                6.1.7600.16385               MCI   
    mctres.dll                 6.1.7600.16385                MCT
    mdminst.dll                6.1.7600.16385               
    mediametadatahandler.dll   6.1.7601.17514              Media Metadata Handler
    mf.dll                     12.0.7601.23896               
    mf3216.dll                 6.1.7600.16385              32-bit to 16-bit Metafile Conversion DLL
    mfaacenc.dll               6.1.7600.16385              Media Foundation AAC Encoder
    mfc140.dll                 14.0.24123.0                MFCDLL Shared Library - Retail Version
    mfc140chs.dll              14.0.24123.0                MFC Language Specific Resources
    mfc140cht.dll              14.0.24123.0                MFC Language Specific Resources
    mfc140deu.dll              14.0.24123.0                MFC Language Specific Resources
    mfc140enu.dll              14.0.24123.0                MFC Language Specific Resources
    mfc140esn.dll              14.0.24123.0                MFC Language Specific Resources
    mfc140fra.dll              14.0.24123.0                MFC Language Specific Resources
    mfc140ita.dll              14.0.24123.0                MFC Language Specific Resources
    mfc140jpn.dll              14.0.24123.0                MFC Language Specific Resources
    mfc140kor.dll              14.0.24123.0                MFC Language Specific Resources
    mfc140rus.dll              14.0.24123.0                MFC Language Specific Resources
    mfc140u.dll                14.0.24123.0                MFCDLL Shared Library - Retail Version
    mfc40.dll                  4.1.0.6151                    MFCDLL -  
    mfc40u.dll                 4.1.0.6151                    MFCDLL -  
    mfc42.dll                  6.6.8064.0                    MFCDLL -  
    mfc42u.dll                 6.6.8064.0                    MFCDLL -  
    mfcm140.dll                14.0.24123.0                MFC Managed Library - Retail Version
    mfcm140u.dll               14.0.24123.0                MFC Managed Library - Retail Version
    mfcsubs.dll                2001.12.8530.16385          COM+
    mfds.dll                   12.0.7601.19145             Media Foundation Direct Show wrapper DLL
    mfdvdec.dll                6.1.7600.16385              Media Foundation DV Decoder
    mferror.dll                12.0.7601.23896                
    mfh264enc.dll              6.1.7600.16385              Media Foundation H264 Encoder
    mfmjpegdec.dll             6.1.7601.23709              Media Foundation MJPEG Decoder
    mfplat.dll                 12.0.7601.23471             Media Foundation Platform DLL
    mfplay.dll                 12.0.7601.17514             Media Foundation Playback API DLL
    mfps.dll                   12.0.7601.23896             Media Foundation Proxy DLL
    mfreadwrite.dll            12.0.7601.17514             Media Foundation ReadWrite DLL
    mfvdsp.dll                 6.1.7601.19091              Windows Media Foundation Video DSP Components
    mfwmaaec.dll               6.1.7601.19091              Windows Media Audio AEC for Media Foundation
    mgmtapi.dll                6.1.7600.16385              Microsoft SNMP Manager API (uses WinSNMP)
    midimap.dll                6.1.7600.16385              Microsoft MIDI Mapper
    migisol.dll                6.1.7601.17514              Migration System Isolation Layer
    miguiresource.dll          6.1.7600.16385               MIG wini32
    mimefilt.dll               2008.0.7601.17514            MIME
    mlang.dll                  6.1.7600.16385               DLL  
    mmcbase.dll                6.1.7601.23892                DLL MMC
    mmci.dll                   6.1.7600.16385                
    mmcico.dll                 6.1.7600.16385              Media class co-installer
    mmcndmgr.dll               6.1.7601.23892                 MMC
    mmcshext.dll               6.1.7601.23892              MMC Shell Extension DLL
    mmdevapi.dll               6.1.7601.17514              MMDevice API
    mmres.dll                  6.1.7600.16385               
    modemui.dll                6.1.7600.16385                Windows
    moricons.dll               6.1.7600.16385              Windows NT Setup Icon Resources Library
    mp3dmod.dll                6.1.7601.19091              Microsoft MP3 Decoder DMO
    mp43decd.dll               6.1.7601.19091              Windows Media MPEG-4 Video Decoder
    mp4sdecd.dll               6.1.7601.19091              Windows Media MPEG-4 S Video Decoder
    mpg4decd.dll               6.1.7601.19091              Windows Media MPEG-4 Video Decoder
    mpr.dll                    6.1.7600.16385                   
    mprapi.dll                 6.1.7601.17514              Windows NT MP Router Administration DLL
    mprddm.dll                 6.1.7601.17514                  
    mprdim.dll                 6.1.7601.23947                
    mprmsg.dll                 6.1.7600.16385               (DLL)    
    msaatext.dll               2.0.10413.0                 Active Accessibility text support
    msac3enc.dll               6.1.7601.17514              Microsoft AC-3 Encoder
    msacm32.dll                6.1.7600.16385                 Microsoft
    msadce.dll                 6.1.7601.17514              OLE DB Cursor Engine
    msadcer.dll                6.1.7600.16385              OLE DB Cursor Engine Resources
    msadcf.dll                 6.1.7601.24023              Remote Data Services Data Factory
    msadcfr.dll                6.1.7600.16385              Remote Data Services Data Factory Resources
    msadco.dll                 6.1.7601.17857              Remote Data Services Data Control
    msadcor.dll                6.1.7600.16385              Remote Data Services Data Control Resources
    msadcs.dll                 6.1.7601.24023              Remote Data Services ISAPI Library
    msadds.dll                 6.1.7600.16385              OLE DB Data Shape Provider
    msaddsr.dll                6.1.7600.16385               OLE DB Data Shape Provider Resources
    msader15.dll               6.1.7600.16385              ActiveX Data Objects Resources
    msado15.dll                6.1.7601.24023              ActiveX Data Objects
    msadomd.dll                6.1.7601.17857              ActiveX Data Objects (Multi-Dimensional)
    msador15.dll               6.1.7601.17857              Microsoft ActiveX Data Objects Recordset
    msadox.dll                 6.1.7601.17857              ActiveX Data Objects Extensions
    msadrh15.dll               6.1.7600.16385              ActiveX Data Objects Rowset Helper
    msafd.dll                  6.1.7600.16385              Microsoft Windows Sockets 2.0 Service Provider
    msasn1.dll                 6.1.7601.17514              ASN.1 Runtime APIs
    msaudite.dll               6.1.7601.24024                 
    mscandui.dll               6.1.7600.16385                MSCANDUI
    mscat32.dll                6.1.7600.16385              MSCAT32 Forwarder DLL
    msclmd.dll                 6.1.7601.17514              Microsoft Class Mini-driver
    mscms.dll                  6.1.7601.23971              DLL-    
    mscoree.dll                4.0.40305.0                 Microsoft .NET Runtime Execution Engine
    mscorier.dll               2.0.50727.5483               IE    Microsoft .NET
    mscories.dll               2.0.50727.5483              Microsoft .NET IE SECURITY REGISTRATION
    mscpx32r.dll               6.1.7600.16385              ODBC Code Page Translator Resources
    mscpxl32.dll               6.1.7600.16385                 ODBC
    msctf.dll                  6.1.7601.23915                MSCTF
    msctfmonitor.dll           6.1.7600.16385              MsCtfMonitor DLL
    msctfp.dll                 6.1.7600.16385              MSCTFP Server DLL
    msctfui.dll                6.1.7600.16385                MSCTFUI
    msdadc.dll                 6.1.7600.16385              OLE DB Data Conversion Stub
    msdadiag.dll               6.1.7600.16385              Built-In Diagnostics
    msdaenum.dll               6.1.7600.16385              OLE DB Root Enumerator Stub
    msdaer.dll                 6.1.7600.16385              OLE DB Error Collection Stub
    msdaora.dll                6.1.7601.23391              OLE DB Provider for Oracle
    msdaorar.dll               6.1.7600.16385              OLE DB Provider for Oracle Resources
    msdaosp.dll                6.1.7601.17632              OLE DB Simple Provider
    msdaprsr.dll               6.1.7600.16385                OLE DB Persistence Services
    msdaprst.dll               6.1.7600.16385              OLE DB Persistence Services
    msdaps.dll                 6.1.7600.16385              OLE DB Interface Proxies/Stubs
    msdarem.dll                6.1.7601.24023              OLE DB Remote Provider
    msdaremr.dll               6.1.7600.16385              OLE DB Remote Provider Resources
    msdart.dll                 6.1.7600.16385              OLE DB Runtime Routines
    msdasc.dll                 6.1.7600.16385              OLE DB Service Components Stub
    msdasql.dll                6.1.7601.17514              OLE DB Provider for ODBC Drivers
    msdasqlr.dll               6.1.7600.16385              OLE DB Provider for ODBC Drivers Resources
    msdatl3.dll                6.1.7600.16385              OLE DB Implementation Support Routines
    msdatt.dll                 6.1.7600.16385              OLE DB Temporary Table Services
    msdaurl.dll                6.1.7600.16385              OLE DB RootBinder Stub
    msdelta.dll                6.1.7600.16385              Microsoft Patch Engine
    msdfmap.dll                6.1.7601.17514              Data Factory Handler
    msdmo.dll                  6.6.7601.17514              DMO Runtime
    msdrm.dll                  6.1.7601.18332                 Windows
    msdtcprx.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL
    msdtcuiu.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Administrative DLL
    msdtcvsp1res.dll           2001.12.8530.16385               Vista SP1
    msexch40.dll               4.0.9756.0                  Microsoft Jet Exchange Isam
    msexcl40.dll               4.0.9801.2                  Microsoft Jet Excel Isam
    msfeeds.dll                11.0.9600.18921             Microsoft Feeds Manager
    msfeedsbs.dll              11.0.9600.16428               - ()
    msftedit.dll               5.41.21.2510                Rich Text Edit Control, v4.1
    mshtml.dll                 11.0.9600.18921               HTML Microsoft
    mshtmldac.dll              11.0.9600.18921             DAC for Trident DOM
    mshtmled.dll               11.0.9600.18921             Microsoft HTML Editing Component
    mshtmler.dll               11.0.9600.16428                 HTML (Microsoft)
    mshtmlmedia.dll            11.0.9600.18921             Microsoft (R) HTML Media DLL
    msi.dll                    5.0.7601.23593              Windows Installer
    msidcrl30.dll              6.1.7600.16385              IDCRL Dynamic Link Library
    msident.dll                6.1.7600.16385                (Microsoft)
    msidle.dll                 6.1.7600.16385              User Idle Monitor
    msidntld.dll               6.1.7600.16385                (Microsoft)
    msieftp.dll                6.1.7601.18300                Microsoft Internet Explorer  FTP
    msihnd.dll                 5.0.7601.23593              Windows installer
    msiltcfg.dll               5.0.7600.16385              Windows Installer Configuration API Stub
    msimg32.dll                6.1.7600.16385              GDIEXT Client DLL
    msimsg.dll                 5.0.7601.23593                 Windows
    msimtf.dll                 6.1.7600.16385              Active IMM Server DLL
    msisip.dll                 5.0.7600.16385              MSI Signature SIP Provider
    msjet40.dll                4.0.9801.0                  Microsoft Jet Engine Library
    msjetoledb40.dll           4.0.9801.0                  
    msjint40.dll               4.0.9801.1                       Microsoft Jet
    msjro.dll                  6.1.7601.17857              Jet and Replication Objects
    msjter40.dll               4.0.9801.0                  Microsoft Jet Database Engine Error DLL
    msjtes40.dll               4.0.9801.0                  Microsoft Jet Expression Service
    msls31.dll                 3.10.349.0                  Microsoft Line Services library file
    msltus40.dll               4.0.9801.0                  Microsoft Jet Lotus 1-2-3 Isam
    msmpeg2adec.dll            6.1.7601.23285              Microsoft DTV-DVD Audio Decoder
    msmpeg2enc.dll             6.1.7601.19091               Microsoft MPEG-2
    msmpeg2vdec.dll            12.0.9200.17037             Microsoft DTV-DVD Video Decoder
    msnetobj.dll               11.0.7601.23471             DRM ActiveX Network Object
    msobjs.dll                 6.1.7601.24024                 
    msoeacct.dll               6.1.7600.16385              Microsoft Internet Account Manager
    msoert2.dll                6.1.7600.16385              Microsoft Windows Mail RT Lib
    msorc32r.dll               6.1.7600.16385                ODBC  Oracle
    msorcl32.dll               6.1.7601.23391              ODBC Driver for Oracle
    mspatcha.dll               6.1.7600.16385              Microsoft File Patch Application API
    mspbde40.dll               4.0.9801.0                  Microsoft Jet Paradox Isam
    msports.dll                6.1.7600.16385                 
    msrating.dll               11.0.9600.18921                  
    msrd2x40.dll               4.0.9801.0                  Microsoft (R) Red ISAM
    msrd3x40.dll               4.0.9801.0                  Microsoft (R) Red ISAM
    msrdc.dll                  6.1.7600.16385              Remote Differential Compression COM server
    msrdpwebaccess.dll         6.3.9600.16415              Microsoft Remote Desktop Services Web Access Control
    msrepl40.dll               4.0.9801.0                  Microsoft Replication Library
    msrle32.dll                6.1.7601.17514              Microsoft RLE Compressor
    msscntrs.dll               7.0.7601.23930              msscntrs.dll
    msscp.dll                  11.0.7601.23471             Windows Media Secure Content Provider
    mssha.dll                  6.1.7600.16385                  Windows
    msshavmsg.dll              6.1.7600.16385                     Windows
    msshooks.dll               7.0.7601.23930              MSSHooks.dll
    mssign32.dll               6.1.7600.16385               API  
    mssip32.dll                6.1.7600.16385              MSSIP32 Forwarder DLL
    mssitlb.dll                7.0.7601.23930              mssitlb
    mssph.dll                  7.0.7601.23930                 Microsoft
    mssphtb.dll                7.0.7601.23930              Outlook MSSearch Connector
    mssprxy.dll                7.0.7601.23930              Microsoft Search Proxy
    mssrch.dll                 7.0.7601.23930              mssrch.dll
    mssvp.dll                  7.0.7601.23930               Vista MSSearch
    msswch.dll                 6.1.7600.16385              msswch
    mstask.dll                 6.1.7601.17514                 
    mstext40.dll               4.0.9756.0                  Microsoft Jet Text Isam
    mstscax.dll                6.3.9600.17930              ActiveX-    
    msutb.dll                  6.1.7601.17514               (DLL)  MSUTB
    msv1_0.dll                 6.1.7601.24024              Microsoft Authentication Package v1.0
    msvbvm60.dll               6.0.98.15                   Visual Basic Virtual Machine
    msvcirt.dll                7.0.7600.16385              Windows NT IOStreams DLL
    msvcp110_clr0400.dll       14.7.2558.0                 Microsoft .NET Framework
    msvcp120_clr0400.dll       12.0.52519.0                Microsoft C Runtime Library
    msvcp140.dll               14.0.24123.0                Microsoft C Runtime Library
    msvcp60.dll                7.0.7600.16385              Windows NT C++ Runtime Library DLL
    msvcr100_clr0400.dll       14.7.2558.0                 Microsoft .NET Framework
    msvcr110_clr0400.dll       14.7.2558.0                 Microsoft .NET Framework
    msvcr120_clr0400.dll       12.0.52519.0                Microsoft C Runtime Library
    msvcrt.dll                 7.0.7601.17744              Windows NT CRT DLL
    msvcrt20.dll               2.12.0.0                    Microsoft C Runtime Library
    msvcrt40.dll               6.1.7600.16385              VC 4.x CRT DLL (Forwarded to msvcrt.dll)
    msvfw32.dll                6.1.7601.17514               Microsoft Video  Windows
    msvidc32.dll               6.1.7601.17514                Microsoft Video 1
    msvidctl.dll               6.5.7601.23569               ActiveX  
    mswdat10.dll               4.0.9801.0                  Microsoft Jet Sort Tables
    mswmdm.dll                 12.0.7600.16385               Windows Media Device Manager
    mswsock.dll                6.1.7601.23451                 API Microsoft Windows Sockets 2.0
    mswstr10.dll               4.0.9801.1                    Microsoft Jet
    msxactps.dll               6.1.7600.16385              OLE DB Transaction Proxies/Stubs
    msxbde40.dll               4.0.9801.0                  Microsoft Jet xBASE Isam
    msxml3.dll                 8.110.7601.23648            MSXML 3.0 SP11
    msxml3r.dll                8.110.7601.23648            XML Resources
    msxml6.dll                 6.30.7601.24000             MSXML 6.0 SP3
    msxml6r.dll                6.30.7601.24000             XML Resources
    msyuv.dll                  6.1.7601.17514              Microsoft UYVY Video Decompressor
    mtxclu.dll                 2001.12.8531.17514          Microsoft Distributed Transaction Coordinator Failover Clustering Support DLL
    mtxdm.dll                  2001.12.8530.16385          COM+
    mtxex.dll                  2001.12.8530.16385          COM+
    mtxlegih.dll               2001.12.8530.16385          COM+
    mtxoci.dll                 2001.12.8531.23391          Microsoft Distributed Transaction Coordinator Database Support DLL for Oracle
    muifontsetup.dll           6.1.7601.17514              MUI Callback for font registry settings
    mycomput.dll               6.1.7600.16385               
    mydocs.dll                 6.1.7601.17514                 " "
    napcrypt.dll               6.1.7601.17514              NAP Cryptographic API helper
    napdsnap.dll               6.1.7601.17514               GPEdit    
    naphlpr.dll                6.1.7601.17514              NAP client config API helper
    napinsp.dll                6.1.7600.16385                    
    napipsec.dll               6.1.7600.16385                      IPSec
    napmontr.dll               6.1.7600.16385                NAP  Netsh
    nativehooks.dll            6.1.7600.16385              Microsoft Narrator Native hook handler
    naturallanguage6.dll       6.1.7601.17514              Natural Language Development Platform 6
    ncdprop.dll                6.1.7600.16385                 
    nci.dll                    6.1.7601.17514              CoInstaller: NET
    ncobjapi.dll               6.1.7600.16385              Microsoft Windows Operating System
    ncrypt.dll                 6.1.7601.24024                (Windows)
    ncryptui.dll               6.1.7601.17514               UI     Windows
    ncsi.dll                   6.1.7601.24000                 
    nddeapi.dll                6.1.7600.16385              Network DDE Share Management APIs
    ndfapi.dll                 6.1.7600.16385              API    
    ndfetw.dll                 6.1.7600.16385              Network Diagnostic Engine Event Interface
    ndfhcdiscovery.dll         6.1.7600.16385              Network Diagnostic Framework HC Discovery API
    ndiscapcfg.dll             6.1.7600.16385              NdisCap Notify Object
    ndishc.dll                 6.1.7600.16385                NDIS
    ndproxystub.dll            6.1.7600.16385              Network Diagnostic Engine Proxy/Stub
    negoexts.dll               6.1.7600.16385              NegoExtender Security Package
    netapi32.dll               6.1.7601.17887              Net Win32 API DLL
    netbios.dll                6.1.7600.16385              NetBIOS Interface Library
    netcenter.dll              6.1.7601.17514                 -  
    netcfgx.dll                6.1.7601.17514                
    netcorehc.dll              6.1.7601.17964                   
    netdiagfx.dll              6.1.7601.17514                
    netevent.dll               6.1.7601.17964                
    netfxperf.dll              4.0.40305.0                 Extensible Performance Counter Shim
    neth.dll                   6.1.7600.16385                 
    netid.dll                  6.1.7601.17514                  
    netiohlp.dll               6.1.7601.17514               DLL   Netio
    netjoin.dll                6.1.7601.17514              Domain Join DLL
    netlogon.dll               6.1.7601.17514                 Net Logon
    netmsg.dll                 6.1.7600.16385                
    netplwiz.dll               6.1.7601.17514                   
    netprof.dll                6.1.7600.16385                 
    netprofm.dll               6.1.7600.16385                
    netshell.dll               6.1.7601.17514                
    netutils.dll               6.1.7601.17514              Net Win32 API Helpers DLL
    networkexplorer.dll        6.1.7601.17514               
    networkitemfactory.dll     6.1.7600.16385                
    networkmap.dll             6.1.7601.17514               
    newdev.dll                 6.0.5054.0                    
    nlaapi.dll                 6.1.7601.24000              Network Location Awareness 2
    nlhtml.dll                 2008.0.7600.16385            HTML
    nlmgp.dll                  6.1.7600.16385                 
    nlmsprep.dll               6.1.7600.16385              Network List Manager Sysprep Module
    nlsbres.dll                6.1.7601.23572              NLSBuild resource DLL
    nlsdata0000.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0001.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0002.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0003.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0007.dll            6.1.7600.16385              Microsoft German Natural Language Server Data and Code
    nlsdata0009.dll            6.1.7600.16385              Microsoft English Natural Language Server Data and Code
    nlsdata000a.dll            6.1.7600.16385              Microsoft Spanish Natural Language Server Data and Code
    nlsdata000c.dll            6.1.7600.16385              Microsoft French Natural Language Server Data and Code
    nlsdata000d.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata000f.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0010.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0011.dll            6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    nlsdata0013.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0018.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0019.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001b.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001d.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0020.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0021.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0022.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0024.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0026.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0027.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata002a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0039.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata003e.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0045.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0046.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0047.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0049.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004b.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004c.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004e.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0414.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0416.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0816.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata081a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0c1a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdl.dll                  6.1.7600.16385              Nls Downlevel DLL
    nlslexicons0001.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0002.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0003.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0007.dll        6.1.7600.16385              Microsoft German Natural Language Server Data and Code
    nlslexicons0009.dll        6.1.7600.16385              Microsoft English Natural Language Server Data and Code
    nlslexicons000a.dll        6.1.7600.16385              Microsoft Spanish Natural Language Server Data and Code
    nlslexicons000c.dll        6.1.7600.16385              Microsoft French Natural Language Server Data and Code
    nlslexicons000d.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons000f.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0010.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0011.dll        6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    nlslexicons0013.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0018.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0019.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001b.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001d.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0020.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0021.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0022.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0024.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0026.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0027.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons002a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0039.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons003e.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0045.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0046.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0047.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0049.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004b.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004c.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004e.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0414.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0416.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0816.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons081a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0c1a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsmodels0011.dll          6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    normaliz.dll               6.1.7600.16385              Unicode Normalization DLL
    npmproxy.dll               6.1.7600.16385              Network List Manager Proxy
    nshhttp.dll                6.1.7600.16385               DLL netsh  HTTP
    nshipsec.dll               6.1.7601.17514               DLL  IPSec  Net
    nshwfp.dll                 6.1.7601.24000                  Windows  Netsh
    nsi.dll                    6.1.7601.23889              NSI User-mode interface DLL
    ntdll.dll                  6.1.7601.24024                NT
    ntdsapi.dll                6.1.7600.16385              Active Directory Domain Services API
    ntlanman.dll               6.1.7601.17514              Microsoft LAN Manager
    ntlanui2.dll               6.1.7600.16385                  
    ntmarta.dll                6.1.7600.16385               Windows NT MARTA
    ntprint.dll                6.1.7601.23889                  
    ntshrui.dll                6.1.7601.17755               ,    
    ntvdm64.dll                6.1.7601.24024              16-   NT64
    objsel.dll                 6.1.7601.18409                
    occache.dll                11.0.9600.18921                 
    ocsetapi.dll               6.1.7601.17514              Windows Optional Component Setup API
    odbc32.dll                 6.1.7601.17514              ODBC Driver Manager
    odbc32gt.dll               6.1.7600.16385              ODBC Driver Generic Thunk
    odbcbcp.dll                6.1.7600.16385              BCP for ODBC
    odbcconf.dll               6.1.7601.17514              ODBC Driver Configuration Program
    odbccp32.dll               6.1.7601.17632              ODBC Installer
    odbccr32.dll               6.1.7601.17632              ODBC Cursor Library
    odbccu32.dll               6.1.7601.17632              ODBC Cursor Library
    odbcint.dll                6.1.7600.16385              ODBC Resources
    odbcji32.dll               6.1.7600.16385              Microsoft ODBC Desktop Driver Pack 3.5
    odbcjt32.dll               6.1.7601.17632              Microsoft ODBC Desktop Driver Pack 3.5
    odbctrac.dll               6.1.7601.17632              ODBC Driver Manager Trace
    oddbse32.dll               6.1.7600.16385              ODBC (3.0) driver for DBase
    odexl32.dll                6.1.7600.16385              ODBC (3.0) driver for Excel
    odfox32.dll                6.1.7600.16385              ODBC (3.0) driver for FoxPro
    odpdx32.dll                6.1.7600.16385              ODBC (3.0) driver for Paradox
    odtext32.dll               6.1.7600.16385              ODBC (3.0) driver for text files
    offfilt.dll                2008.0.7600.16385            OFFICE
    ogldrv.dll                 6.1.7600.16385              MSOGL
    ole2.dll                   2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    ole2disp.dll               2.10.3050.1                 OLE 2.1 16/32 Interoperability Library
    ole2nls.dll                2.10.3050.1                 OLE 2.1 16/32 Interoperability Library
    ole32.dll                  6.1.7601.24000              Microsoft OLE   Windows
    oleacc.dll                 7.0.0.0                     Active Accessibility Core Component
    oleacchooks.dll            7.0.0.0                     Active Accessibility Event Hooks Library
    oleaccrc.dll               7.0.0.0                     Active Accessibility Resource DLL
    oleaut32.dll               6.1.7601.23775              
    olecli32.dll               6.1.7600.16385                OLE
    oledb32.dll                6.1.7601.17514              OLE DB Core Services
    oledb32r.dll               6.1.7600.16385                 OLE DB
    oledlg.dll                 6.1.7600.16385                 OLE
    oleprn.dll                 6.1.7600.16385              Oleprn DLL
    olepro32.dll               6.1.7601.23452              
    oleres.dll                 6.1.7601.24000                OLE
    olesvr32.dll               6.1.7600.16385              Object Linking and Embedding Server Library
    olethk32.dll               6.1.7601.17514              Microsoft OLE for Windows
    onex.dll                   6.1.7601.17514                IEEE 802.1X
    onexui.dll                 6.1.7601.17514                 IEEE 802.1X
    onlineidcpl.dll            6.1.7601.17514                -  
    oobefldr.dll               6.1.7601.17514                
    opcservices.dll            6.1.7601.17514              Native Code OPC Services Library
    openal32.dll               6.14.357.23                 Standard OpenAL(TM) Implementation
    opencl.dll                 24.20.11001.5003            OpenCL Client DLL
    opengl32.dll               6.1.7600.16385              OpenGL Client DLL
    osbaseln.dll               6.1.7600.16385              Service Reporting API
    osuninst.dll               6.1.7600.16385              Uninstall Interface
    p2p.dll                    6.1.7601.24000                
    p2pcollab.dll              6.1.7600.16385                  
    p2pgraph.dll               6.1.7600.16385              Peer-to-Peer Graphing
    p2pnetsh.dll               6.1.7600.16385                 NetSh
    packager.dll               6.1.7601.18645               2
    panmap.dll                 6.1.7600.16385              PANOSE(tm) Font Mapper
    pautoenr.dll               6.1.7600.16385                
    pcaui.dll                  6.1.7600.16385                  
    pcwum.dll                  6.1.7600.16385              Performance Counters for Windows Native DLL
    pdh.dll                    6.1.7601.23717                  Windows
    pdhui.dll                  6.1.7601.23841                
    peerdist.dll               6.1.7601.24000                BranchCache
    peerdistsh.dll             6.1.7600.16385                BranchCache Netshell
    perfcentercpl.dll          6.1.7601.17514               
    perfctrs.dll               6.1.7600.16385               
    perfdisk.dll               6.1.7600.16385                  Windows
    perfnet.dll                6.1.7600.16385                   Windows
    perfos.dll                 6.1.7600.16385                  Windows
    perfproc.dll               6.1.7600.16385                   Windows
    perfts.dll                 6.1.7601.17514              Windows Remote Desktop Services Performance Objects
    photometadatahandler.dll   6.1.7600.16385              Photo Metadata Handler
    photowiz.dll               6.1.7601.17514                
    pid.dll                    6.1.7600.16385              Microsoft PID
    pidgenx.dll                6.1.7600.16385              Pid Generation
    pifmgr.dll                 6.1.7601.17514              Windows NT PIF Manager Icon Resources Library
    pku2u.dll                  6.1.7601.18658              Pku2u Security Package
    pla.dll                    6.1.7601.23717                 
    playsndsrv.dll             6.1.7600.16385               PlaySound
    pmcsnap.dll                6.1.7600.16385              pmcsnap dll
    pngfilt.dll                11.0.9600.16428             IE PNG plugin image decoder
    pnidui.dll                 6.1.7601.17514                
    pnpsetup.dll               6.1.7600.16385              Pnp installer for CMI
    pnrpnsp.dll                6.1.7600.16385                 PNRP
    polstore.dll               6.1.7601.23452              Policy Storage dll
    portabledeviceapi.dll      6.1.7601.17514               API    Windows
    portabledeviceclassextension.dll  6.1.7600.16385              Windows Portable Device Class Extension Component
    portabledeviceconnectapi.dll  6.1.7600.16385              Portable Device Connection API Components
    portabledevicestatus.dll   6.1.7601.17514                  Microsoft Windows
    portabledevicesyncprovider.dll  6.1.7601.17514                 Microsoft Windows
    portabledevicetypes.dll    6.1.7600.16385              Windows Portable Device (Parameter) Types Component
    portabledevicewiacompat.dll  6.1.7600.16385              PortableDevice WIA Compatibility Driver
    portabledevicewmdrm.dll    6.1.7600.16385              Windows Portable Device WMDRM Component
    pots.dll                   6.1.7600.16385               
    powercpl.dll               6.1.7601.17514                
    powrprof.dll               6.1.7600.16385              DLL     
    ppcsnap.dll                6.1.7600.16385              ppcsnap DLL
    presentationcffrasterizernative_v0300.dll  3.0.6920.5469               WinFX OpenType/CFF Rasterizer
    presentationhostproxy.dll  4.0.40305.0                 Windows Presentation Foundation Host Proxy
    presentationnative_v0300.dll  3.0.6920.4902               PresentationNative_v0300.dll
    prflbmsg.dll               6.1.7600.16385                  
    printui.dll                6.1.7601.17514                 
    prncache.dll               6.1.7601.17514              Print UI Cache
    prnfldr.dll                6.1.7601.17514              prnfldr dll
    prnntfy.dll                6.1.7600.16385              prnntfy DLL
    prntvpt.dll                6.1.7601.17514              Print Ticket Services Module
    profapi.dll                6.1.7600.16385              User Profile Basic API
    propsys.dll                7.0.7601.17514                 (Microsoft)
    provsvc.dll                6.1.7601.17514                Windows
    provthrd.dll               6.1.7600.16385              WMI Provider Thread & Log Library
    psapi.dll                  6.1.7600.16385              Process Status Helper
    psbase.dll                 6.1.7600.16385                
    pshed.dll                  6.1.7600.16385                ,   
    psisdecd.dll               6.6.7601.17669              Microsoft SI/PSI parser for MPEG2 based networks.
    pstorec.dll                6.1.7600.16385              Protected Storage COM interfaces
    pstorsvc.dll               6.1.7600.16385              Protected storage server
    puiapi.dll                 6.1.7600.16385               DLL puiapi
    puiobj.dll                 6.1.7601.17514               DLL  PrintUI
    pwrshplugin.dll            6.1.7600.16385              pwrshplugin.dll
    qagent.dll                 6.1.7601.17514                
    qasf.dll                   12.0.7601.19091             DirectShow ASF Support
    qcap.dll                   6.6.7601.17514                DirecxX DirectShow.
    qcliprov.dll               6.1.7601.17514               WMI   
    qdv.dll                    6.6.7601.17514                DirecxX DirectShow.
    qdvd.dll                   6.6.7601.23471              DirectShow DVD PlayBack Runtime.
    qedit.dll                  6.6.7601.19091               DirectShow
    qedwipes.dll               6.6.7600.16385              DirectShow Editing SMPTE Wipes
    qmgrprxy.dll               7.5.7600.16385              Background Intelligent Transfer Service Proxy
    qshvhost.dll               6.1.7601.17514                SHV
    qsvrmgmt.dll               6.1.7601.17514                
    quartz.dll                 6.6.7601.23709                DirecxX DirectShow.
    query.dll                  6.1.7601.23930                  
    qutil.dll                  6.1.7601.17514                
    qwave.dll                  6.1.7600.16385              Windows NT
    racengn.dll                6.1.7601.17514                  
    racpldlg.dll               6.1.7600.16385                 
    radardt.dll                6.1.7600.16385                   Windows
    radarrs.dll                6.1.7600.16385                   Microsoft Windows
    rapidfire.dll              1.2.0.15                    AMD RapidFire
    rapidfireserver.dll        1.2.0.15                    AMD Rapid Fire Server
    rasadhlp.dll               6.1.7600.16385              Remote Access AutoDial Helper
    rasapi32.dll               6.1.7600.16385              Remote Access API
    rascfg.dll                 6.1.7601.24000                RAS
    raschap.dll                6.1.7601.17514                 PPP CHAP
    rasctrs.dll                6.1.7600.16385                     Windows NT
    rasdiag.dll                6.1.7601.24000                  RAS
    rasdlg.dll                 6.1.7600.16385              API     
    rasgcw.dll                 6.1.7600.16385                RAS
    rasman.dll                 6.1.7600.16385              Remote Access Connection Manager
    rasmm.dll                  6.1.7600.16385                RAS
    rasmontr.dll               6.1.7600.16385                RAS
    rasmxs.dll                 6.1.7601.24000              Remote Access Device DLL for modems, PADs and switches
    rasplap.dll                6.1.7600.16385                 RAS PLAP
    rasppp.dll                 6.1.7601.17514              Remote Access PPP
    rasser.dll                 6.1.7601.24000              Remote Access Media DLL for COM ports
    rastapi.dll                6.1.7601.17514              Remote Access TAPI Compliance Layer
    rastls.dll                 6.1.7601.18584                 PPP EAP-TLS
    rdpcore.dll                6.1.7601.23892              RDP Core DLL
    rdpd3d.dll                 6.1.7601.17514              RDP Direct3D Remoting DLL
    rdpencom.dll               6.1.7601.17514              RDPSRAPI COM Objects
    rdpendp.dll                6.1.7601.17514                 RDP
    rdpendp_winip.dll          6.2.9200.16398              RDP Audio Endpoint
    rdprefdrvapi.dll           6.1.7601.17514              Reflector Driver API
    rdvgumd32.dll              6.1.7601.17514                 ()
    rdvidcrl.dll               6.3.9600.16415              Remote Desktop Services Client for Microsoft Online Services
    reagent.dll                6.1.7601.17514               DLL   Microsoft Windows
    regapi.dll                 6.1.7601.17514              Registry Configuration APIs
    regctrl.dll                6.1.7600.16385              RegCtrl
    remotepg.dll               6.1.7601.17514              CPL-  
    resampledmo.dll            6.1.7601.19091              Windows Media Resampler
    resutils.dll               6.1.7601.17514              Microsoft Cluster Resource Utility DLL
    rgb9rast.dll               6.1.7600.16385              Microsoft Windows Operating System
    riched20.dll               5.31.23.1230                Rich Text Edit Control, v3.1
    riched32.dll               6.1.7601.17514              Wrapper Dll for Richedit 1.0
    rnr20.dll                  6.1.7600.16385              Windows Socket2 NameSpace DLL
    rpcdiag.dll                6.1.7600.16385              RPC Diagnostics
    rpchttp.dll                6.1.7601.24024              RPC HTTP DLL
    rpcndfp.dll                1.0.0.1                        RPC NDF
    rpcns4.dll                 6.1.7600.16385                    (RPC)
    rpcnsh.dll                 6.1.7600.16385                RPC Netshell
    rpcrt4.dll                 6.1.7601.24024                 
    rpcrtremote.dll            6.1.7601.17514              Remote RPC Extension
    rsaenh.dll                 6.1.7600.16385              Microsoft Enhanced Cryptographic Provider
    rshx32.dll                 6.1.7600.16385                
    rstrtmgr.dll               6.1.7600.16385               
    rtffilt.dll                2008.0.7600.16385            RTF
    rtm.dll                    6.1.7601.23947                
    rtutils.dll                6.1.7601.17514              Routing Utilities
    samcli.dll                 6.1.7601.17514              Security Accounts Manager Client DLL
    samlib.dll                 6.1.7601.23677              SAM Library DLL
    sampleres.dll              6.1.7600.16385               (Microsoft)
    sas.dll                    6.1.7600.16385              WinLogon Software SAS Library
    sbe.dll                    6.6.7601.17528              DirectShow Stream Buffer Filter.
    sbeio.dll                  12.0.7600.16385             Stream Buffer IO DLL
    sberes.dll                 6.6.7600.16385                  DirectShow.
    scansetting.dll            6.1.7601.17514                    Microsoft Windows(TM)
    scarddlg.dll               6.1.7600.16385              SCardDlg -   -
    scecli.dll                 6.1.7601.17514                 
    scesrv.dll                 6.1.7601.18686                
    schannel.dll               6.1.7601.24024              TLS / SSL Security Provider
    schedcli.dll               6.1.7601.17514              Scheduler Service Client DLL
    scksp.dll                  6.1.7600.16385              Microsoft Smart Card Key Storage Provider
    scripto.dll                6.6.7600.16385              Microsoft ScriptO
    scrobj.dll                 5.8.7600.16385              Windows  Script Component Runtime
    scrptadm.dll               6.1.7601.17514                
    scrrun.dll                 5.8.7601.18283              Microsoft  Script Runtime
    sdiageng.dll               6.1.7600.16385                 
    sdiagprv.dll               6.1.7600.16385              API    Windows
    sdohlp.dll                 6.1.7600.16385                 SDO NPS
    searchfolder.dll           6.1.7601.17514              SearchFolder
    sechost.dll                6.1.7601.18869              Host for SCM/SDDL/LSA Lookup APIs
    secproc.dll                6.1.7601.18332              Windows Rights Management Desktop Security Processor
    secproc_isv.dll            6.1.7601.18332              Windows Rights Management Desktop Security Processor
    secproc_ssp.dll            6.1.7601.18332              Windows Rights Management Services Server Security Processor
    secproc_ssp_isv.dll        6.1.7601.18332              Windows Rights Management Services Server Security Processor (Pre-production)
    secur32.dll                6.1.7601.24024              Security Support Provider Interface
    security.dll               6.1.7600.16385              Security Support Provider Interface
    sendmail.dll               6.1.7600.16385               
    sens.dll                   6.1.7600.16385                   (SENS)
    sensapi.dll                6.1.7600.16385              SENS Connectivity API DLL
    sensorsapi.dll             6.1.7600.16385              Sensor API
    sensorscpl.dll             6.1.7601.17514                "    "
    serialui.dll               6.1.7600.16385                
    serwvdrv.dll               6.1.7600.16385                Unimodem
    sessenv.dll                6.1.7601.17514                   
    setupapi.dll               6.1.7601.17514              Windows Setup API
    setupcln.dll               6.1.7601.17514                
    sfc.dll                    6.1.7600.16385              Windows File Protection
    sfc_os.dll                 6.1.7600.16385              Windows File Protection
    shacct.dll                 6.1.7601.17514              Shell Accounts Classes
    shdocvw.dll                6.1.7601.23896                    
    shell32.dll                6.1.7601.24000                 Windows
    shellstyle.dll             6.1.7600.16385              Windows Shell Style Resource Dll
    shfolder.dll               6.1.7600.16385              Shell Folder Service
    shgina.dll                 6.1.7601.17514              Windows Shell User Logon
    shimeng.dll                6.1.7601.19050              Shim Engine DLL
    shimgvw.dll                6.1.7601.17514               
    shlwapi.dll                6.1.7601.17514                 
    shpafact.dll               6.1.7600.16385              Windows Shell LUA/PA Elevation Factory Dll
    shsetup.dll                6.1.7601.17514              Shell setup helper
    shsvcs.dll                 6.1.7601.17514               DLL   Windows
    shunimpl.dll               6.1.7601.17514              Windows Shell Obsolete APIs
    shwebsvc.dll               6.1.7601.17514              -  Windows
    signdrv.dll                6.1.7600.16385              WMI provider for Signed Drivers
    sisbkup.dll                6.1.7601.17514              Single-Instance Store Backup Support Functions
    slc.dll                    6.1.7600.16385              Software Licensing Client DLL
    slcext.dll                 6.1.7600.16385              Software Licensing Client Extension Dll
    slwga.dll                  6.1.7601.17514              Software Licensing WGA API
    smartcardcredentialprovider.dll  6.1.7601.18276                 - Windows
    smbhelperclass.dll         1.0.0.1                        SMB (   )    
    sndvolsso.dll              6.1.7601.17514               SCA 
    snmpapi.dll                6.1.7600.16385              SNMP Utility Library
    softkbd.dll                6.1.7600.16385                  
    softpub.dll                6.1.7600.16385              Softpub Forwarder DLL
    sortserver2003compat.dll   6.1.7600.16385              Sort Version Server 2003
    sortwindows6compat.dll     6.1.7600.16385              Sort Version Windows 6.0
    spbcd.dll                  6.1.7601.17514              BCD Sysprep Plugin
    spfileq.dll                6.1.7600.16385              Windows SPFILEQ
    spinf.dll                  6.1.7600.16385              Windows SPINF
    spnet.dll                  6.1.7600.16385              Net Sysprep Plugin
    spopk.dll                  6.1.7601.17514              OPK Sysprep Plugin
    spp.dll                    6.1.7601.17514                  Microsoft Windows
    sppc.dll                   6.1.7601.17514              Software Licensing Client DLL
    sppcc.dll                  6.1.7600.16385                  
    sppcext.dll                6.1.7600.16385              Software Protection Platform Client Extension Dll
    sppcomapi.dll              6.1.7601.17514                 
    sppcommdlg.dll             6.1.7600.16385              API     
    sppinst.dll                6.1.7601.17514              SPP CMI Installer Plug-in DLL
    sppwmi.dll                 6.1.7600.16385              Software Protection Platform WMI provider
    spwinsat.dll               6.1.7600.16385              WinSAT Sysprep Plugin
    spwizeng.dll               6.1.7601.17514              Setup Wizard Framework
    spwizimg.dll               6.1.7600.16385              Setup Wizard Framework Resources
    spwizres.dll               6.1.7601.17514                 
    spwmp.dll                  6.1.7601.23930              Windows Media Player System Preparation DLL
    sqlceoledb30.dll           3.0.7600.0                  Microsoft SQL Mobile
    sqlceqp30.dll              3.0.7600.0                  Microsoft SQL Mobile
    sqlcese30.dll              3.0.7601.0                  Microsoft SQL Mobile
    sqloledb.dll               6.1.7601.17514              OLE DB Provider for SQL Server
    sqlsrv32.dll               6.1.7601.17514              SQL Server ODBC Driver
    sqlunirl.dll               2000.80.728.0               String Function .DLL for SQL Enterprise Components
    sqlwid.dll                 1999.10.20.0                Unicode Function .DLL for SQL Enterprise Components
    sqlwoa.dll                 1999.10.20.0                Unicode/ANSI Function .DLL for SQL Enterprise Components
    sqlxmlx.dll                6.1.7600.16385              XML extensions for SQL Server
    sqmapi.dll                 6.1.7601.17514              SQM Client
    srchadmin.dll              7.0.7601.17514               
    srclient.dll               6.1.7601.24024              Microsoft Windows System Restore Client Library
    srhelper.dll               6.1.7600.16385              Microsoft Windows driver and windows update enumeration library
    srpuxnativesnapin.dll      6.1.7600.16385                     
    srvcli.dll                 6.1.7601.17514              Server Service Client DLL
    sscore.dll                 6.1.7601.17514               DLL-  
    ssdpapi.dll                6.1.7600.16385              SSDP Client API DLL
    sspicli.dll                6.1.7601.24024              Security Support Provider Interface
    ssshim.dll                 6.1.7600.16385              Windows Componentization Platform Servicing API
    stclient.dll               2001.12.8530.16385          COM+ Configuration Catalog Client
    sti.dll                    6.1.7600.16385                   
    stobject.dll               6.1.7601.17514                 Systray
    storage.dll                2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    storagecontexthandler.dll  6.1.7600.16385                   
    storprop.dll               6.1.7600.16385                  
    structuredquery.dll        7.0.7601.24024              Structured Query
    sud.dll                    6.1.7601.17514                SUD
    sxproxy.dll                6.1.7600.16385                  Microsoft Windows
    sxs.dll                    6.1.7601.17514              Fusion 2.5
    sxshared.dll               6.1.7600.16385              Microsoft Windows SX Shared Library
    sxsstore.dll               6.1.7600.16385              Sxs Store DLL
    synccenter.dll             6.1.7601.17514                
    synceng.dll                6.1.7601.17959              Windows Briefcase Engine
    synchostps.dll             6.1.7600.16385              Proxystub for sync host
    syncinfrastructure.dll     6.1.7600.16385                Microsoft Windows.
    syncinfrastructureps.dll   6.1.7600.16385              Microsoft Windows sync infrastructure proxy stub.
    syncreg.dll                2007.94.7600.16385          Microsoft Synchronization Framework Registration
    syncui.dll                 6.1.7601.17514               Windows
    syssetup.dll               6.1.7601.17514              Windows NT System Setup
    systemcpl.dll              6.1.7601.17514              CPL 
    t2embed.dll                6.1.7601.24007              Microsoft T2Embed Font Embedding
    tapi3.dll                  6.1.7600.16385              Microsoft TAPI3
    tapi32.dll                 6.1.7600.16385               API  Microsoft Windows
    tapimigplugin.dll          6.1.7600.16385              Microsoft Windows(TM) TAPI Migration Plugin Dll
    tapiperf.dll               6.1.7600.16385              Microsoft Windows(TM) Telephony Performance Monitor
    tapisrv.dll                6.1.7601.17514                 Microsoft Windows
    tapisysprep.dll            6.1.7600.16385              Microsoft Windows(TM) Telephony Sysprep Work
    tapiui.dll                 6.1.7600.16385               DLL   Microsoft Windows
    taskcomp.dll               6.1.7601.24000                  
    taskschd.dll               6.1.7601.17514              Task Scheduler COM API
    taskschdps.dll             6.1.7600.16385              Task Scheduler Interfaces Proxy
    tbs.dll                    6.1.7601.19146              TBS
    tcpipcfg.dll               6.1.7601.17514                
    tcpmonui.dll               6.1.7600.16385                  TCP/IP
    tdh.dll                    6.1.7601.18939                 
    termmgr.dll                6.1.7601.17514              Microsoft TAPI3 Terminal Manager
    thawbrkr.dll               6.1.7600.16385              Thai Word Breaker
    themecpl.dll               6.1.7601.17514              CPL 
    themeui.dll                6.1.7601.23913              API   Windows
    thumbcache.dll             6.1.7601.17514                
    timedatemuicallback.dll    6.1.7600.16385              Time Date Control UI Language Change plugin
    tlscsp.dll                 6.1.7601.17514              Microsoft Remote Desktop Services Cryptographic Utility
    tpmcompc.dll               6.1.7600.16385                
    tquery.dll                 7.0.7601.23930              tquery.dll
    traffic.dll                6.1.7601.24000              Microsoft Traffic Control 1.0 DLL
    trapi.dll                  6.1.7601.17514              Microsoft Narrator Text Renderer
    tsbyuv.dll                 6.1.7601.17514              Toshiba Video Codec
    tschannel.dll              6.1.7600.16385              Task Scheduler Proxy
    tsgqec.dll                 6.3.9600.16415                      
    tsmf.dll                   6.1.7601.17514                MF    
    tspkg.dll                  6.1.7601.24024              Web Service Security Package
    tsworkspace.dll            6.1.7601.18546                      RemoteApp
    tvratings.dll              6.6.7600.16385              Module for managing TV ratings
    twext.dll                  6.1.7601.17514              :  
    txflog.dll                 2001.12.8530.16385          COM+
    txfw32.dll                 6.1.7600.16385              TxF Win32 DLL
    typelib.dll                2.10.3029.1                 OLE 2.1 16/32 Interoperability Library
    tzres.dll                  6.1.7601.23949               DLL   
    ubpm.dll                   6.1.7601.18741               DLL    
    ucmhc.dll                  6.1.7600.16385                 UCM
    ucrtbase.dll               10.0.10586.1171             Microsoft C Runtime Library
    udhisapi.dll               6.1.7600.16385              UPnP Device Host ISAPI Extension
    uexfat.dll                 6.1.7600.16385              eXfat Utility DLL
    ufat.dll                   6.1.7600.16385              FAT Utility DLL
    uianimation.dll            6.2.9200.22005              Windows Animation Manager
    uiautomationcore.dll       7.0.0.0                        Microsoft UI
    uicom.dll                  6.1.7600.16385              Add/Remove Modems
    uiribbon.dll               6.1.7601.17514                Windows
    uiribbonres.dll            6.1.7601.17514              Windows Ribbon Framework Resources
    ulib.dll                   6.1.7600.16385              DLL   
    umdmxfrm.dll               6.1.7600.16385              Unimodem Tranform Module
    unimdmat.dll               6.1.7601.17514              - AT   Unimodem
    uniplat.dll                6.1.7600.16385              Unimodem AT Mini Driver Platform Driver for Windows NT
    untfs.dll                  6.1.7601.17514              NTFS Utility DLL
    upnp.dll                   6.1.7601.17514              API   UPnP
    upnphost.dll               6.1.7600.16385                PNP-
    ureg.dll                   6.1.7600.16385              Registry Utility DLL
    url.dll                    11.0.9600.16428             Internet Shortcut Shell Extension DLL
    urlmon.dll                 11.0.9600.18921              OLE32  Win32
    usbceip.dll                6.1.7600.16385               USBCEIP
    usbperf.dll                6.1.7600.16385               DLL   USB
    usbui.dll                  6.1.7600.16385              USB UI Dll
    user32.dll                 6.1.7601.23594                 USER API Windows
    useraccountcontrolsettings.dll  6.1.7601.17514                  
    usercpl.dll                6.1.7601.17514                
    userenv.dll                6.1.7601.17514              Userenv
    usp10.dll                  1.626.7601.23894            Uniscribe Unicode script processor
    utildll.dll                6.1.7601.17514                WinStation
    uudf.dll                   6.1.7600.16385              UDF Utility DLL
    uxinit.dll                 6.1.7600.16385              Windows User Experience Session Initialization Dll
    uxlib.dll                  6.1.7601.17514              Setup Wizard Framework
    uxlibres.dll               6.1.7600.16385              UXLib Resources
    uxtheme.dll                6.1.7600.16385                UxTheme (Microsoft)
    van.dll                    6.1.7601.17514                
    vault.dll                  6.1.7601.17514                -  Windows
    vaultcli.dll               6.1.7600.16385              Credential Vault Client Library
    vbajet32.dll               6.0.1.9431                  Visual Basic for Applications Development Environment - Expression Service Loader
    vbscript.dll               5.8.9600.18921              Microsoft  VBScript
    vcamp140.dll               14.0.24123.0                Microsoft C++ AMP Runtime
    vccorlib140.dll            14.0.24123.0                Microsoft  VC WinRT core library
    vcomp140.dll               14.0.24123.0                Microsoft C/C++ OpenMP Runtime
    vcruntime140.dll           14.0.24123.0                Microsoft C Runtime Library
    vdmdbg.dll                 6.1.7600.16385              VDMDBG.DLL
    vds_ps.dll                 6.1.7600.16385              Microsoft Virtual Disk Service proxy/stub
    vdsbas.dll                 6.1.7601.17514                  
    vdsdyn.dll                 6.1.7600.16385                  VDS,  2.1.0.1
    vdsvd.dll                  6.1.7600.16385              VDS Virtual Disk Provider, Version 1.0
    verifier.dll               6.1.7600.16385              Standard application verifier provider dll
    version.dll                6.1.7600.16385              Version Checking and File Installation Libraries
    vfpodbc.dll                1.0.2.0                     vfpodbc
    vfwwdm32.dll               6.1.7601.17514               VfW MM Driver    WDM-
    vidreszr.dll               6.1.7601.19091              Windows Media Resizer
    virtdisk.dll               6.1.7600.16385              Virtual Disk API DLL
    vmixp8.dll                 1.0.0.21                    Vmix Dynamic Link Library
    vpnikeapi.dll              6.1.7601.17514              VPN IKE API's
    vss_ps.dll                 6.1.7600.16385              Microsoft Volume Shadow Copy Service proxy/stub
    vssapi.dll                 6.1.7601.17514              Microsoft Volume Shadow Copy Requestor/Writer Services API DLL
    vsstrace.dll               6.1.7600.16385                    Microsoft
    vulkan-1.dll               1.1.70.0                    Vulkan Loader
    vulkan-1-1-0-65-0.dll      1.0.65.0                    Vulkan Loader
    vulkan-1-1-1-70-0.dll      1.1.70.0                    Vulkan Loader
    w32topl.dll                6.1.7600.16385              Windows NT Topology Maintenance Tool
    wab32.dll                  6.1.7601.17699              Microsoft (R) Contacts DLL
    wab32res.dll               6.1.7600.16385               Microsoft (R) DLL
    wabsyncprovider.dll        6.1.7600.16385                 Microsoft Windows
    wavemsp.dll                6.1.7601.17514              Microsoft Wave MSP
    wbemcomn.dll               6.1.7601.17514              WMI
    wcnapi.dll                 6.1.7601.24000              Windows Connect Now - API Helper DLL
    wcncsvc.dll                6.1.7601.24000                Windows -   
    wcneapauthproxy.dll        6.1.7601.24000              Windows Connect Now - WCN EAP Authenticator Proxy
    wcneappeerproxy.dll        6.1.7601.24000              Windows Connect Now - WCN EAP PEER Proxy
    wcnwiz.dll                 6.1.7600.16385                Windows Connect Now
    wcspluginservice.dll       6.1.7601.23971               DLL WcsPlugInService
    wdc.dll                    6.1.7601.23841               
    wdi.dll                    6.1.7601.18713                Windows
    wdigest.dll                6.1.7601.24024              Microsoft Digest Access
    wdscore.dll                6.1.7601.17514              Panther Engine Module
    webcheck.dll               11.0.9600.18921              -
    webclnt.dll                6.1.7601.23542               DLL - DAV
    webio.dll                  6.1.7601.23375              API    
    webservices.dll            6.1.7601.17514                - Windows
    wecapi.dll                 6.1.7600.16385              Event Collector Configuration API
    wer.dll                    6.1.7601.23877                  Windows
    werdiagcontroller.dll      6.1.7601.23877              WER Diagnostic Controller
    werui.dll                  6.1.7600.16385               DLL      Windows
    wevtapi.dll                6.1.7600.16385              API    
    wevtfwd.dll                6.1.7600.16385              WS-Management Event Forwarding Plug-in
    wfapigp.dll                6.1.7601.24000              Windows Firewall GPO Helper dll
    wfhc.dll                   6.1.7600.16385               Windows.   
    whealogr.dll               6.1.7600.16385                WHEA
    whhelper.dll               6.1.7600.16385              DLL     winHttp
    wiaaut.dll                 6.1.7600.16385               WIA-
    wiadefui.dll               6.1.7601.17514                  WIA
    wiadss.dll                 6.1.7600.16385               WIA -  TWAIN
    wiaextensionhost64.dll     6.1.7600.16385              WIA Extension Host for thunking APIs from 32-bit to 64-bit process
    wiascanprofiles.dll        6.1.7600.16385              Microsoft Windows ScanProfiles
    wiashext.dll               6.1.7600.16385                     
    wiatrace.dll               6.1.7600.16385              WIA Tracing
    wiavideo.dll               6.1.7601.17514              WIA Video
    wimgapi.dll                6.1.7601.17514               Windows Imaging
    win32spl.dll               6.1.7601.23889                    
    winbio.dll                 6.1.7600.16385              API   Windows
    winbrand.dll               6.1.7600.16385              Windows Branding Resources
    wincredprovider.dll        6.1.7601.18409               DLL wincredprovider
    windowscodecs.dll          6.2.9200.21830              Microsoft Windows Codecs Library
    windowscodecsext.dll       6.2.9200.16492              Microsoft Windows Codecs Extended Library
    winfax.dll                 6.1.7600.16385              Microsoft  Fax API Support DLL
    winhttp.dll                6.1.7601.24000               HTTP Windows
    wininet.dll                11.0.9600.18921                Win32
    winipsec.dll               6.1.7601.23452              Windows IPsec SPD Client DLL
    winmm.dll                  6.1.7601.17514              MCI API DLL
    winnsi.dll                 6.1.7601.23889              Network Store Information RPC interface
    winrnr.dll                 6.1.7600.16385              LDAP RnR Provider DLL
    winrscmd.dll               6.1.7600.16385              remtsvc
    winrsmgr.dll               6.1.7600.16385              WSMan Shell API
    winrssrv.dll               6.1.7600.16385              winrssrv
    winsatapi.dll              6.1.7601.17514              Windows System Assessment Tool API
    winscard.dll               6.1.7601.23971              API - (Microsoft)
    winshfhc.dll               6.1.7600.16385              File Risk Estimation
    winsockhc.dll              6.1.7600.16385                   Winsock
    winsrpc.dll                6.1.7600.16385              WINS RPC LIBRARY
    winsta.dll                 6.1.7601.18540              Winstation Library
    winsync.dll                2007.94.7600.16385          Synchronization Framework
    winsyncmetastore.dll       2007.94.7600.16385          Windows Synchronization Metadata Store
    winsyncproviders.dll       2007.94.7600.16385          Windows Synchronization Provider Framework
    wintrust.dll               6.1.7601.23971              Microsoft Trust Verification APIs
    winusb.dll                 6.1.7600.16385              Windows USB Driver User Library
    wkscli.dll                 6.1.7601.17514              Workstation Service Client DLL
    wksprtps.dll               6.3.9600.16415              WorkspaceRuntime ProxyStub DLL
    wlanapi.dll                6.1.7601.23915              Windows WLAN AutoConfig Client Side API DLL
    wlancfg.dll                6.1.7600.16385               DLL    Netsh  WLAN
    wlanconn.dll               6.1.7600.16385                Dot11
    wlandlg.dll                6.1.7600.16385                   
    wlangpui.dll               6.1.7601.17514               "   "
    wlanhlp.dll                6.1.7601.23915              Windows Wireless LAN 802.11 Client Side Helper API
    wlaninst.dll               6.1.7600.16385              Windows NET Device Class Co-Installer for Wireless LAN
    wlanmm.dll                 6.1.7600.16385                Dot11   
    wlanmsm.dll                6.1.7601.23915              Windows Wireless LAN 802.11 MSM DLL
    wlanpref.dll               6.1.7601.17514                
    wlansec.dll                6.1.7601.23915              Windows Wireless LAN 802.11 MSM Security Module DLL
    wlanui.dll                 6.1.7601.17514                 
    wlanutil.dll               6.1.7600.16385               DLL     Windows   802.11
    wldap32.dll                6.1.7601.23889              Win32 LDAP API DLL
    wlgpclnt.dll               6.1.7600.16385                 802.11
    wls0wndh.dll               6.1.7600.16385              Session0 Viewer Window Hook DLL
    wmadmod.dll                6.1.7601.19091              Windows Media Audio Decoder
    wmadmoe.dll                6.1.7601.19091              Windows Media Audio 10 Encoder/Transcoder
    wmasf.dll                  12.0.7600.16385             Windows Media ASF DLL
    wmcodecdspps.dll           6.1.7600.16385              Windows Media CodecDSP Proxy Stub Dll
    wmdmlog.dll                12.0.7600.16385             Windows Media Device Manager Logger
    wmdmps.dll                 12.0.7600.16385             Windows Media Device Manager Proxy Stub
    wmdrmdev.dll               12.0.7601.17514             Windows Media DRM for Network Devices Registration DLL
    wmdrmnet.dll               12.0.7601.17514             Windows Media DRM for Network Devices DLL
    wmdrmsdk.dll               11.0.7601.23471             Windows Media DRM SDK DLL
    wmerror.dll                12.0.7600.16385               Windows Media ()
    wmi.dll                    6.1.7601.17787              WMI DC and DP functionality
    wmidx.dll                  12.0.7600.16385             Windows Media Indexer DLL
    wmiprop.dll                6.1.7600.16385                  WDM
    wmnetmgr.dll               12.0.7601.17514             Windows Media Network Plugin Manager DLL
    wmp.dll                    12.0.7601.23930             Windows Media Player
    wmpcm.dll                  12.0.7600.16385             Windows Media Player Compositing Mixer
    wmpdui.dll                 12.0.7600.16385             Windows DirectUser Engine
    wmpdxm.dll                 12.0.7601.17514             Windows Media Player Extension
    wmpeffects.dll             12.0.7601.17514             Windows Media Player Effects
    wmpencen.dll               12.0.7601.17514             Windows Media Player Encoding Module
    wmphoto.dll                6.2.9200.17254               Windows Media
    wmploc.dll                 12.0.7601.23930               Windows Media
    wmpmde.dll                 12.0.7601.19091             WMPMDE DLL
    wmpps.dll                  12.0.7601.17514             Windows Media Player Proxy Stub Dll
    wmpshell.dll               12.0.7601.17514                Windows Media
    wmpsrcwp.dll               12.0.7601.17514             WMPSrcWp Module
    wmsgapi.dll                6.1.7600.16385              WinLogon IPC Client
    wmspdmod.dll               6.1.7601.19091              Windows Media Audio Voice Decoder
    wmspdmoe.dll               6.1.7601.19091              Windows Media Audio Voice Encoder
    wmvcore.dll                12.0.7601.17514             Windows Media Playback/Authoring DLL
    wmvdecod.dll               6.1.7601.19091              Windows Media Video Decoder
    wmvdspa.dll                6.1.7600.16385              Windows Media Video DSP Components - Advanced
    wmvencod.dll               6.1.7601.19091              Windows Media Video 9 Encoder
    wmvsdecd.dll               6.1.7601.19091              Windows Media Screen Decoder
    wmvsencd.dll               6.1.7601.19091              Windows Media Screen Encoder
    wmvxencd.dll               6.1.7601.19091              Windows Media Video Encoder
    wow32.dll                  6.1.7601.24024              Wow32
    wpc.dll                    1.0.0.1                        
    wpcao.dll                  6.1.7600.16385                WPC
    wpcsvc.dll                 1.0.0.1                         Windows
    wpdshext.dll               6.1.7601.18738                  
    wpdshserviceobj.dll        6.1.7601.17514              Windows Portable Device Shell Service Object
    wpdsp.dll                  6.1.7601.17514              WMDM Service Provider for Windows Portable Devices
    wpdwcn.dll                 6.1.7601.17514                    WCN
    wrap_oal.dll               2.2.0.0                     OpenAL32
    ws2_32.dll                 6.1.7601.23451              32-  Windows Socket 2.0
    ws2help.dll                6.1.7600.16385              Windows Socket 2.0 Helper for Windows NT
    wscapi.dll                 6.1.7601.17514              Windows Security Center API
    wscinterop.dll             6.1.7600.16385              Windows Health Center WSC Interop
    wscisvif.dll               6.1.7600.16385              Windows Security Center ISV API
    wscmisetup.dll             6.1.7600.16385              Installers for Winsock Transport and Name Space Providers
    wscproxystub.dll           6.1.7600.16385              Windows Security Center ISV Proxy Stub
    wsdapi.dll                 6.1.7601.17514              -   DLL API- 
    wsdchngr.dll               6.1.7601.17514              WSD Challenge Component
    wsecedit.dll               6.1.7600.16385                 
    wshbth.dll                 6.1.7601.17514              Windows Sockets Helper DLL
    wshcon.dll                 5.8.7600.16385              Microsoft  Windows Script Controller
    wshelper.dll               6.1.7600.16385               DLL    Winsock Net
    wshext.dll                 5.8.7600.16385              Microsoft  Shell Extension for Windows Script Host
    wship6.dll                 6.1.7600.16385               DLL  Winsock2 (TL/IPv6)
    wshirda.dll                6.1.7601.17514              Windows Sockets Helper DLL
    wshqos.dll                 6.1.7601.24000               DLL   QoS Winsock2
    wshrm.dll                  6.1.7601.19055                DLL   Windows  PGM
    wshtcpip.dll               6.1.7600.16385               DLL   Winsock2 (TL/IPv4)
    wsmanmigrationplugin.dll   6.1.7601.23512              WinRM Migration Plugin
    wsmauto.dll                6.1.7601.23512              WSMAN Automation
    wsmplpxy.dll               6.1.7601.23512              wsmplpxy
    wsmres.dll                 6.1.7601.23512               DLL  WSMan
    wsmsvc.dll                 6.1.7601.23512               WSMan
    wsmwmipl.dll               6.1.7601.23512              WSMAN WMI Provider
    wsnmp32.dll                6.1.7601.17514              Microsoft WinSNMP v2.0 Manager API
    wsock32.dll                6.1.7600.16385              Windows Socket 32-Bit DLL
    wtsapi32.dll               6.1.7601.17514              Windows Remote Desktop Session Host Server SDK APIs
    wuapi.dll                  7.6.7601.23806              API    Windows
    wudriver.dll               7.6.7601.23806              Windows Update WUDriver Stub
    wups.dll                   7.6.7601.23806              Windows Update client proxy stub
    wuwebv.dll                 7.6.7601.23806              Windows Update Vista Web Control
    wvc.dll                    6.1.7601.23841              Windows Visual Components
    wwanapi.dll                6.1.7600.16385              Mbnapi
    wwapi.dll                  8.1.2.0                     WWAN API
    wzcdlg.dll                 6.1.7600.16385              Windows Connect Now - Flash Config Enrollee
    x3daudio1_0.dll            9.11.519.0                  X3DAudio
    x3daudio1_1.dll            9.15.779.0                  X3DAudio
    x3daudio1_2.dll            9.21.1148.0                 X3DAudio
    x3daudio1_3.dll            9.22.1284.0                 X3DAudio
    x3daudio1_4.dll            9.23.1350.0                 X3DAudio
    x3daudio1_5.dll            9.25.1476.0                 X3DAudio
    x3daudio1_6.dll            9.26.1590.0                 3D Audio Library
    x3daudio1_7.dll            9.28.1886.0                 3D Audio Library
    xactengine2_0.dll          9.11.519.0                  XACT Engine API
    xactengine2_1.dll          9.12.589.0                  XACT Engine API
    xactengine2_10.dll         9.21.1148.0                 XACT Engine API
    xactengine2_2.dll          9.13.644.0                  XACT Engine API
    xactengine2_3.dll          9.14.701.0                  XACT Engine API
    xactengine2_4.dll          9.15.779.0                  XACT Engine API
    xactengine2_5.dll          9.16.857.0                  XACT Engine API
    xactengine2_6.dll          9.17.892.0                  XACT Engine API
    xactengine2_7.dll          9.18.944.0                  XACT Engine API
    xactengine2_8.dll          9.19.1007.0                 XACT Engine API
    xactengine2_9.dll          9.20.1057.0                 XACT Engine API
    xactengine3_0.dll          9.22.1284.0                 XACT Engine API
    xactengine3_1.dll          9.23.1350.0                 XACT Engine API
    xactengine3_2.dll          9.24.1400.0                 XACT Engine API
    xactengine3_3.dll          9.25.1476.0                 XACT Engine API
    xactengine3_4.dll          9.26.1590.0                 XACT Engine API
    xactengine3_5.dll          9.27.1734.0                 XACT Engine API
    xactengine3_6.dll          9.28.1886.0                 XACT Engine API
    xactengine3_7.dll          9.29.1962.0                 XACT Engine API
    xapofx1_0.dll              9.23.1350.0                 XAPOFX
    xapofx1_1.dll              9.24.1400.0                 XAPOFX
    xapofx1_2.dll              9.25.1476.0                 XAPOFX
    xapofx1_3.dll              9.26.1590.0                 Audio Effect Library
    xapofx1_4.dll              9.28.1886.0                 Audio Effect Library
    xapofx1_5.dll              9.29.1962.0                 Audio Effect Library
    xaudio2_0.dll              9.22.1284.0                 XAudio2 Game Audio API
    xaudio2_1.dll              9.23.1350.0                 XAudio2 Game Audio API
    xaudio2_2.dll              9.24.1400.0                 XAudio2 Game Audio API
    xaudio2_3.dll              9.25.1476.0                 XAudio2 Game Audio API
    xaudio2_4.dll              9.26.1590.0                 XAudio2 Game Audio API
    xaudio2_5.dll              9.27.1734.0                 XAudio2 Game Audio API
    xaudio2_6.dll              9.28.1886.0                 XAudio2 Game Audio API
    xaudio2_7.dll              9.29.1962.0                 XAudio2 Game Audio API
    xinput1_1.dll              9.12.589.0                  Microsoft Common Controller API
    xinput1_2.dll              9.14.701.0                  Microsoft Common Controller API
    xinput1_3.dll              9.18.944.0                  Microsoft Common Controller API
    xinput9_1_0.dll            6.1.7600.16385                XNA
    xmlfilter.dll              2008.0.7600.16385            XML
    xmllite.dll                1.3.1001.0                  Microsoft XmlLite Library
    xmlprovi.dll               6.1.7600.16385              Network Provisioning Service Client API
    xolehlp.dll                2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Helper APIs DLL
    xpsfilt.dll                6.1.7600.16385              XML Paper Specification Document IFilter
    xpsgdiconverter.dll        6.2.9200.16492              XPS to GDI Converter
    xpsprint.dll               6.2.9200.16492              XPS Printing DLL
    xpsrasterservice.dll       6.1.7601.17514              XPS Rasterization Service Component
    xpsservices.dll            6.1.7601.17514              Xps Object Model in memory creation and deserialization
    xpsshhdr.dll               6.1.7600.16385              Package Document Shell Extension Handler
    xpssvcs.dll                6.1.7600.16385              Native Code Xps Services Library
    xwizards.dll               6.1.7600.16385                 
    xwreg.dll                  6.1.7600.16385              Extensible Wizard Registration Manager Module
    xwtpdui.dll                6.1.7600.16385                   DUI
    xwtpw32.dll                6.1.7600.16385                   Win32
    zipfldr.dll                6.1.7601.17514               ZIP-


--------[   ]------------------------------------------------------------------------------------------------

     :
                         06.05.2018 10:48:51
                           06.05.2018 10:56:35
                                            06.05.2018 20:56:36
                                             36002  (0 ., 10 , 0 , 1 )

      :
                                     27.12.2017 1:49:13
                            27.12.2017 1:52:14
                                        6616314  (76 ., 13 , 51 , 53 )
                                       4684530  (54 ., 5 , 15 , 30 )
                                  86519  (1 ., 0 , 1 , 59 )
                                 221111  (2 ., 13 , 25 , 11 )
                                       194
                                58.55%

      (" "):
                                        30.12.2017 22:49:16
                                     31.12.2017 15:01:26
                                              2

    :
                                                    


--------[   ]-----------------------------------------------------------------------------------------------

    Users                                                                              C:\Users
    ADMIN$                                    Admin                           C:\Windows
    C$                                                           C:\
    D$                                                           D:\
    E$                                                           E:\
    IPC$                            IPC            IPC                             


--------[    ]----------------------------------------------------------------------------------------------

    Pavel                                         BEST                      BEST


--------[  ]------------------------------------------------------------------------------------------------

  [ HomeGroupUser$ ]

     :
                                         HomeGroupUser$
                                               HomeGroupUser$
                                                       
                                               HomeUsers
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [ Pavel ]

     :
                                         Pavel
                                               Pavel
                                               HomeUsers; 
                                     203
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                                 /
                                               HomeUsers; 
                                     6
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                                      
                                               
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            


--------[  Windows ]-----------------------------------------------------------------------------------------------

  [ Radeon RX 560 Series ]

     :
                                      Radeon RX 560 Series
                                          Radeon RX 560 Series
       BIOS                                       115-C994PI0-102
                                      AMD Radeon Graphics Processor (0x67FF)
       DAC                                           Internal DAC(400MHz)
                                            25.04.2018
                                          24.20.11001.5003
                                       Advanced Micro Devices, Inc.
                                           4 

     :
      aticfx64                                          8.17.10.1613
      aticfx64                                          8.17.10.1613
      aticfx64                                          8.17.10.1613
      aticfx32                                          8.17.10.1613
      aticfx32                                          8.17.10.1613
      aticfx32                                          8.17.10.1613
      atiumd64                                          9.14.10.01334
      atidxx64                                          8.17.10.0796
      atidxx64                                          8.17.10.0796
      atiumdag                                          9.14.10.01334
      atidxx32                                          8.17.10.0796
      atidxx32                                          8.17.10.0796
      atiumdva                                          8.14.10.0618
      atiumd6a                                          8.14.10.0618
      atitmm64                                          6.14.11.25

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates

  [ Radeon RX 560 Series ]

     :
                                      Radeon RX 560 Series
                                          Radeon RX 560 Series
       BIOS                                       115-C994PI0-102
                                      AMD Radeon Graphics Processor (0x67FF)
       DAC                                           Internal DAC(400MHz)
                                            25.04.2018
                                          24.20.11001.5003
                                       Advanced Micro Devices, Inc.
                                           4 

     :
      aticfx64                                          8.17.10.1613
      aticfx64                                          8.17.10.1613
      aticfx64                                          8.17.10.1613
      aticfx32                                          8.17.10.1613
      aticfx32                                          8.17.10.1613
      aticfx32                                          8.17.10.1613
      atiumd64                                          9.14.10.01334
      atidxx64                                          8.17.10.0796
      atidxx64                                          8.17.10.0796
      atiumdag                                          9.14.10.01334
      atidxx32                                          8.17.10.0796
      atidxx32                                          8.17.10.0796
      atiumdva                                          8.14.10.0618
      atiumd6a                                          8.14.10.0618
      atitmm64                                          6.14.11.25

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates

  [ Radeon RX 560 Series ]

     :
                                      Radeon RX 560 Series
                                          Radeon RX 560 Series
       BIOS                                       115-C994PI0-102
                                      AMD Radeon Graphics Processor (0x67FF)
       DAC                                           Internal DAC(400MHz)
                                            25.04.2018
                                          24.20.11001.5003
                                       Advanced Micro Devices, Inc.
                                           4 

     :
      aticfx64                                          8.17.10.1613
      aticfx64                                          8.17.10.1613
      aticfx64                                          8.17.10.1613
      aticfx32                                          8.17.10.1613
      aticfx32                                          8.17.10.1613
      aticfx32                                          8.17.10.1613
      atiumd64                                          9.14.10.01334
      atidxx64                                          8.17.10.0796
      atidxx64                                          8.17.10.0796
      atiumdag                                          9.14.10.01334
      atidxx32                                          8.17.10.0796
      atidxx32                                          8.17.10.0796
      atiumdva                                          8.14.10.0618
      atiumd6a                                          8.14.10.0618
      atitmm64                                          6.14.11.25

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates

  [ Radeon RX 560 Series ]

     :
                                      Radeon RX 560 Series
                                          Radeon RX 560 Series
       BIOS                                       115-C994PI0-102
                                      AMD Radeon Graphics Processor (0x67FF)
       DAC                                           Internal DAC(400MHz)
                                            25.04.2018
                                          24.20.11001.5003
                                       Advanced Micro Devices, Inc.
                                           4 

     :
      aticfx64                                          8.17.10.1613
      aticfx64                                          8.17.10.1613
      aticfx64                                          8.17.10.1613
      aticfx32                                          8.17.10.1613
      aticfx32                                          8.17.10.1613
      aticfx32                                          8.17.10.1613
      atiumd64                                          9.14.10.01334
      atidxx64                                          8.17.10.0796
      atidxx64                                          8.17.10.0796
      atiumdag                                          9.14.10.01334
      atidxx32                                          8.17.10.0796
      atidxx32                                          8.17.10.0796
      atiumdva                                          8.14.10.0618
      atiumd6a                                          8.14.10.0618
      atitmm64                                          6.14.11.25

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates

  [ Radeon RX 560 Series ]

     :
                                      Radeon RX 560 Series
                                          Radeon RX 560 Series
       BIOS                                       115-C994PI0-102
                                      AMD Radeon Graphics Processor (0x67FF)
       DAC                                           Internal DAC(400MHz)
                                            25.04.2018
                                          24.20.11001.5003
                                       Advanced Micro Devices, Inc.
                                           4 

     :
      aticfx64                                          8.17.10.1613
      aticfx64                                          8.17.10.1613
      aticfx64                                          8.17.10.1613
      aticfx32                                          8.17.10.1613
      aticfx32                                          8.17.10.1613
      aticfx32                                          8.17.10.1613
      atiumd64                                          9.14.10.01334
      atidxx64                                          8.17.10.0796
      atidxx64                                          8.17.10.0796
      atiumdag                                          9.14.10.01334
      atidxx32                                          8.17.10.0796
      atidxx32                                          8.17.10.0796
      atiumdva                                          8.14.10.0618
      atiumd6a                                          8.14.10.0618
      atitmm64                                          6.14.11.25

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates


--------[  PCI / AGP ]---------------------------------------------------------------------------------------------

    AMD Radeon RX 560 (Polaris 21) (Asus RX560)                                       
    AMD Radeon RX 560 (Polaris 21)                                                    3D-


--------[   ]---------------------------------------------------------------------------------------

  [ PCI Express 3.0 x8: AMD Radeon RX 560 (Polaris 21) ]

      :
                                            AMD Radeon RX 560 (Polaris 21)
       BIOS                                       015.050.002.001.000000
       BIOS                                         26.04.2017
                                       Polaris 21 XT
                                          115-C994PI0-102
      PCI-                                    1002-67FF / 1043-04BC  (Rev CF)
                                       3000 .
                                  14 nm
                                         123 mm2
      ASIC Quality                                      69.9%
                                                 PCI Express 3.0 x8 @ 1.1 x8
                                           4 
                                               214   (original: 1275 MHz)
       RAMDAC                                    400 
                                     16
                                 64
                                     1024  (v5.1)
        DirectX                      DirectX v12.0
      PowerControl                                      0%
       WDDM                                       WDDM 1.1

      :
                                                 GDDR5
                                              128 
                                         300  (QDR)  (original: 1750 MHz)
                                      1200 
                                   [ TRIAL VERSION ]

    :
                                             AMD GCN4 (Polaris)
        (CU)                       16
      SIMD                         4
       SIMD                                       16
        SIMD                            1
      Local Data Share                                  64 
      Global Data Share                                 64 

      :
                            3424 / @ 214 
                            [ TRIAL VERSION ]
      FLOPS                          438.3 GFLOPS @ 214 
      FLOPS                            [ TRIAL VERSION ]
      24-  IOPS                         438.3 GIOPS @ 214 
      32-  IOPS                         87.7 GIOPS @ 214 

    :
                                    11%
                                        7%
                                        327 
                                      101 

    AMD PowerPlay7 (BIOS):
      Max GPU Clock                                     1800 
      Max Memory Clock                                  2000 
      PowerControl Limit                                75%
      SCLK DPM0                                         214 
      SCLK DPM1                                         603 
      SCLK DPM2                                         958 
      SCLK DPM3                                         1060 
      SCLK DPM4                                         1128 
      SCLK DPM5                                         1182 
      SCLK DPM6                                         1230 
      SCLK DPM7                                         1275 
      MCLK DPM0                                         300   (VDDCI: 0.80000 V)
      MCLK DPM1                                         625   (VDDCI: 0.87500 V)
      MCLK DPM2                                         1750   (VDDCI: 0.87500 V)

    AMD PowerTune (BIOS):
      Thermal Design Power                              60 W
      Max Power Delivery Limit                          60 W
      Thermal Design Current                            60 A
       Tjmax                                 90 C  (194 F)
      Software Shutdown Temperature                     94 C  (201 F)
      Hotspot Temperature                               105 C  (221 F)

      :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates

    ATI GPU Registers:
      ati-$002F4                                        2E005F00
      ati-$02004                                        00432210
      ati-$02408                                        000F007F
      ati-$025B8                                        00000001
      ati-$02760                                        000060A2
      ati-$029C4                                        00005665
      ati-$029EC                                        00000000
      ati-$029F8                                        FFFFFFFF
      ati-$029FC                                        FFFFFFFF
      ati-$02A00                                        50600FB2
      ati-$02A04                                        2014031D
      ati-$02BA0                                        00000000
      ati-$02BA4                                        00000000
      ati-$02BB0                                        00000910
      ati-$02BB4                                        000000AA
      ati-$02BB8                                        00000000
      ati-$02BBC                                        00090004
      ati-$02BC0                                        00000000
      ati-$02BC4                                        00000000
      ati-$02BCC                                        00000000
      ati-$02BD0                                        00000000
      ati-$03688                                        6400FF68
      ati-$0368C                                        00000000
      ati-$03690                                        004FE830
      ati-$03694                                        00779210
      ati-$03698                                        00000030
      ati-$0369C                                        6731002F
      ati-$036A0                                        00000000
      ati-$036A4                                        00000002
      ati-$036A8                                        00000014
      ati-$036AC                                        00400000
      ati-$036B0                                        00000000
      ati-$036B4                                        001A0000
      ati-$05428                                        00001000
      ati-$089BC                                        FF000001  [SE0 SH0]
      ati-$089C0                                        00000000  [SE0 SH0]
      ati-$089BC                                        00000000  [SE0 SH1]
      ati-$089C0                                        00000000  [SE0 SH1]
      ati-$089BC                                        FF000001  [SE1 SH0]
      ati-$089C0                                        00000000  [SE1 SH0]
      ati-$089BC                                        00000000  [SE1 SH1]
      ati-$089C0                                        00000000  [SE1 SH1]
      ati-$089BC                                        00000000  [SE2 SH0]
      ati-$089C0                                        00000000  [SE2 SH0]
      ati-$089BC                                        00000000  [SE2 SH1]
      ati-$089C0                                        00000000  [SE2 SH1]
      ati-$089BC                                        00000000  [SE3 SH0]
      ati-$089C0                                        00000000  [SE3 SH0]
      ati-$089BC                                        00000000  [SE3 SH1]
      ati-$089C0                                        00000000  [SE3 SH1]
      ati-$098F0                                        00000000
      ati-$098F4                                        00000000
      ati-$098F8                                        00000000
      ati-$098FC                                        00000000
      ati-$09B7C                                        00000000
      ati-$30800                                        E0030100
      ati-GCKSMCIND-0003FA14                            000009C4
      ati-GCKSMCIND-0003FA18                            000003E8
      ati-GCKSMCIND-0003FA50                            00000001
      ati-GCKSMCIND-0003FA54                            0000014C
      ati-GCKSMCIND-0003FA58                            00000000
      ati-GCKSMCIND-0003FF74                            00003C00
      ati-GCKSMCIND-0003FF78                            00000677
      ati-GCKSMCIND-0003FF7C                            000006A2
      ati-GCKSMCIND-0003FF80                            00000000
      ati-GCKSMCIND-0003FF84                            00000000
      ati-GCKSMCIND-C0100034                            02823981
      ati-GCKSMCIND-C0100038                            0000B2C0
      ati-GCKSMCIND-C0200000                            00804603
      ati-GCKSMCIND-C0200014                            00000000
      ati-GCKSMCIND-C02000F0                            00000000
      ati-GCKSMCIND-C0200288                            00000005
      ati-GCKSMCIND-C020028C                            01850002
      ati-GCKSMCIND-C0200290                            01790003
      ati-GCKSMCIND-C0200294                            00007885
      ati-GCKSMCIND-C0300008                            00000000
      ati-GCKSMCIND-C0300014                            00004025
      ati-GCKSMCIND-C0300018                            00000030
      ati-GCKSMCIND-C0300068                            00090087
      ati-GCKSMCIND-C0300074                            0031489C
      ati-GCKSMCIND-C050002C                            00000001
      ati-GCKSMCIND-C050008C                            0000000F
      ati-GCKSMCIND-C050008C                            0000000F
      ati-GCKSMCIND-C05000B4                            00000000
      ati-GCKSMCIND-C05000B8                            00003800
      ati-GCKSMCIND-C05000CC                            0000000F
      ati-GCKSMCIND-C0500120                            0000000F
      ati-GCKSMCIND-C0500140                            00200005
      ati-GCKSMCIND-C0500144                            00000001
      ati-GCKSMCIND-C0500148                            10280000
      ati-GCKSMCIND-C0500174                            00240000
      ati-GCKSMCIND-C05001A0                            00000003
      ati-GCKSMCIND-C05001D0                            05E60BB8
      ati-GCKSMCIND-C05001D4                            00000000
      ati-GCKSMCIND-C05001D8                            00E829B8
      ati-GCKSMCIND-C05001DC                            00E829B8
      ati-GCKSMCIND-C05001E0                            00E829B8
      ati-GCKSMCIND-C05001E4                            00E829B8
      ati-GCKSMCIND-C05001E8                            00000000
      ati-GCKSMCIND-C05001EC                            00000000
      ati-GCKSMCIND-C05001F0                            00000000
      ati-GCKSMCIND-C05001F4                            00000000
      ati-GCKSMCIND-C05001F8                            00000000
      ati-GCKSMCIND-C05001FC                            40040000
      ati-GCKSMCIND-C0500200                            00000009
      ati-GCKSMCIND-C0500204                            00003600
      ati-GCKSMCIND-C0500208                            00000000
      ati-GCKSMCIND-C050020C                            00000000
      ati-GCKSMCIND-C0500210                            08000000
      ati-GCKSMCIND-C0500214                            64000000
      ati-GCKSMCIND-C0500218                            00000100
      ati-GCKSMCIND-C050021C                            00400000
      ati-GCKSMCIND-C0500220                            00000000
      ati-GCKSMCIND-C0500224                            00000000
      ati-GCKSMCIND-C0500228                            00002011
      ati-GCKSMCIND-C050022C                            00000000
      ati-GCKSMCIND-C0500230                            00000006
      ati-GCKSMCIND-C0500234                            00030041
      ati-GCKSMCIND-C0500238                            0032000F
      ati-GCKSMCIND-C050023C                            0010000F
      ati-GCKSMCIND-C0500240                            00000000
      ati-GCKSMCIND-C0500244                            00000000
      ati-GCKSMCIND-C0500248                            40840000
      ati-GCKSMCIND-C050024C                            00000019
      ati-GCKSMCIND-C0500250                            00000100
      ati-GCKSMCIND-C0500254                            00000000
      ati-GCKSMCIND-C0500258                            00000000
      ati-GCKSMCIND-C050025C                            08000000
      ati-GCKSMCIND-C0500260                            64000080
      ati-GCKSMCIND-C0500264                            00000100
      ati-GCKSMCIND-C0500268                            00400000
      ati-GCKSMCIND-C050026C                            00000000
      ati-GCKSMCIND-C0500270                            00000000
      ati-GCKSMCIND-C0500274                            00000000
      ati-GCKSMCIND-C0500278                            00022086
      ati-GCKSMCIND-C050027C                            00030041
      ati-GCKSMCIND-C0500280                            0032000F
      ati-GCKSMCIND-C0500284                            0010000F
      ati-GCKSMCIND-C0500288                            00000000
      ati-GCKSMCIND-C050028C                            00223D70
      ati-GCKSMCIND-C0500290                            041E0400
      ati-GCKSMCIND-C0500294                            00000000
      ati-GCKSMCIND-C0500298                            0115FFFF
      ati-GCKSMCIND-C050029C                            00223D70
      ati-GCKSMCIND-C05002A0                            061E0007
      ati-GCKSMCIND-C05002A4                            00221209
      ati-GCKSMCIND-C05002A8                            0115FFFF
      ati-GCKSMCIND-C05002AC                            00000004
      ati-GCKSMCIND-C05002B0                            00000000
      ati-GCKSMCIND-C05002B4                            00000004
      ati-GCKSMCIND-C05002B8                            00000000
      ati-GCKSMCIND-C05002BC                            00000000
      ati-GCKSMCIND-C05002C0                            00000000
      ati-GCKSMCIND-C05002C4                            40840000
      ati-GCKSMCIND-C05002C8                            00000019
      ati-GCKSMCIND-C05002CC                            00003600
      ati-GCKSMCIND-C05002D0                            00000000
      ati-GCKSMCIND-C05002D4                            00000000
      ati-GCKSMCIND-C05002D8                            08000000
      ati-GCKSMCIND-C05002DC                            64000080
      ati-GCKSMCIND-C05002E0                            00000100
      ati-GCKSMCIND-C05002E4                            00400000
      ati-GCKSMCIND-C05002E8                            00000000
      ati-GCKSMCIND-C05002EC                            00000000
      ati-GCKSMCIND-C05002F0                            00000000
      ati-GCKSMCIND-C05002F4                            0201E085
      ati-GCKSMCIND-C05002F8                            00030041
      ati-GCKSMCIND-C05002FC                            0032000F
      ati-GCKSMCIND-C0500300                            0010000F
      ati-GCKSMCIND-C0500304                            00000000
      ati-GCKSMCIND-C0500308                            00303D70
      ati-GCKSMCIND-C050030C                            04260400
      ati-GCKSMCIND-C0500310                            00000000
      ati-GCKSMCIND-C0500314                            029FFFFF
      ati-GCKSMCIND-C0500318                            001E0000
      ati-GCKSMCIND-C050031C                            041E0400
      ati-GCKSMCIND-C0500320                            003005A3
      ati-GCKSMCIND-C0500324                            0400FFFF
      ati-GCKSMCIND-C0500328                            00000003
      ati-GCKSMCIND-C050032C                            00000000
      ati-GCKSMCIND-C0500330                            00022004
      ati-GCKSMCIND-C0500334                            00000000
      ati-GCKSMCIND-C0500338                            00000000
      ati-GCKSMCIND-C050033C                            00000000
      ati-GCKSMCIND-C0500340                            00000000
      ati-GCKSMCIND-C0500344                            00000000


--------[  ]-----------------------------------------------------------------------------------------------------

  [ LG W3000H ]

     :
                                             LG W3000H
      ID                                        GSM75EA
                                                  W3000H
                                             30" LCD (WQXGA)
                                              1 / 2008
                                           1801107018
      .                         641 mm x 401 mm (29.8")
                                       16:10
                                                 370 cd/m2
                                           3000:1
                                              170/170
                                            30 - 99 
                                           50 - 60 
                                  2560 x 1600
                                       101 ppi
                                                   2.20
        DPMS                        Active-Off

     :
      1280 x 800                                         : 71.00 
      2560 x 1600                                        : 268.00 

     :
                                                   LG Electronics
                                     http://www.lg.com/us/monitors
                                       http://www.lg.com/us/support
                                     http://www.aida64.com/driver-updates


--------[   ]------------------------------------------------------------------------------------------------

      :
                                     
                                              1280 x 800
                                            32 
                                       1
                                        96 dpi
        /                         36 / 36
                                     51
                                      60 
                                    C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg

      :
       -                             
                                              
                                      
                              
      ClearType                                         
             
                                
                                  
                                      
                                  
                                 
                                            
                                   
       /           
                                           
                              
                               
                            
                              
      Windows Aero                                      
       Windows Plus!                               


--------[  ]-----------------------------------------------------------------------------------------------

    \\.\DISPLAY1           (0,0)          (1280,800)


--------[  ]-------------------------------------------------------------------------------------------------

    640 x 480           8   60 Hz
    640 x 480           8   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    640 x 480          16   60 Hz
    640 x 480          16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    640 x 480          32   60 Hz
    640 x 480          32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480           8   60 Hz
    720 x 480           8   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480          16   60 Hz
    720 x 480          16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480          32   60 Hz
    720 x 480          32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576           8   60 Hz
    720 x 576           8   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576          16   60 Hz
    720 x 576          16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576          32   60 Hz
    720 x 576          32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    800 x 600           8   60 Hz
    800 x 600           8   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    800 x 600          16   60 Hz
    800 x 600          16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    800 x 600          32   60 Hz
    800 x 600          32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1024 x 768          8   60 Hz
    1024 x 768          8   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1024 x 768         16   60 Hz
    1024 x 768         16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1024 x 768         32   60 Hz
    1024 x 768         32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 720          8   60 Hz
    1280 x 720          8   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 720         16   60 Hz
    1280 x 720         16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 720         32   60 Hz
    1280 x 720         32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 800          8   60 Hz
    1280 x 800         16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 1024         8   60 Hz
    1280 x 1024         8   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 1024        16   60 Hz
    1280 x 1024        16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 1024        32   60 Hz
    1280 x 1024        32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1600 x 1200         8   60 Hz
    1600 x 1200         8   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1600 x 1200        16   60 Hz
    1600 x 1200        16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1600 x 1200        32   60 Hz
    1600 x 1200        32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1680 x 1050         8   60 Hz
    1680 x 1050         8   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1680 x 1050        16   60 Hz
    1680 x 1050        16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1680 x 1050        32   60 Hz
    1680 x 1050        32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1920 x 1080         8   60 Hz
    1920 x 1080         8   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1920 x 1080        16   60 Hz
    1920 x 1080        16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1920 x 1080        32   60 Hz
    1920 x 1080        32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    2560 x 1600         8   60 Hz
    2560 x 1600        16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]


--------[ GPGPU ]-------------------------------------------------------------------------------------------------------

  [ Direct3D: Radeon RX 560 Series (Polaris 11 (Baffin)) ]

     :
                                           Radeon RX 560 Series
                                       Polaris 11 (Baffin)
      PCI-                                    1002-67FF / 1043-04BC  (Rev CF)
                                        3 
                                             aticfx32.dll
                                          24.20.11001.5003
      Shader Model                                      SM 5.0
      Max Threads                                       1024
      Multiple UAV Access                               8 UAVs
      Thread Dispatch                                   3D
      Thread Local Storage                              32 

     :
      10-bit Precision Floating-Point                    
      16-bit Precision Floating-Point                    
      Append/Consume Buffers                            
      Atomic Operations                                 
      Double-Precision Floating-Point                   
      Gather4                                           
      Indirect Compute Dispatch                         
      Map On Default Buffers                             

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates

  [ OpenCL: Radeon RX 560 Series (Baffin) ]

     OpenCL:
                                               AMD Accelerated Parallel Processing
                                      Advanced Micro Devices, Inc.
                                         OpenCL 2.1 AMD-APP (2580.6)
                                        Full

     :
                                           Baffin
                                            Radeon RX 560 Series
                                            
                                     Advanced Micro Devices, Inc.
                                        OpenCL 1.2 AMD-APP (2580.6)
                                       Full
                                          2580.6
       OpenCL C                                   OpenCL C 1.2 
      Supported SPIR Versions                           1.2
                                                 1275 
       /                       16 / 1024
      SIMD                         4
       SIMD                                       16
        SIMD                            1
      Wavefront Width                                   64
      Address Space Size                                32 
      Max 2D Image Size                                 16384 x 16384
      Max 3D Image Size                                 2048 x 2048 x 2048
      Max Image Array Size                              2048
      Max Image Buffer Size                             134217728
      Max Samplers                                      16
      Max Work-Item Size                                1024 x 1024 x 1024
      Max Work-Group Size                               256
      Max Argument Size                                 1 
      Max Constant Buffer Size                          3145728 
      Max Constant Arguments                            8
      Max Printf Buffer Size                            4 
      Native ISA Vector Widths                          char4, short2, int1, half1, float1, double1
      Preferred Native Vector Widths                    char4, short2, int1, long1, half1, float1, double1
      Host Timer Resolution                             426 ns
      Profiling Timer Resolution                        1 ns
      Profiling Timer Offset Since Epoch                1525593380277585447 ns
      OpenCL DLL                                        opencl.dll (2.2.1.0)

     :
      Global Memory                                     3 
      Free Global Memory                                4143313  / 3913169 
      Global Memory Cache                               16   (Read/Write, 64-byte line)
      Global Memory Channels                            4
      Global Memory Channel Banks                       16
      Global Memory Channel Bank Width                  256 
      Local Memory                                      32 
      Local Memory Size Per Compute Unit                64 
      Local Memory Banks                                32
      Max Memory Object Allocation Size                 3 
      Memory Base Address Alignment                     2048 
      Min Data Type Alignment                           128 
      Image Row Pitch Alignment                         256 pixels
      Image Base Address Alignment                      256 pixels

     OpenCL:
      OpenCL 1.1                                          (100%)
      OpenCL 1.2                                          (100%)
      OpenCL 2.0                                          (87%)

     :
      Command-Queue Out Of Order Execution              
      Command-Queue Profiling                           
      Compiler Available                                
                                          
      Images                                            
      Kernel Execution                                  
      Linker Available                                  
      Little-Endian Device                              
      Native Kernel Execution                            
      Sub-Group Independent Forward Progress             
      SVM Atomics                                        
      SVM Coarse Grain Buffer                            
      SVM Fine Grain Buffer                              
      SVM Fine Grain System                              
      Thread Trace                                      
      Unified Memory                                    

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                            
      IEEE754-2008 FMA                                   
      INF and NaNs                                       
      Rounding to Infinity                               
      Rounding to Nearest Even                           
      Rounding to Zero                                   
      Software Basic Floating-Point Operations          

         :
      Correctly Rounded Divide and Sqrt                 
      Denorms                                            
      IEEE754-2008 FMA                                  
      INF and NaNs                                      
      Rounding to Infinity                              
      Rounding to Nearest Even                          
      Rounding to Zero                                  
      Software Basic Floating-Point Operations          

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                           
      IEEE754-2008 FMA                                  
      INF and NaNs                                      
      Rounding to Infinity                              
      Rounding to Nearest Even                          
      Rounding to Zero                                  
      Software Basic Floating-Point Operations          

     :
       /                   96 / 25
      cl_altera_compiler_mode                            
      cl_altera_device_temperature                       
      cl_altera_live_object_tracking                     
      cl_amd_bus_addressable_memory                      
      cl_amd_c1x_atomics                                 
      cl_amd_compile_options                             
      cl_amd_core_id                                     
      cl_amd_d3d10_interop                               
      cl_amd_d3d9_interop                                
      cl_amd_device_attribute_query                     
      cl_amd_device_board_name                           
      cl_amd_device_memory_flags                         
      cl_amd_device_persistent_memory                    
      cl_amd_device_profiling_timer_offset               
      cl_amd_device_topology                             
      cl_amd_event_callback                              
      cl_amd_fp64                                       
      cl_amd_hsa                                         
      cl_amd_image2d_from_buffer_read_only               
      cl_amd_liquid_flash                               
      cl_amd_media_ops                                  
      cl_amd_media_ops2                                 
      cl_amd_offline_devices                             
      cl_amd_popcnt                                     
      cl_amd_predefined_macros                           
      cl_amd_printf                                     
      cl_amd_svm                                         
      cl_amd_vec3                                       
      cl_apple_contextloggingfunctions                   
      cl_apple_gl_sharing                                
      cl_apple_setmemobjectdestructor                    
      cl_arm_core_id                                     
      cl_arm_printf                                      
      cl_ext_atomic_counters_32                          
      cl_ext_atomic_counters_64                          
      cl_ext_device_fission                              
      cl_ext_migrate_memobject                           
      cl_intel_accelerator                               
      cl_intel_advanced_motion_estimation                
      cl_intel_ctz                                       
      cl_intel_d3d11_nv12_media_sharing                  
      cl_intel_device_partition_by_names                 
      cl_intel_dx9_media_sharing                         
      cl_intel_exec_by_local_thread                      
      cl_intel_motion_estimation                         
      cl_intel_packed_yuv                                
      cl_intel_printf                                    
      cl_intel_required_subgroup_size                    
      cl_intel_simultaneous_sharing                      
      cl_intel_subgroups                                 
      cl_intel_thread_local_exec                         
      cl_intel_va_api_media_sharing                      
      cl_intel_visual_analytics                          
      cl_khr_3d_image_writes                            
      cl_khr_byte_addressable_store                     
      cl_khr_context_abort                               
      cl_khr_d3d10_sharing                              
      cl_khr_d3d11_sharing                              
      cl_khr_depth_images                                
      cl_khr_dx9_media_sharing                          
      cl_khr_egl_event                                   
      cl_khr_egl_image                                   
      cl_khr_fp16                                       
      cl_khr_fp64                                       
      cl_khr_gl_depth_images                             
      cl_khr_gl_event                                   
      cl_khr_gl_msaa_sharing                             
      cl_khr_gl_sharing                                 
      cl_khr_global_int32_base_atomics                  
      cl_khr_global_int32_extended_atomics              
      cl_khr_icd                                         
      cl_khr_il_program                                  
      cl_khr_image2d_from_buffer                        
      cl_khr_initialize_memory                           
      cl_khr_int64_base_atomics                         
      cl_khr_int64_extended_atomics                     
      cl_khr_local_int32_base_atomics                   
      cl_khr_local_int32_extended_atomics               
      cl_khr_mipmap_image                                
      cl_khr_mipmap_image_writes                         
      cl_khr_priority_hints                              
      cl_khr_select_fprounding_mode                      
      cl_khr_spir                                       
      cl_khr_srgb_image_writes                           
      cl_khr_subgroups                                   
      cl_khr_terminate_context                           
      cl_khr_throttle_hints                              
      cl_nv_compiler_options                             
      cl_nv_copy_opts                                    
      cl_nv_d3d10_sharing                                
      cl_nv_d3d11_sharing                                
      cl_nv_d3d9_sharing                                 
      cl_nv_device_attribute_query                       
      cl_nv_pragma_unroll                                
      cl_qcom_ext_host_ptr                               
      cl_qcom_ion_host_ptr                               

  [ OpenCL: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz ]

     OpenCL:
                                               AMD Accelerated Parallel Processing
                                      Advanced Micro Devices, Inc.
                                         OpenCL 2.1 AMD-APP (2580.6)
                                        Full

     :
                                           Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
                                           
                                     GenuineIntel
                                        OpenCL 1.2 AMD-APP (2580.6)
                                       Full
                                          2580.6 (sse2)
       OpenCL C                                   OpenCL C 1.2 
      Supported SPIR Versions                           1.2
                                                 2400 
                                   4
      Address Space Size                                32 
      Max 2D Image Size                                 8192 x 8192
      Max 3D Image Size                                 2048 x 2048 x 2048
      Max Image Array Size                              2048
      Max Image Buffer Size                             65536
      Max Samplers                                      16
      Max Work-Item Size                                1024 x 1024 x 1024
      Max Work-Group Size                               1024
      Max Global Variable Size                          1048576 
      Preferred Global Variables Total Size             1048576 
      Max Argument Size                                 4 
      Max Constant Buffer Size                          64 
      Max Constant Arguments                            8
      Max Pipe Arguments                                16
      Max Printf Buffer Size                            64 
      Native ISA Vector Widths                          char16, short8, int2, half2, float4, double2
      Preferred Native Vector Widths                    char16, short8, int4, long2, half2, float4, double2
      Host Timer Resolution                             426 ns
      Profiling Timer Resolution                        426 ns
      Profiling Timer Offset Since Epoch                1525593380277585447 ns
      OpenCL DLL                                        opencl.dll (2.2.1.0)

     :
      Global Memory                                     2 
      Global Memory Cache                               32   (Read/Write, 64-byte line)
      Local Memory                                      32 
      Max Memory Object Allocation Size                 1 
      Memory Base Address Alignment                     1024 
      Min Data Type Alignment                           128 

     OpenCL:
      OpenCL 1.1                                          (100%)
      OpenCL 1.2                                          (100%)
      OpenCL 2.0                                          (75%)

     :
      Command-Queue Out Of Order Execution              
      Command-Queue Profiling                           
      Compiler Available                                
                                          
      Images                                            
      Kernel Execution                                  
      Linker Available                                  
      Little-Endian Device                              
      Native Kernel Execution                           
      Sub-Group Independent Forward Progress             
      SVM Atomics                                        
      SVM Coarse Grain Buffer                            
      SVM Fine Grain Buffer                              
      SVM Fine Grain System                              
      Thread Trace                                       
      Unified Memory                                    

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                            
      IEEE754-2008 FMA                                   
      INF and NaNs                                       
      Rounding to Infinity                               
      Rounding to Nearest Even                           
      Rounding to Zero                                   
      Software Basic Floating-Point Operations          

         :
      Correctly Rounded Divide and Sqrt                 
      Denorms                                           
      IEEE754-2008 FMA                                  
      INF and NaNs                                      
      Rounding to Infinity                              
      Rounding to Nearest Even                          
      Rounding to Zero                                  
      Software Basic Floating-Point Operations          

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                           
      IEEE754-2008 FMA                                  
      INF and NaNs                                      
      Rounding to Infinity                              
      Rounding to Nearest Even                          
      Rounding to Zero                                  
      Software Basic Floating-Point Operations          

     :
       /                   96 / 19
      cl_altera_compiler_mode                            
      cl_altera_device_temperature                       
      cl_altera_live_object_tracking                     
      cl_amd_bus_addressable_memory                      
      cl_amd_c1x_atomics                                 
      cl_amd_compile_options                             
      cl_amd_core_id                                     
      cl_amd_d3d10_interop                               
      cl_amd_d3d9_interop                                
      cl_amd_device_attribute_query                     
      cl_amd_device_board_name                           
      cl_amd_device_memory_flags                         
      cl_amd_device_persistent_memory                    
      cl_amd_device_profiling_timer_offset               
      cl_amd_device_topology                             
      cl_amd_event_callback                              
      cl_amd_fp64                                       
      cl_amd_hsa                                         
      cl_amd_image2d_from_buffer_read_only               
      cl_amd_liquid_flash                                
      cl_amd_media_ops                                  
      cl_amd_media_ops2                                 
      cl_amd_offline_devices                             
      cl_amd_popcnt                                     
      cl_amd_predefined_macros                           
      cl_amd_printf                                     
      cl_amd_svm                                         
      cl_amd_vec3                                       
      cl_apple_contextloggingfunctions                   
      cl_apple_gl_sharing                                
      cl_apple_setmemobjectdestructor                    
      cl_arm_core_id                                     
      cl_arm_printf                                      
      cl_ext_atomic_counters_32                          
      cl_ext_atomic_counters_64                          
      cl_ext_device_fission                             
      cl_ext_migrate_memobject                           
      cl_intel_accelerator                               
      cl_intel_advanced_motion_estimation                
      cl_intel_ctz                                       
      cl_intel_d3d11_nv12_media_sharing                  
      cl_intel_device_partition_by_names                 
      cl_intel_dx9_media_sharing                         
      cl_intel_exec_by_local_thread                      
      cl_intel_motion_estimation                         
      cl_intel_packed_yuv                                
      cl_intel_printf                                    
      cl_intel_required_subgroup_size                    
      cl_intel_simultaneous_sharing                      
      cl_intel_subgroups                                 
      cl_intel_thread_local_exec                         
      cl_intel_va_api_media_sharing                      
      cl_intel_visual_analytics                          
      cl_khr_3d_image_writes                            
      cl_khr_byte_addressable_store                     
      cl_khr_context_abort                               
      cl_khr_d3d10_sharing                              
      cl_khr_d3d11_sharing                               
      cl_khr_depth_images                                
      cl_khr_dx9_media_sharing                           
      cl_khr_egl_event                                   
      cl_khr_egl_image                                   
      cl_khr_fp16                                        
      cl_khr_fp64                                       
      cl_khr_gl_depth_images                             
      cl_khr_gl_event                                   
      cl_khr_gl_msaa_sharing                             
      cl_khr_gl_sharing                                 
      cl_khr_global_int32_base_atomics                  
      cl_khr_global_int32_extended_atomics              
      cl_khr_icd                                         
      cl_khr_il_program                                  
      cl_khr_image2d_from_buffer                         
      cl_khr_initialize_memory                           
      cl_khr_int64_base_atomics                          
      cl_khr_int64_extended_atomics                      
      cl_khr_local_int32_base_atomics                   
      cl_khr_local_int32_extended_atomics               
      cl_khr_mipmap_image                                
      cl_khr_mipmap_image_writes                         
      cl_khr_priority_hints                              
      cl_khr_select_fprounding_mode                      
      cl_khr_spir                                       
      cl_khr_srgb_image_writes                           
      cl_khr_subgroups                                   
      cl_khr_terminate_context                           
      cl_khr_throttle_hints                              
      cl_nv_compiler_options                             
      cl_nv_copy_opts                                    
      cl_nv_d3d10_sharing                                
      cl_nv_d3d11_sharing                                
      cl_nv_d3d9_sharing                                 
      cl_nv_device_attribute_query                       
      cl_nv_pragma_unroll                                
      cl_qcom_ext_host_ptr                               
      cl_qcom_ion_host_ptr                               

     :
                                                   Intel Corporation
                                     http://www.intel.com/products/chipsets
                                       http://support.intel.com/support/graphics
                                     http://www.aida64.com/driver-updates


--------[  Windows ]-----------------------------------------------------------------------------------------------

    midi-out.0   0001 001B  Microsoft GS Wavetable Synth
    mixer.0      0001 0068   (Realtek High Definiti
    mixer.1      0001 0068  S/PDIF Pass-through Device (ASU
    mixer.10     0001 0068  .  (ASUS Xonar Essence S
    mixer.11     0001 0068   (ASUS Xonar Essence ST
    mixer.2      0001 0068  Realtek Digital Output (Realtek
    mixer.3      0001 0068   (ASUS Xonar Essence ST
    mixer.4      0001 0068  Realtek Digital Input (Realtek 
    mixer.5      0001 0068  Wave (ASUS Xonar Essence STX Au
    mixer.6      FFFF FFFF   (3- Vimicro USB2.0 Cam
    mixer.7      0001 0068   (Realtek High Definiti
    mixer.8      0001 0068  Stereo Mix (ASUS Xonar Essence 
    mixer.9      0001 0068  Aux (ASUS Xonar Essence STX Aud
    wave-in.0    FFFF FFFF   (3- Vimicro USB2.0 Cam
    wave-in.1    0001 0065  Realtek Digital Input (Realtek 
    wave-in.2    0001 0065  Wave (ASUS Xonar Essence STX Au
    wave-in.3    0001 0065   (Realtek High Definiti
    wave-in.4    0001 0065  Stereo Mix (ASUS Xonar Essence 
    wave-in.5    0001 0065  Aux (ASUS Xonar Essence STX Aud
    wave-in.6    0001 0065  .  (ASUS Xonar Essence S
    wave-in.7    0001 0065   (ASUS Xonar Essence ST
    wave-out.0   0001 0064   (Realtek High Definiti
    wave-out.1   0001 0064  S/PDIF Pass-through Device (ASU
    wave-out.2   0001 0064  Realtek Digital Output (Realtek
    wave-out.3   0001 0064   (ASUS Xonar Essence ST


--------[  PCI / PnP ]---------------------------------------------------------------------------------------------

    ATI Radeon HDMI @ AMD Baffin/Lexa - High Definition Audio Controller              PCI
    C-Media CMI8788 Audio Chip                                                        PCI
    Realtek ALC889A @ Intel 82801IB ICH9 - High Definition Audio Controller [A-2]     PCI


--------[ HD Audio ]----------------------------------------------------------------------------------------------------

  [ AMD Baffin/Lexa - High Definition Audio Controller ]

     :
                                      AMD Baffin/Lexa - High Definition Audio Controller
        (Windows)                      High Definition Audio (Microsoft)
                                                 PCI
       /  /                        1 / 0 / 1
      ID                                      1002-AAE0
                               1043-AAE0
                                                  00
       ID                                     PCI\VEN_1002&DEV_AAE0&SUBSYS_AAE01043&REV_00

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/chipsets
                                       http://support.amd.com
       BIOS                                 http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [ ATI Radeon HDMI ]

     :
                                      ATI Radeon HDMI
        (Windows)                     AMD High Definition Audio Device
                                           Audio
                                                 HDAUDIO
      ID                                      1002-AA01
                               00AA-0100
                                                  1007
       ID                                     HDAUDIO\FUNC_01&VEN_1002&DEV_AA01&SUBSYS_00AA0100&REV_1007

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/chipsets
                                       http://support.amd.com
                                     http://www.aida64.com/driver-updates

  [ Intel 82801IB ICH9 - High Definition Audio Controller [A-2] ]

     :
                                      Intel 82801IB ICH9 - High Definition Audio Controller [A-2]
        (Windows)                      High Definition Audio (Microsoft)
                                                 PCI
       /  /                        0 / 27 / 0
      ID                                      8086-293E
                               1458-A002
                                                  02
       ID                                     PCI\VEN_8086&DEV_293E&SUBSYS_A0021458&REV_02

     :
                                                   Intel Corporation
                                     http://www.intel.com/products/chipsets
                                       http://support.intel.com/support/chipsets
       BIOS                                 http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [ Realtek ALC889A ]

     :
                                      Realtek ALC889A
        (Windows)                     Realtek High Definition Audio
                                           Audio
                                                 HDAUDIO
      ID                                      10EC-0885
                               1458-A002
                                                  1001
       ID                                     HDAUDIO\FUNC_01&VEN_10EC&DEV_0885&SUBSYS_1458A002&REV_1001

     :
                                                   Realtek Semiconductor Corp.
                                     http://www.realtek.com.tw/products/productsView.aspx?Langid=1&PNid=8&PFid=14&Level=3&Conn=2
                                       http://www.realtek.com.tw/downloads
                                     http://www.aida64.com/driver-updates


--------[   Windows ]-------------------------------------------------------------------------------------

  [  ]

     :
                                        
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          flpydisk.inf
      INF Section                                       floppy_install.NT

  [ RDP8 CF USB Device ]

     :
                                        RDP8 CF USB Device
                                            21.06.2006
                                          6.1.7601.19133
                                       Microsoft
      INF-                                          disk.inf
      INF Section                                       disk_install.NT

  [ RDP8 MS/M2 USB Device ]

     :
                                        RDP8 MS/M2 USB Device
                                            21.06.2006
                                          6.1.7601.19133
                                       Microsoft
      INF-                                          disk.inf
      INF Section                                       disk_install.NT

  [ RDP8 SD/microSD USB Device ]

     :
                                        RDP8 SD/microSD USB Device
                                            21.06.2006
                                          6.1.7601.19133
                                       Microsoft
      INF-                                          disk.inf
      INF Section                                       disk_install.NT

  [ SAMSUNG HD501LJ ATA Device ]

     :
                                        SAMSUNG HD501LJ ATA Device
                                            21.06.2006
                                          6.1.7601.19133
                                       Microsoft
      INF-                                          disk.inf
      INF Section                                       disk_install.NT

  [ TOSHIBA A100 ATA Device ]

     :
                                        TOSHIBA A100 ATA Device
                                            21.06.2006
                                          6.1.7601.19133
                                       Microsoft
      INF-                                          disk.inf
      INF Section                                       disk_install.NT

  [ HL-DT-ST DVD-RAM GSA-H55N ATA Device ]

     :
                                        HL-DT-ST DVD-RAM GSA-H55N ATA Device
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          cdrom.inf
      INF Section                                       cdrom_install

  [ ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf
      INF Section                                       atapi_Inst

     :
      IRQ                                               14
                                                    01F0-01F7
                                                    03F6-03F6

  [ ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf
      INF Section                                       atapi_Inst

  [ ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf
      INF Section                                       atapi_Inst

  [ ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf
      INF Section                                       atapi_Inst

     :
      IRQ                                               15
                                                    0170-0177
                                                    0376-0376

  [ ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf
      INF Section                                       atapi_Inst

  [ ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf
      INF Section                                       atapi_Inst

  [ Intel(R) ICH9 Family 2 port Serial ATA Storage Controller 1 - 2921 ]

     :
                                        Intel(R) ICH9 Family 2 port Serial ATA Storage Controller 1 - 2921
                                            04.06.2009
                                          9.1.1.1013
                                       Intel
      INF-                                          oem9.inf
      INF Section                                       pciide_Inst

     :
                                                    F000-F00F
                                                    F100-F10F

  [ Intel(R) ICH9 Family 2 port Serial ATA Storage Controller 2 - 2926 ]

     :
                                        Intel(R) ICH9 Family 2 port Serial ATA Storage Controller 2 - 2926
                                            04.06.2009
                                          9.1.1.1013
                                       Intel
      INF-                                          oem9.inf
      INF Section                                       pciide_Inst

     :
      IRQ                                               19
                                                    E700-E707
                                                    E800-E803
                                                    E900-E907
                                                    EA00-EA03
                                                    EB00-EB0F
                                                    EC00-EC0F

  [    PCI IDE ]

     :
                                           PCI IDE
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf
      INF Section                                       pciide_Inst

     :
      IRQ                                               19
                                                  F8000000-F8001FFF
                                                    C000-C007
                                                    C100-C103
                                                    C200-C207
                                                    C300-C303
                                                    C400-C40F

  [     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          fdc.inf
      INF Section                                       fdc_install.NT

     :
      DMA                                               02
      IRQ                                               06
                                                    03F0-03F5
                                                    03F7-03F7


--------[   ]--------------------------------------------------------------------------------------------

    A:                                                                                                                     
    [ TRIAL VERSION ]                                NTFS      [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    D:                                               NTFS          91965       54216       37749    41 %  CA55-B565
    E:                                               NTFS         384971      160523      224447    58 %  7A05-1AFB
    F:                                                                                                               
    H:                                                                                                                     
    I:                                                                                                                     
    J:                                                                                                                     


--------[   ]--------------------------------------------------------------------------------------------

  [  #1 - SAMSUNG HD501LJ (465 ) ]

    #1 ()    NTFS             D:                                              0 MB    91965 MB
    #2               NTFS             E:                                          91965 MB   384971 MB

  [  #2 - TOSHIBA A100 (111 ) ]

    #1 ()    NTFS             C:                                              1 MB   114472 MB


--------[   ]---------------------------------------------------------------------------------------

  [ F:\  HL-DT-ST DVD-RAM GSA-H55N ATA Device ]

      :
                                      HL-DT-ST DVD-RAM GSA-H55N ATA Device
                                           0:7:K8;I
                                          1.03
                                            17.08.2007
                                             2 
                                           Hitachi-LG
                                           DVD+RW/DVD-RW/DVD-RAM
                                               ATAPI
                                              5
                               4
                                      4

     :
      DVD+R9 Dual Layer                                 10x
      DVD+R                                             20x
      DVD+RW                                            8x
      DVD-R9 Dual Layer                                 10x
      DVD-R                                             20x
      DVD-RW                                            6x
      DVD-RAM                                           12x
      CD-R                                              48x
      CD-RW                                             32x

     :
      DVD-ROM                                           16x
      CD-ROM                                            48x

      :
      BD-ROM                                             
      BD-R                                               
      BD-RE                                              
      HD DVD-ROM                                         
      HD DVD-R Dual Layer                                
      HD DVD-RW Dual Layer                               
      HD DVD-R                                           
      HD DVD-RW                                          
      HD DVD-RAM                                         
      DVD-ROM                                           
      DVD+R9 Dual Layer                                  + 
      DVD+RW9 Dual Layer                                 
      DVD+R                                              + 
      DVD+RW                                             + 
      DVD-R9 Dual Layer                                  + 
      DVD-RW9 Dual Layer                                 
      DVD-R                                              + 
      DVD-RW                                             + 
      DVD-RAM                                            + 
      CD-ROM                                            
      CD-R                                               + 
      CD-RW                                              + 

      :
      AACS                                               
      BD CPS                                             
      Buffer Underrun Protection                        
      C2 Error Pointers                                  
      CD+G                                               
      CD-Text                                           
      DVD-Download Disc Recording                        
      Hybrid Disc                                        
      JustLink                                           
      CPRM                                              
      CSS                                               
      LabelFlash                                         
      Layer-Jump Recording                              
      LightScribe                                        
      Mount Rainier                                      
      OSSC                                               
      Qflix Recording                                    
      SecurDisc                                         
      SMART                                              
      VCPS                                               

     :
                                                   LG Electronics
                                     http://www.lg.com/us/data-storage
                                        http://www.lg.com/us/support
                                     http://www.aida64.com/driver-updates


--------[ ATA ]---------------------------------------------------------------------------------------------------------

  [ SAMSUNG HD501LJ (S0Q9J1DP900209) ]

      ATA:
      ID                                          SAMSUNG HD501LJ
                                           S0Q9J1DP900209
                                                  CR100-10
      World Wide Name                                   5-0000F0-01B900209
                                           SATA-II
                                               : 969019, : 16,   : 63,   : 554
       LBA                                       976771055
       /             512  / 512 
                                                   16  (Dual Ported, Read Ahead)
                                           16
      .  PIO                                   PIO 4
      .  MWDMA                                 MWDMA 2
      .  UDMA                                  UDMA 6
        UDMA                               UDMA 5
                                516063 
       ATA                                      ATA8-ACS

      ATA:
      48-bit LBA                                        , 
      Automatic Acoustic Management (AAM)               , 
      Device Configuration Overlay (DCO)                , 
      DMA Setup Auto-Activate                           , 
      Free-Fall Control                                  
      General Purpose Logging (GPL)                     , 
      Hardware Feature Control                           
      Host Protected Area (HPA)                         , 
      HPA Security Extensions                           , 
      Hybrid Information Feature                         
      In-Order Data Delivery                             
      Native Command Queuing (NCQ)                      
      NCQ Autosense                                      
      NCQ Priority Information                           
      NCQ Queue Management Command                       
      NCQ Streaming                                      
      Phy Event Counters                                
      Read Look-Ahead                                   , 
      Release Interrupt                                  
                                       , 
      Sense Data Reporting (SDR)                         
      Service Interrupt                                  
      SMART                                             , 
      SMART Error Logging                               , 
      SMART Self-Test                                   , 
      Software Settings Preservation (SSP)              , 
      Streaming                                          
      Tagged Command Queuing (TCQ)                       
                                               , 
      Write-Read-Verify                                  

     SSD:
      Data Set Management                                
      Deterministic Read After TRIM                      
       TRIM                                       

     :
       (APM)                             
      Automatic Partial to Slumber Transitions (APST)   
      Device Initiated Interface Power Management (DIPM), 
      Device Sleep (DEVSLP)                              
      Extended Power Conditions (EPC)                    
      Host Initiated Interface Power Management (HIPM)  
      IDLE IMMEDIATE With UNLOAD FEATURE                 
      Link Power State Device Sleep                      
                                          , 
      Power-Up In Standby (PUIS)                         

     ATA:
      DEVICE RESET                                       
      DOWNLOAD MICROCODE                                , 
      FLUSH CACHE                                       , 
      FLUSH CACHE EXT                                   , 
      NOP                                               , 
      READ BUFFER                                       , 
      WRITE BUFFER                                      , 

       :
                                           Samsung
                                  SpinPoint T166
      -                                       3.5"
                                  500 
                                                   3
                                 6
                                      146.05 x 101.6 x 25.4 mm
                                         512 g
                                4.17 ms
                                        7200 RPM
      .                     1080 /
                                      8.9 ms
                                0.8 ms
                                       18 ms
                                               SATA-II
        '-'                300 /
                                             16 
                                          10 

     :
                                                   Samsung
                                     http://www.samsung.com/us/computer/solid-state-drives
                                     http://www.aida64.com/driver-updates

  [ TOSHIBA A100 (Y6MB406EKQ7U) ]

      ATA:
      ID                                          TOSHIBA A100
                                           Y6MB406EKQ7U
                                                  SBFA10.3
      World Wide Name                                   5-00080D-C00638133
                                           SATA-III
                                               : 232581, : 16,   : 63,   : 512
       LBA                                       234441648
       /             512  / 512 
                                           16
      .  PIO                                   PIO 4
      .  MWDMA                                 MWDMA 2
      .  UDMA                                  UDMA 6
        UDMA                               UDMA 5
                                114473 
      -                                       2.5"
                                        SSD

      ATA:
      48-bit LBA                                        , 
      Automatic Acoustic Management (AAM)                
      Device Configuration Overlay (DCO)                 
      DMA Setup Auto-Activate                           , 
      Free-Fall Control                                  
      General Purpose Logging (GPL)                     , 
      Hardware Feature Control                           
      Host Protected Area (HPA)                         , 
      HPA Security Extensions                           , 
      Hybrid Information Feature                         
      In-Order Data Delivery                             
      Native Command Queuing (NCQ)                      
      NCQ Autosense                                      
      NCQ Priority Information                           
      NCQ Queue Management Command                       
      NCQ Streaming                                      
      Phy Event Counters                                
      Read Look-Ahead                                   , 
      Release Interrupt                                  
                                       , 
      Sense Data Reporting (SDR)                         
      Service Interrupt                                  
      SMART                                             , 
      SMART Error Logging                               , 
      SMART Self-Test                                    
      Software Settings Preservation (SSP)              , 
      Streaming                                          
      Tagged Command Queuing (TCQ)                       
                                               , 
      Write-Read-Verify                                  

     SSD:
      Data Set Management                               
      Deterministic Read After TRIM                      
       TRIM                                      

     :
       (APM)                             
      Automatic Partial to Slumber Transitions (APST)   
      Device Initiated Interface Power Management (DIPM), 
      Device Sleep (DEVSLP)                             
      Extended Power Conditions (EPC)                    
      Host Initiated Interface Power Management (HIPM)   
      IDLE IMMEDIATE With UNLOAD FEATURE                 
      Link Power State Device Sleep                     , 
                                          , 
      Power-Up In Standby (PUIS)                         

     ATA:
      DEVICE RESET                                       
      DOWNLOAD MICROCODE                                , 
      FLUSH CACHE                                       , 
      FLUSH CACHE EXT                                   , 
      NOP                                               , 
      READ BUFFER                                       , 
      WRITE BUFFER                                      , 

      SSD:
                                           Toshiba
       SSD                                     A100
      -                                       2.5"
                                  120 
                                          Toshiba TC58NC1010
       -                                   15nm TLC NAND
                                      100 x 69.85 x 7 mm
                                         37.5 g
      .              550 /
      .               480 /
      .  4-                        87000 IOPS
      .  4-                        82000 IOPS
                                               SATA-III
                      600 /

     :
                                                   Toshiba Corp., Storage Device Division
                                     http://sdd.toshiba.com
                                     http://www.aida64.com/driver-updates


--------[ SMART ]-------------------------------------------------------------------------------------------------------

  [ SAMSUNG HD501LJ (S0Q9J1DP900209) ]

    01  Raw Read Error Rate                  51   253  100           0  OK:  
    03  Spinup Time                          15   100  100        7104  OK:  
    04  Start/Stop Count                     0    93   93         7685  OK:  
    05  Reallocated Sector Count             10   98   98           19  OK:  
    07  Seek Error Rate                      51   253  253           0  OK:  
    08  Seek Time Performance                15   253  253           0  OK:  
    09  Power-On Time Count                  0    100  100       25631  OK:  
    0A  Spinup Retry Count                   51   253  253           0  OK:  
    0B  Calibration Retry Count              0    253  100           0  OK:  
    0C  Power Cycle Count                    0    97   97         3284  OK:  
    BB  Reported Uncorrectable Errors        0    253  253           0  OK:  
    BC  Command Timeout                      0    253  253           0  OK:  
    BE  Airflow Temperature                  0    71   52           29  OK:  
    C2  Temperature                          0    151  94           29  OK:  
    C3  Hardware ECC Recovered               0    100  100      101749  OK:  
    C4  Reallocation Event Count             0    98   98           19  OK:  
    C5  Current Pending Sector Count         0    253  253           0  OK:  
    C6  Offline Uncorrectable Sector Count   0    253  253           0  OK:  
    C7  Ultra ATA CRC Error Rate             0    200  200           0  OK:  
    C8  Write Error Rate                     0    253  100           0  OK:  
    C9  Soft Read Error Rate                 0    253  100           0  OK:  
    CA  Data Address Mark Errors             0    253  253           0  OK:  

  [ TOSHIBA A100 (Y6MB406EKQ7U) ]

    09  Power-On Hours Count                 0    100  100        4760  OK:  
    0C  Power Cycle Count                    0    100  100         429  OK:  
    A7  SSD Protect Mode                     0    100  100           0  OK:  
    A8  SATA PHY Error Count                 0    100  100           0  OK:  
    A9  Total Bad Block Count                10   100  100           0  OK:  
    AD  Erase Count                          0    189  189           0  OK:  
    C0  Unexpected Power Loss Count          0    100  100          72  OK:  
    C2  Temperature                          20   69   63   37, 21, 31  OK:  


--------[  Windows ]------------------------------------------------------------------------------------------------

  [ Realtek PCIe GBE Family Controller ]

      :
                                          Realtek PCIe GBE Family Controller
                                           Ethernet
                                         00-1D-7D-D1-18-9E
                                                 
                                      100 Mbps
      MTU                                               1500 
      DHCP-                               06.05.2018 20:56:37
      DHCP-                               06.05.2018 22:56:37
                                            13959479949 (13312.8 )
                                          1076201126 (1026.3 )

      :
      IP /                                  [ TRIAL VERSION ]
                                                    [ TRIAL VERSION ]
      DHCP                                              [ TRIAL VERSION ]
      DNS                                               [ TRIAL VERSION ]

      :
                                                   Realtek Semiconductor Corp.
                                     http://www.realtek.com.tw/products/productsView.aspx?Langid=1&PNid=7&PFid=10&Level=3&Conn=2
                                       http://www.realtek.com.tw/downloads
                                     http://www.aida64.com/driver-updates


--------[  PCI / PnP ]----------------------------------------------------------------------------------------------

    Realtek RTL8168B/8111B PCI-E Gigabit Ethernet Adapter (PHY: Realtek RTL8211/8212)  PCI


--------[  ]----------------------------------------------------------------------------------------------------

     :
                                        https://yandex.ua/time/
                                          http://go.microsoft.com/fwlink/?LinkId=54896
                                       C:\Windows\system32\blank.htm
                               C:\Users\Pavel\Downloads

     :
                                            

    LAN-:
                                            


--------[  ]----------------------------------------------------------------------------------------------------

                  0.0.0.0          0.0.0.0      192.168.0.1  20   192.168.0.101 (Realtek PCIe GBE Family Controller)
                127.0.0.0        255.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  306  [ TRIAL VERSION ]
          127.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
              192.168.0.0    255.255.255.0    192.168.0.101  276  192.168.0.101 (Realtek PCIe GBE Family Controller)
          [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  276  [ TRIAL VERSION ]
            192.168.0.255  255.255.255.255    192.168.0.101  276  192.168.0.101 (Realtek PCIe GBE Family Controller)
                224.0.0.0        240.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  276  [ TRIAL VERSION ]
          255.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          255.255.255.255  255.255.255.255    192.168.0.101  276  192.168.0.101 (Realtek PCIe GBE Family Controller)


--------[  DirectX ]-----------------------------------------------------------------------------------------------

    amstream.dll                              6.06.7601.17514   Final Retail                         70656  21.11.2010 6:24:00
    bdaplgin.ax                               6.01.7600.16385   Final Retail                         74240  14.07.2009 4:14:10
    d2d1.dll                                  6.02.9200.16765   Final Retail  Russian                     3419136  26.11.2013 11:16:52
    d3d10.dll                                 6.02.9200.16492   Final Retail  English                     1080832  27.12.2017 3:58:20
    d3d10_1.dll                               6.02.9200.16492   Final Retail  English                      161792  27.12.2017 3:58:20
    d3d10_1core.dll                           6.02.9200.16492   Final Retail  English                      249856  27.12.2017 3:58:20
    d3d10core.dll                             6.02.9200.16492   Final Retail  English                      220160  27.12.2017 3:58:20
    d3d10level9.dll                           6.02.9200.21830   Final Retail  English                      603648  14.04.2016 16:49:14
    d3d10warp.dll                             6.02.9200.17033   Final Retail  English                     1987584  30.07.2015 20:57:32
    d3d11.dll                                 6.02.9200.16570   Final Retail  English                     1505280  27.12.2017 3:55:54
    d3d8.dll                                  6.01.7600.16385   Final Retail                    1036800  14.07.2009 4:15:08
    d3d8thk.dll                               6.01.7600.16385   Final Retail                      11264  14.07.2009 4:15:08
    d3d9.dll                                  6.01.7601.17514   Final Retail                    1828352  21.11.2010 6:24:23
    d3dim.dll                                 6.01.7600.16385   Final Retail                     386048  14.07.2009 4:15:08
    d3dim700.dll                              6.01.7600.16385   Final Retail                     817664  14.07.2009 4:15:08
    d3dramp.dll                               6.01.7600.16385   Final Retail                     593920  14.07.2009 4:15:08
    d3dxof.dll                                6.01.7600.16385   Final Retail                      53760  14.07.2009 4:15:08
    ddraw.dll                                 6.01.7600.16385   Final Retail                        531968  14.07.2009 4:15:10
    ddrawex.dll                               6.01.7600.16385   Final Retail                      30208  14.07.2009 4:15:10
    devenum.dll                               6.06.7601.19091   Final Retail                         67584  09.12.2015 0:53:41
    dinput.dll                                6.01.7600.16385   Final Retail                        136704  14.07.2009 4:15:11
    dinput8.dll                               6.01.7600.16385   Final Retail                        145408  14.07.2009 4:15:11
    dmband.dll                                6.01.7600.16385   Final Retail                      30720  14.07.2009 4:15:12
    dmcompos.dll                              6.01.7600.16385   Final Retail                      63488  14.07.2009 4:15:12
    dmime.dll                                 6.01.7600.16385   Final Retail                     179712  14.07.2009 4:15:12
    dmloader.dll                              6.01.7600.16385   Final Retail                      38400  14.07.2009 4:15:12
    dmscript.dll                              6.01.7600.16385   Final Retail                      86016  14.07.2009 4:15:12
    dmstyle.dll                               6.01.7600.16385   Final Retail                     105984  14.07.2009 4:15:12
    dmsynth.dll                               6.01.7600.16385   Final Retail                     105472  14.07.2009 4:15:12
    dmusic.dll                                6.01.7600.16385   Final Retail                        101376  14.07.2009 4:15:12
    dplaysvr.exe                              6.01.7600.16385   Final Retail                         29184  14.07.2009 4:14:18
    dplayx.dll                                6.01.7600.16385   Final Retail                     213504  14.07.2009 4:15:12
    dpmodemx.dll                              6.01.7600.16385   Final Retail                         23040  14.07.2009 4:15:12
    dpnaddr.dll                               6.01.7601.17514   Final Retail                       2560  21.11.2010 6:23:53
    dpnathlp.dll                              6.01.7600.16385   Final Retail  English                       57344  14.07.2009 4:15:14
    dpnet.dll                                 6.01.7601.17989   Final Retail                        376832  02.11.2012 8:11:31
    dpnhpast.dll                              6.01.7600.16385   Final Retail                       7168  14.07.2009 4:15:12
    dpnhupnp.dll                              6.01.7600.16385   Final Retail                       7168  14.07.2009 4:15:12
    dpnlobby.dll                              6.01.7600.16385   Final Retail                       2560  14.07.2009 4:04:52
    dpnsvr.exe                                6.01.7600.16385   Final Retail                         33280  14.07.2009 4:14:18
    dpwsockx.dll                              6.01.7600.16385   Final Retail                         44032  14.07.2009 4:15:12
    dsdmo.dll                                 6.01.7600.16385   Final Retail                     173568  14.07.2009 4:15:13
    dsound.dll                                6.01.7600.16385   Final Retail                        453632  14.07.2009 4:15:13
    dswave.dll                                6.01.7600.16385   Final Retail                      20992  14.07.2009 4:15:13
    dwrite.dll                                6.02.9200.22164   Final Retail  Russian                     1251328  12.05.2017 19:25:42
    dxdiagn.dll                               6.01.7601.17514   Final Retail                        210432  21.11.2010 6:24:22
    dxgi.dll                                  6.02.9200.16492   Final Retail  English                      293376  27.12.2017 3:58:20
    dxmasf.dll                                12.00.7601.23930  Final Retail                       4096  12.10.2017 3:24:38
    dxtmsft.dll                               11.00.9600.18921  Final Retail  English                      416256  10.02.2018 8:42:56
    dxtrans.dll                               11.00.9600.18921  Final Retail  English                      279040  10.02.2018 8:35:06
    dxva2.dll                                 6.01.7600.16385   Final Retail  English                       88064  14.07.2009 4:15:14
    encapi.dll                                6.01.7600.16385   Final Retail                      20992  14.07.2009 4:15:14
    gcdef.dll                                 6.01.7600.16385   Final Retail                        120832  14.07.2009 4:15:22
    iac25_32.ax                               2.00.0005.0053    Final Retail                        197632  14.07.2009 4:14:10
    ir41_32.ax                                4.51.0016.0003    Final Retail                        839680  14.07.2009 4:14:10
    ir41_qc.dll                               4.30.0062.0002    Final Retail                     120320  14.07.2009 4:15:34
    ir41_qcx.dll                              4.30.0062.0002    Final Retail                     120320  14.07.2009 4:15:34
    ir50_32.dll                               5.2562.0015.0055  Final Retail                        746496  14.07.2009 4:15:34
    ir50_qc.dll                               5.00.0063.0048    Final Retail                     200192  14.07.2009 4:15:34
    ir50_qcx.dll                              5.00.0063.0048    Final Retail                     200192  14.07.2009 4:15:34
    ivfsrc.ax                                 5.10.0002.0051    Final Retail                        146944  14.07.2009 4:14:10
    joy.cpl                                   6.01.7600.16385   Final Retail                        138240  14.07.2009 4:14:09
    ksproxy.ax                                6.01.7601.19091   Final Retail                        193536  09.12.2015 0:53:08
    kstvtune.ax                               6.01.7601.17514   Final Retail                         84480  21.11.2010 6:25:10
    ksuser.dll                                6.01.7601.19091   Final Retail                          4608  09.12.2015 0:53:47
    kswdmcap.ax                               6.01.7601.17514   Final Retail                        107008  21.11.2010 6:24:15
    ksxbar.ax                                 6.01.7601.17514   Final Retail                         48640  21.11.2010 6:25:10
    mciqtz32.dll                              6.06.7601.17514   Final Retail                         36352  21.11.2010 6:24:00
    mfc40.dll                                 4.01.0000.6151    Beta Retail                         954752  21.11.2010 6:24:00
    mfc42.dll                                 6.06.8064.0000    Beta Retail                        1137664  11.03.2011 8:33:59
    Microsoft.DirectX.AudioVideoPlayback.dll  5.04.0000.2904    Final Retail                      53248  27.12.2017 15:21:03
    Microsoft.DirectX.Diagnostics.dll         5.04.0000.2904    Final Retail                      12800  27.12.2017 15:21:03
    Microsoft.DirectX.Direct3D.dll            9.05.0132.0000    Final Retail                     473600  27.12.2017 15:21:03
    Microsoft.DirectX.Direct3DX.dll           5.04.0000.3900    Final Retail                    2676224  27.12.2017 15:21:00
    Microsoft.DirectX.Direct3DX.dll           9.04.0091.0000    Final Retail                    2846720  27.12.2017 15:21:00
    Microsoft.DirectX.Direct3DX.dll           9.05.0132.0000    Final Retail                     563712  27.12.2017 15:21:00
    Microsoft.DirectX.Direct3DX.dll           9.06.0168.0000    Final Retail                     567296  27.12.2017 15:21:00
    Microsoft.DirectX.Direct3DX.dll           9.07.0239.0000    Final Retail                     576000  27.12.2017 15:21:00
    Microsoft.DirectX.Direct3DX.dll           9.08.0299.0000    Final Retail                     577024  27.12.2017 15:21:00
    Microsoft.DirectX.Direct3DX.dll           9.09.0376.0000    Final Retail                     577536  27.12.2017 15:21:00
    Microsoft.DirectX.Direct3DX.dll           9.10.0455.0000    Final Retail                     577536  27.12.2017 15:21:00
    Microsoft.DirectX.Direct3DX.dll           9.11.0519.0000    Final Retail                     578560  27.12.2017 15:21:00
    Microsoft.DirectX.Direct3DX.dll           9.12.0589.0000    Final Retail                     578560  27.12.2017 15:21:03
    Microsoft.DirectX.DirectDraw.dll          5.04.0000.2904    Final Retail                     145920  27.12.2017 15:21:03
    Microsoft.DirectX.DirectInput.dll         5.04.0000.2904    Final Retail                     159232  27.12.2017 15:21:03
    Microsoft.DirectX.DirectPlay.dll          5.04.0000.2904    Final Retail                     364544  27.12.2017 15:21:03
    Microsoft.DirectX.DirectSound.dll         5.04.0000.2904    Final Retail                     178176  27.12.2017 15:21:03
    Microsoft.DirectX.dll                     5.04.0000.2904    Final Retail                     223232  27.12.2017 15:21:03
    mpeg2data.ax                              6.06.7601.17514   Final Retail                         72704  21.11.2010 6:25:10
    mpg2splt.ax                               6.06.7601.17528   Final Retail                     199680  23.12.2010 8:50:23
    msdmo.dll                                 6.06.7601.17514   Final Retail                      30720  21.11.2010 6:24:02
    msdvbnp.ax                                6.06.7601.17514   Final Retail                         59904  21.11.2010 6:25:10
    msvidctl.dll                              6.05.7601.23569   Final Retail                       2291712  07.10.2016 18:12:46
    msyuv.dll                                 6.01.7601.17514   Final Retail                      22528  21.11.2010 6:23:50
    pid.dll                                   6.01.7600.16385   Final Retail                      36352  14.07.2009 4:16:12
    psisdecd.dll                              6.06.7601.17669   Final Retail                        465408  17.08.2011 7:24:12
    psisrndr.ax                               6.06.7601.17669   Final Retail                         75776  17.08.2011 7:19:27
    qasf.dll                                  12.00.7601.19091  Final Retail                     206848  09.12.2015 0:53:54
    qcap.dll                                  6.06.7601.17514   Final Retail                        190976  21.11.2010 6:24:08
    qdv.dll                                   6.06.7601.17514   Final Retail                        283136  21.11.2010 6:24:09
    qdvd.dll                                  6.06.7601.23471   Final Retail                        519680  14.06.2016 18:21:34
    qedit.dll                                 6.06.7601.19091   Final Retail                        509952  09.12.2015 0:53:54
    qedwipes.dll                              6.06.7600.16385   Final Retail                     733184  14.07.2009 4:09:35
    quartz.dll                                6.06.7601.23709   Final Retail                       1329664  04.03.2017 4:14:51
    vbisurf.ax                                6.01.7601.17514   Final Retail                      33792  21.11.2010 6:25:10
    vfwwdm32.dll                              6.01.7601.17514   Final Retail                         56832  21.11.2010 6:24:09
    wsock32.dll                               6.01.7600.16385   Final Retail                         15360  14.07.2009 4:16:20


--------[ DirectX -  ]---------------------------------------------------------------------------------------------

  [   ]

     DirectDraw:
        DirectDraw                           display
        DirectDraw                       
                                       aticfx32.dll (8.17.10.1613)
                                      Radeon RX 560 Series

     Direct3D:
                                16, 32
        Z-                          16, 24, 32
      Multisample Anti-Aliasing Modes                   MSAA 2x, MSAA 4x, MSAA 8x
                               1 x 1
                              16384 x 16384
                              5.0
        DirectX                      DirectX v11.0

     Direct3D:
      Additive Texture Blending                         
      AGP Texturing                                     
      Anisotropic Filtering                             
      Automatic Mipmap Generation                       
      Bilinear Filtering                                
      Compute Shader                                    
      Cubic Environment Mapping                         
      Cubic Filtering                                    
      Decal-Alpha Texture Blending                      
      Decal Texture Blending                            
      Directional Lights                                
      DirectX Texture Compression                       
      DirectX Volumetric Texture Compression             
      Dithering                                         
      Dot3 Texture Blending                             
      Double-Precision Floating-Point                   
      Driver Concurrent Creates                         
      Driver Command Lists                               
      Dynamic Textures                                  
      Edge Anti-Aliasing                                 
      Environmental Bump Mapping                        
      Environmental Bump Mapping + Luminance            
      Factor Alpha Blending                             
      Geometric Hidden-Surface Removal                   
      Geometry Shader                                   
      Guard Band                                        
      Hardware Scene Rasterization                      
      Hardware Transform & Lighting                     
      Legacy Depth Bias                                 
      Map On Default Buffers                             
      Mipmap LOD Bias Adjustments                       
      Mipmapped Cube Textures                           
      Mipmapped Volume Textures                         
      Modulate-Alpha Texture Blending                   
      Modulate Texture Blending                         
      Non-Square Textures                               
      N-Patches                                          
      Perspective Texture Correction                    
      Point Lights                                      
      Point Sampling                                    
      Projective Textures                               
      Quintic Bezier Curves & B-Splines                  
      Range-Based Fog                                   
      Rectangular & Triangular Patches                   
      Rendering In Windowed Mode                        
      Runtime Shader Linking                             
      Scissor Test                                      
      Slope-Scale Based Depth Bias                      
      Specular Flat Shading                             
      Specular Gouraud Shading                          
      Specular Phong Shading                             
      Spherical Mapping                                 
      Spot Lights                                       
      Stencil Buffers                                   
      Sub-Pixel Accuracy                                
      Subtractive Texture Blending                      
      Table Fog                                         
      Texture Alpha Blending                            
      Texture Clamping                                  
      Texture Mirroring                                 
      Texture Transparency                              
      Texture Wrapping                                  
      Tiled Resources                                    
      Triangle Culling                                   
      Trilinear Filtering                               
      Two-Sided Stencil Test                            
      Vertex Alpha Blending                             
      Vertex Fog                                        
      Vertex Tweening                                   
      Volume Textures                                   
      W-Based Fog                                       
      W-Buffering                                        
      Z-Based Fog                                       
      Z-Bias                                            
      Z-Test                                            

      FourCC:
      ATIC                                              
      AYUV                                              
      CMSL                                              
      DXT1                                              
      DXT2                                              
      DXT3                                              
      DXT4                                              
      DXT5                                              
      FLGL                                              
      GET4                                              
      GINF                                              
      INST                                              
      M2IA                                              
      NULL                                              
      NV12                                              
      NV21                                              
      P010                                              
      R2VB                                              
      RESZ                                              
      SHDT                                              
      SYV2                                              
      UYVY                                              
      YUY2                                              
      YV12                                              

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates


--------[ DirectX -  ]----------------------------------------------------------------------------------------------

  [    ]

     DirectSound:
                                        
                                          
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [  (Realtek High Definition Audio) ]

     DirectSound:
                                       (Realtek High Definition Audio)
                                          {0.0.0.00000000}.{66c9a4b9-2191-472c-ada9-003b51e2cb26}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [ S/PDIF Pass-through Device (ASUS Xonar Essence STX Audio Device) ]

     DirectSound:
                                      S/PDIF Pass-through Device (ASUS Xonar Essence STX Audio Device)
                                          {0.0.0.00000000}.{d50c388a-4e2c-4842-9ee4-2d01723a38cd}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [ Realtek Digital Output (Realtek High Definition Audio) ]

     DirectSound:
                                      Realtek Digital Output (Realtek High Definition Audio)
                                          {0.0.0.00000000}.{d6f7888c-d41e-4d10-a600-05c4cce03548}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [  (ASUS Xonar Essence STX Audio Device) ]

     DirectSound:
                                       (ASUS Xonar Essence STX Audio Device)
                                          {0.0.0.00000000}.{f13fb3f2-4714-425f-87e5-f9c1c60286cb}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    


--------[  PCI ]----------------------------------------------------------------------------------------------

  [ AMD Baffin/Lexa - High Definition Audio Controller ]

     :
                                      AMD Baffin/Lexa - High Definition Audio Controller
                                                 PCI Express 3.0 x8
       /  /                        1 / 0 / 1
      ID                                      1002-AAE0
                               1043-AAE0
                                         0403 (High Definition Audio)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD Radeon RX 560 (Polaris 21) Video Adapter ]

     :
                                      AMD Radeon RX 560 (Polaris 21) Video Adapter
                                                 PCI Express 3.0 x8
       /  /                        1 / 0 / 0
      ID                                      1002-67FF
                               1043-04BC
                                         0300 (VGA Display Controller)
                                                  CF
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/en-us/products/graphics/desktop
                                       http://sites.amd.com/us/game/downloads
                                     http://www.aida64.com/driver-updates

  [ C-Media CMI8788 Audio Chip ]

     :
                                      C-Media CMI8788 Audio Chip
                                                 PCI
       /  /                        4 / 4 / 0
      ID                                      13F6-8788
                               1043-835C
                                         0401 (Audio Device)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Gigabyte GBB363 SATA-II RAID Controller ]

     :
                                      Gigabyte GBB363 SATA-II RAID Controller
                                                 PCI Express 1.0 x1
       /  /                        5 / 0 / 0
      ID                                      197B-2363
                               1458-B000
                                         0101 (IDE Controller)
                                                  02
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801IB I/O Controller Hub 9 (ICH9) [A-2] ]

     :
                                      Intel 82801IB I/O Controller Hub 9 (ICH9) [A-2]
                                                 PCI
       /  /                        0 / 30 / 0
      ID                                      8086-244E
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  92
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801IB ICH9 - 2-port SATA Controller [A-2] ]

     :
                                      Intel 82801IB ICH9 - 2-port SATA Controller [A-2]
                                                 PCI
       /  /                        0 / 31 / 2
      ID                                      8086-2921
                               1458-B002
                                         0101 (IDE Controller)
                                                  02
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ Intel 82801IB ICH9 - 2-port SATA Controller [A-2] ]

     :
                                      Intel 82801IB ICH9 - 2-port SATA Controller [A-2]
                                                 PCI
       /  /                        0 / 31 / 5
      ID                                      8086-2926
                               1458-B002
                                         0101 (IDE Controller)
                                                  02
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ Intel 82801IB ICH9 - High Definition Audio Controller [A-2] ]

     :
                                      Intel 82801IB ICH9 - High Definition Audio Controller [A-2]
                                                 PCI Express 1.0
       /  /                        0 / 27 / 0
      ID                                      8086-293E
                               1458-A002
                                         0403 (High Definition Audio)
                                                  02
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801IB ICH9 - PCI Express Root Port 1 [A-2] ]

     :
                                      Intel 82801IB ICH9 - PCI Express Root Port 1 [A-2]
                                                 PCI
       /  /                        0 / 28 / 0
      ID                                      8086-2940
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  02
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801IB ICH9 - PCI Express Root Port 2 [A-2] ]

     :
                                      Intel 82801IB ICH9 - PCI Express Root Port 2 [A-2]
                                                 PCI
       /  /                        0 / 28 / 1
      ID                                      8086-2942
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  02
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801IB ICH9 - PCI Express Root Port 4 [A-2] ]

     :
                                      Intel 82801IB ICH9 - PCI Express Root Port 4 [A-2]
                                                 PCI
       /  /                        0 / 28 / 3
      ID                                      8086-2946
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  02
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801IB ICH9 - PCI Express Root Port 5 [A-2] ]

     :
                                      Intel 82801IB ICH9 - PCI Express Root Port 5 [A-2]
                                                 PCI
       /  /                        0 / 28 / 4
      ID                                      8086-2948
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  02
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801IB ICH9 - SMBus Controller [A-2] ]

     :
                                      Intel 82801IB ICH9 - SMBus Controller [A-2]
                                                 PCI
       /  /                        0 / 31 / 3
      ID                                      8086-2930
                               1458-5001
                                         0C05 (SMBus Controller)
                                                  02
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801IB ICH9 - USB Universal Host Controller [A-2] ]

     :
                                      Intel 82801IB ICH9 - USB Universal Host Controller [A-2]
                                                 PCI
       /  /                        0 / 26 / 0
      ID                                      8086-2937
                               1458-5004
                                         0C03 (USB Controller)
                                                  02
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801IB ICH9 - USB Universal Host Controller [A-2] ]

     :
                                      Intel 82801IB ICH9 - USB Universal Host Controller [A-2]
                                                 PCI
       /  /                        0 / 26 / 1
      ID                                      8086-2938
                               1458-5004
                                         0C03 (USB Controller)
                                                  02
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801IB ICH9 - USB Universal Host Controller [A-2] ]

     :
                                      Intel 82801IB ICH9 - USB Universal Host Controller [A-2]
                                                 PCI
       /  /                        0 / 26 / 2
      ID                                      8086-2939
                               1458-5004
                                         0C03 (USB Controller)
                                                  02
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801IB ICH9 - USB Universal Host Controller [A-2] ]

     :
                                      Intel 82801IB ICH9 - USB Universal Host Controller [A-2]
                                                 PCI
       /  /                        0 / 29 / 0
      ID                                      8086-2934
                               1458-5004
                                         0C03 (USB Controller)
                                                  02
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801IB ICH9 - USB Universal Host Controller [A-2] ]

     :
                                      Intel 82801IB ICH9 - USB Universal Host Controller [A-2]
                                                 PCI
       /  /                        0 / 29 / 1
      ID                                      8086-2935
                               1458-5004
                                         0C03 (USB Controller)
                                                  02
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801IB ICH9 - USB Universal Host Controller [A-2] ]

     :
                                      Intel 82801IB ICH9 - USB Universal Host Controller [A-2]
                                                 PCI
       /  /                        0 / 29 / 2
      ID                                      8086-2936
                               1458-5004
                                         0C03 (USB Controller)
                                                  02
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801IB ICH9 - USB2 Enhanced Host Controller [A-2] ]

     :
                                      Intel 82801IB ICH9 - USB2 Enhanced Host Controller [A-2]
                                                 PCI
       /  /                        0 / 26 / 7
      ID                                      8086-293C
                               1458-5006
                                         0C03 (USB2 EHCI Controller)
                                                  02
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801IB ICH9 - USB2 Enhanced Host Controller [A-2] ]

     :
                                      Intel 82801IB ICH9 - USB2 Enhanced Host Controller [A-2]
                                                 PCI
       /  /                        0 / 29 / 7
      ID                                      8086-293A
                               1458-5006
                                         0C03 (USB2 EHCI Controller)
                                                  02
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801IR ICH9 - LPC Bridge [A-2] ]

     :
                                      Intel 82801IR ICH9 - LPC Bridge [A-2]
                                                 PCI
       /  /                        0 / 31 / 0
      ID                                      8086-2918
                               1458-5001
                                         0601 (PCI/ISA Bridge)
                                                  02
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Intel G31/G33/P31/P35 Chipset - Memory Controller Hub [A-2] ]

     :
                                      Intel G31/G33/P31/P35 Chipset - Memory Controller Hub [A-2]
                                                 PCI
       /  /                        0 / 0 / 0
      ID                                      8086-29C0
                               1458-5000
                                         0600 (Host/PCI Bridge)
                                                  02
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel G31/G33/P31/P35 Chipset - PCI Express Graphics Root [A-2] ]

     :
                                      Intel G31/G33/P31/P35 Chipset - PCI Express Graphics Root [A-2]
                                                 PCI
       /  /                        0 / 1 / 0
      ID                                      8086-29C1
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  02
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ PLX Technology ExpressLane PEX 8112 PCI Express-to-PCI Bridge ]

     :
                                      PLX Technology ExpressLane PEX 8112 PCI Express-to-PCI Bridge
                                                 PCI
       /  /                        3 / 0 / 0
      ID                                      10B5-8112
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  AA
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Realtek RTL8168B/8111B PCI-E Gigabit Ethernet Adapter ]

     :
                                      Realtek RTL8168B/8111B PCI-E Gigabit Ethernet Adapter
                                                 PCI Express 1.0 x1
       /  /                        6 / 0 / 0
      ID                                      10EC-8168
                               1458-E000
                                         0200 (Ethernet Controller)
                                                  01
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

      :
                                                   Realtek Semiconductor Corp.
                                     http://www.realtek.com.tw/products/productsView.aspx?Langid=1&PNid=7&PFid=10&Level=3&Conn=2
                                       http://www.realtek.com.tw/downloads
                                     http://www.aida64.com/driver-updates


--------[  USB ]----------------------------------------------------------------------------------------------

  [  USB  (USB Keyboard) ]

     :
                                       USB 
      ID                                      046D-C31C
                                         03 / 01 (Human Interface Device)
                                      01
                                                  6400h
                                           Logitech
                                                 USB Keyboard
        USB                         1.10
                                         Low  (USB 1.1)

  [  USB  (USB OPTICAL MOUSE) ]

     :
                                       USB 
      ID                                      18F8-0F99
                                         03 / 01 (Human Interface Device)
                                      02
                                                  0100h
                                                 USB OPTICAL MOUSE
        USB                         1.10
                                         Low  (USB 1.1)

  [    USB (TS-RDP8) ]

     :
                                         USB
      ID                                      5453-5038
                                         08 / 06 (Mass Storage)
                                      50
                                                  0100h
                                           Transcend
                                                 TS-RDP8
                                           RDP800000000
        USB                         2.00
                                         High  (USB 2.0)

  [  USB  (Vimicro USB2.0 Camera) ]

     :
                                       USB 
      ID                                      0AC8-3420
                                         EF / 02 (Interface Association Descriptor)
                                      01
                                                  0100h
                                           Vimicro Corp.
                                                 Vimicro USB2.0 Camera
        USB                         2.00
                                         High  (USB 2.0)


--------[  ]------------------------------------------------------------------------------------------------

    Cmaudio8788                        Registry\Common\Run      C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.dll,CMICtrlWnd
    Cmaudio8788GX                      Registry\Common\Run      C:\Windows\syswow64\HsMgr.exe Envoke
    Cmaudio8788GX64                    Registry\Common\Run      C:\Windows\system\HsMgr64.exe Envoke
    RtHDVCpl                           Registry\Common\Run      C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s


--------[   ]-------------------------------------------------------------------------------------

    Adobe  [ TRIAL VERSION ]                                                                29.0.0.113    Adobe F [ TRIAL VERSION ]                     Adobe Systems Incorporated                
    Adobe  [ TRIAL VERSION ]                                                                29.0.0.140    Adobe F [ TRIAL VERSION ]                     Adobe Systems Incorporated                
    AMD Se [ TRIAL VERSION ]                                                                 1.00.0000    {731417 [ TRIAL VERSION ]                     Advanced Micro Devices, Inc.    2018-05-04
    AMD Se [ TRIAL VERSION ]                                                          2018.0425.4.41502    {F52C31 [ TRIAL VERSION ]                     ##COMPANY_NAME##                2018-05-04
    AMD So [ TRIAL VERSION ]                                                                    18.4.1    AMD Cat [ TRIAL VERSION ]                     Advanced Micro Devices, Inc.              
    ASUS X [ TRIAL VERSION ]                                                                              C-Media [ TRIAL VERSION ]                                                               
    Kaspersky Internet Security [ ()]                                          18.0.0.405    {5AAE61FF-858E-453E-B8F3-944618149975}                  2018-05-06
    Kaspersky Internet Security                                                             18.0.0.405    InstallWIX_{5AAE61FF-858E-453E-B8F3-944618149975}                      
    Microsoft .NET Framework 4.6.1 (RUS) [ ()]                                  4.6.01055    {395723E7-7D0C-3045-BC96-5FCA1EEFCD11}                    2017-12-27
    Microsoft .NET Framework 4.6.1 ()                                                 4.6.01055    {92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1049                        
    Microsoft .NET Framework 4.7.1                                                           4.7.02558    {E0C7523C-686B-3EE6-8FB1-CB4339E30EDD}        Microsoft Corporation           2018-02-18
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 [ ()]             9.0.30729    {2DFD8316-9EF1-3210-908C-4CB61961C1AC}        Microsoft Corporation           2018-04-27
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319                             10.0.30319    {DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}        Microsoft Corporation           2018-04-27
    Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24123                          14.0.24123.0    {2cbcedbb-f38c-48a3-a3e1-6c6fd821a7f4}        Microsoft Corporation                     
    Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24123                          14.0.24123.0    {206898cc-4b41-4d98-ac28-9f9ae57f91fe}        Microsoft Corporation                     
    Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.24123                           14.0.24123    {21134089-9B59-34C8-BE11-929D26AD5207}        Microsoft Corporation           2017-12-27
    Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.24123                              14.0.24123    {FDBE9DB4-7A91-3A28-B27E-705EF7CFAE57}        Microsoft Corporation           2017-12-27
    Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.24123                           14.0.24123    {03AC7A79-F8AF-38FC-9DA0-98DAB4F4B1CD}        Microsoft Corporation           2017-12-27
    Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.24123                              14.0.24123    {06AE3BCC-7612-39D3-9F3B-B6601D877D02}        Microsoft Corporation           2017-12-27
    Notepad++ (64-bit x64)                                                                       7.5.3    Notepad++                                     Notepad++ Team                            
    OpenAL                                                                                                OpenAL                                                                                  
    Pale Moon (x64 en-US)                                                                       27.8.3    Pale Moon (x64 en-US)                         Moonchild Productions                     
    Pale Moon 27.7.0a2 (x86 en-US)                                                            27.7.0a2    Pale Moon 27.7.0a2 (x86 en-US)                Moonchild Productions                     
    PingPlotter 5                                                                          5.5.11.4413    PingPlotter 5 5.5.11.4413                     Pingman Tools, LLC                        
    RaidCall                                                                          7.3.6-1.2.12972.172    RaidCall                                      raidcall.com.ru                           
    Realtek Ethernet Controller Driver                                                   7.88.617.2014    {8833FFB6-5B0C-4764-81AA-06DFEED9A476}        Realtek                         2017-12-31
    Realtek HDMI Audio Driver for ATI                                                       6.0.1.6650    {5449FB4F-1802-4D5B-A6D8-087DB1142147}        Realtek Semiconductor Corp.               
    Realtek High Definition Audio Driver []                                          6.0.1.6662    {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}        Realtek Semiconductor Corp.     2017-12-27
    Sapphire TRIXX 6.4.0                                                                         6.4.0    {54CE6A44-8553-4B78-9B07-AC88A9D581E8}_is1    Sapphire Technology             2017-12-29
    Skype,  8.19                                                                            8.19    Skype_is1                                     Skype Technologies S.A.         2018-04-27
    SpeedFan (remove only)                                                                                SpeedFan                                                                                
    TechPowerUp GPU-Z                                                                                     TechPowerUp GPU-Z                             TechPowerUp                               
    Trinity Media Player                                                                        2.2.16    Trinity Media Player_is1                      Trinity Company                 2018-03-23
    True Image 2013 [ ()]                                                       16.0.6514    {4E5DD560-1F36-4D15-B403-C4550A43A010}        Acronis                         2017-12-27
    Update [ TRIAL VERSION ]                                                                         1    {92FB6C [ TRIAL VERSION ]                     Microsoft Corporation                     
    Update [ TRIAL VERSION ]                                                                         1    {92FB6C [ TRIAL VERSION ]                     Microsoft Corporation                     
    Update [ TRIAL VERSION ]                                                                         1    {92FB6C [ TRIAL VERSION ]                     Microsoft Corporation                     
    Vivald [ TRIAL VERSION ]                                                              1.15.1147.36    Vivaldi [ TRIAL VERSION ]                     Vivaldi                         2017-12-30
    VLC me [ TRIAL VERSION ]                                                                     3.0.1    VLC med [ TRIAL VERSION ]                     VideoLAN                                  
    Vulkan [ TRIAL VERSION ]                                                                  1.0.65.0    VulkanR [ TRIAL VERSION ]                     LunarG, Inc.                              
    Vulkan [ TRIAL VERSION ]                                                                  1.1.70.0    VulkanR [ TRIAL VERSION ]                     LunarG, Inc.                              
    Wave E [ TRIAL VERSION ]                                                                   3.7.0.0    Wave Ed [ TRIAL VERSION ]                     AbyssMedia.com                  2018-03-21
    WinRAR [ TRIAL VERSION ]                                                                    4.20.0    WinRAR  [ TRIAL VERSION ]                     win.rar GmbH                              
    World  [ TRIAL VERSION ]                                                                              {1EAC1D [ TRIAL VERSION ]                     Wargaming.net                   2018-02-10
    World  [ TRIAL VERSION ]                                                                              {1EAC1D [ TRIAL VERSION ]                     Wargaming.net                   2018-05-06
    World  [ TRIAL VERSION ]                                                                              {1EAC1D [ TRIAL VERSION ]                     Wargaming.net                   2018-02-02


--------[  Windows ]----------------------------------------------------------------------------------------

      :
                                              Microsoft Windows 7 Ultimate
                                       [ TRIAL VERSION ]
      Winlogon Shell                                    explorer.exe
          (UAC)  
      UAC Remote Restrictions                           
                                   
      Windows Update Agent                              7.6.7601.23806 (win7sp1_ldr.170510-0600)

       (DEP, NX, EDB):
                                        
                                        
       ( )                       
       ( )                        


--------[   ]--------------------------------------------------------------------------------------------

    Microsoft Windows Defender                6.1.7600.16385(win7_rtm.090713-1255)


--------[   ]--------------------------------------------------------------------------------------

     :
                                    RTZ 2 ()
                            (UTC+03:00) , -, 
                               
                                    

    :
       (.)                                      
       (.)                                      Russian
       (ISO 639)                                    ru

    /:
       (.)                                    
       (.)                                    Russia
       (ISO 3166)                                 RU
                                               7

     :
        (.)                          
        (.)                          Russian Ruble
         (.)                   ?
         (ISO 4217)                RUB
                                      123456789,00 ?
                         -123456789,00 ?

    :
                                           H:mm:ss
                                       dd.MM.yyyy
                                        d MMMM yyyy '.'
                                       123456789,00
                          -123456789,00
                                            first; second; third
                                               0123456789

     :
                                       / 
                                           / 
                                              / 
                                           / 
                                            / 
                                            / 
                                        / 

    :
                                             / 
                                            / 
                                              / 
                                             / 
                                                / 
                                               / 
                                               / 
                                            / 
                                           / 
                                            / 
                                             / 
                                            / 

    :
                                            Gregorian (localized)
                                 A4
                                        

    :
      LCID 0419h ()                              ()


--------[  ]---------------------------------------------------------------------------------------------------

    ALLUSERSPROFILE           C:\ProgramData
    APPDATA                   C:\Users\Pavel\AppData\Roaming
    CommonProgramFiles(x86)   C:\Program Files (x86)\Common Files
    CommonProgramFiles        C:\Program Files (x86)\Common Files
    CommonProgramW6432        C:\Program Files\Common Files
    COMPUTERNAME              BEST
    ComSpec                   C:\Windows\system32\cmd.exe
    FP_NO_HOST_CHECK          NO
    HOMEDRIVE                 C:
    HOMEPATH                  \Users\Pavel
    LOCALAPPDATA              C:\Users\Pavel\AppData\Local
    LOGONSERVER               \\BEST
    NUMBER_OF_PROCESSORS      4
    OS                        Windows_NT
    Path                      C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Common Files\Acronis\SnapAPI\
    PATHEXT                   .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    PROCESSOR_ARCHITECTURE    x86
    PROCESSOR_ARCHITEW6432    AMD64
    PROCESSOR_IDENTIFIER      Intel64 Family 6 Model 15 Stepping 11, GenuineIntel
    PROCESSOR_LEVEL           6
    PROCESSOR_REVISION        0f0b
    ProgramData               C:\ProgramData
    ProgramFiles(x86)         C:\Program Files (x86)
    ProgramFiles              C:\Program Files (x86)
    ProgramW6432              C:\Program Files
    PSModulePath              C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
    PUBLIC                    C:\Users\Public
    SESSIONNAME               Console
    SystemDrive               C:
    SystemRoot                C:\Windows
    TEMP                      C:\Users\Pavel\AppData\Local\Temp
    TMP                       C:\Users\Pavel\AppData\Local\Temp
    USERDOMAIN                BEST
    USERNAME                  Pavel
    USERPROFILE               C:\Users\Pavel
    windir                    C:\Windows
    windows_tracing_flags     3
    windows_tracing_logfile   C:\BVTBin\Tests\installpackage\csilogfile.log


--------[   ]---------------------------------------------------------------------------------------------

  [ system.ini ]

    ; for 16-bit app support
    [386Enh]
    woafont=dosapp.fon
    EGA80WOA.FON=EGA80WOA.FON
    EGA40WOA.FON=EGA40WOA.FON
    CGA80WOA.FON=CGA80WOA.FON
    CGA40WOA.FON=CGA40WOA.FON
    
    [drivers]
    wave=mmdrv.dll
    timer=timer.drv
    
    [mci]

  [ win.ini ]

    ; for 16-bit app support
    [fonts]
    [extensions]
    [mci extensions]
    [files]
    [Mail]
    MAPI=1
    [MCI Extensions.BAK]
    3g2=MPEGVideo
    3gp=MPEGVideo
    3gp2=MPEGVideo
    3gpp=MPEGVideo
    aac=MPEGVideo
    adt=MPEGVideo
    adts=MPEGVideo
    m2t=MPEGVideo
    m2ts=MPEGVideo
    m2v=MPEGVideo
    m4a=MPEGVideo
    m4v=MPEGVideo
    mod=MPEGVideo
    mov=MPEGVideo
    mp4=MPEGVideo
    mp4v=MPEGVideo
    mts=MPEGVideo
    ts=MPEGVideo
    tts=MPEGVideo

  [ hosts ]

    

  [ lmhosts.sam ]

    
    
    
    


--------[   ]---------------------------------------------------------------------------------------------

    Administrative Tools         C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    AppData                      C:\Users\Pavel\AppData\Roaming
    Cache                        C:\Users\Pavel\AppData\Local\Microsoft\Windows\Temporary Internet Files
    CD Burning                   C:\Users\Pavel\AppData\Local\Microsoft\Windows\Burn\Burn
    Common Administrative Tools  C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    Common AppData               C:\ProgramData
    Common Desktop               C:\Users\Public\Desktop
    Common Documents             C:\Users\Public\Documents
    Common Favorites             C:\Users\Pavel\Favorites
    Common Files (x86)           C:\Program Files (x86)\Common Files
    Common Files                 C:\Program Files (x86)\Common Files
    Common Music                 C:\Users\Public\Music
    Common Pictures              C:\Users\Public\Pictures
    Common Programs              C:\ProgramData\Microsoft\Windows\Start Menu\Programs
    Common Start Menu            C:\ProgramData\Microsoft\Windows\Start Menu
    Common Startup               C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    Common Templates             C:\ProgramData\Microsoft\Windows\Templates
    Common Video                 C:\Users\Public\Videos
    Cookies                      C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Cookies
    Desktop                      C:\Users\Pavel\Desktop
    Device                       C:\Windows\inf
    Favorites                    C:\Users\Pavel\Favorites
    Fonts                        C:\Windows\Fonts
    History                      C:\Users\Pavel\AppData\Local\Microsoft\Windows\History
    Local AppData                C:\Users\Pavel\AppData\Local
    My Documents                 C:\Users\Pavel\Documents
    My Music                     C:\Users\Pavel\Music
    My Pictures                  C:\Users\Pavel\Pictures
    My Video                     C:\Users\Pavel\Videos
    NetHood                      C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Network Shortcuts
    PrintHood                    C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
    Profile                      C:\Users\Pavel
    Program Files (x86)          C:\Program Files (x86)
    Program Files                C:\Program Files (x86)
    Programs                     C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
    Recent                       C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Recent
    Resources                    C:\Windows\resources
    SendTo                       C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\SendTo
    Start Menu                   C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu
    Startup                      C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    System (x86)                 C:\Windows\SysWOW64
    System                       C:\Windows\system32
    Temp                         C:\Users\Pavel\AppData\Local\Temp\
    Templates                    C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Templates
    Windows                      C:\Windows


--------[   ]-------------------------------------------------------------------------------------------

                         2018-04-30 08:40:29                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2018-04-30 15:56:23                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2018-04-30 15:59:16                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2018-04-30 18:14:15                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2018-05-01 20:30:21                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2018-05-02 09:02:57                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2018-05-02 21:14:01                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2018-05-02 21:17:09                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2018-05-03 08:46:11                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2018-05-03 21:09:23                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2018-05-04 08:18:32                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2018-05-04 21:04:57                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2018-05-05 07:41:31                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2018-05-06 08:02:02                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2018-05-06 10:16:02                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2018-05-06 10:58:20                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
      Audit Success   12545      2018-04-29 23:15:20                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x2fa04      ,   .  ,  ,  .        .  
      Audit Success   103        2018-04-29 23:15:21                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2018-04-30 08:38:40                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2018-04-30 08:38:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 08:38:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x354    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 08:38:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x354    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-04-30 08:38:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-04-30 08:38:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2018-04-30 08:38:40                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xdcf0  
      Audit Success   12544      2018-04-30 08:38:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x354    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 08:38:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x354    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 08:38:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x354    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-04-30 08:38:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-04-30 08:38:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-04-30 08:38:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-04-30 08:38:45                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Pavel     :  BEST   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x3a0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2018-04-30 08:38:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x322e3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x3a0    :  C:\Windows\System32\winlogon.exe      :     : BEST     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 08:38:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x354    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-04-30 08:38:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x322e3    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-04-30 08:38:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-04-30 08:38:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3c060   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 08:38:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x354    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-04-30 08:38:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2018-04-30 08:46:02                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x490   :  C:\Windows\System32\svchost.exe     :  2018-04-30T05:46:02.108384400Z   :  2018-04-30T05:46:02.108000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2018-04-30 09:56:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x354    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 09:56:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x354    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-04-30 09:56:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-04-30 09:56:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2018-04-30 11:14:01                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-04-30 11:14:01                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12290      2018-04-30 11:16:56                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-04-30 11:16:56                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12544      2018-04-30 14:22:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x354    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-04-30 14:22:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2018-04-30 15:06:52                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12545      2018-04-30 15:06:52                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x322e3      ,   .  ,  ,  .        .  
      Audit Success   12288      2018-04-30 15:56:21                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x2ca12      :    : 0xc7c   :  C:\Windows\System32\rundll32.exe     :  2007-12-31T21:02:43.415989600Z   :  2018-04-30T12:56:21.000000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2018-04-30 15:56:21                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x2ca12      :    : 0xc7c   :  C:\Windows\System32\rundll32.exe     :  2018-04-30T12:56:21.003750100Z   :  2018-04-30T12:56:21.000000000Z          .    Windows,    ,    .           .  
      Audit Success   12545      2018-04-30 15:56:43                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x2ca12      ,   .  ,  ,  .        .  
      Audit Success   103        2018-04-30 15:56:44                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2018-04-30 15:57:27                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2018-04-30 15:57:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 15:57:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 15:57:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-04-30 15:57:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-04-30 15:57:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2018-04-30 15:57:27                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xdce0  
      Audit Success   12544      2018-04-30 15:57:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 15:57:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-04-30 15:57:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-04-30 15:57:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-04-30 15:57:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-04-30 15:57:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-04-30 15:57:32                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Pavel     :  BEST   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x328    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2018-04-30 15:57:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x2e2de   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x328    :  C:\Windows\System32\winlogon.exe      :     : BEST     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 15:57:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-04-30 15:57:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x2e2de    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-04-30 15:57:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-04-30 15:57:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3758f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 15:57:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-04-30 15:57:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2018-04-30 16:49:57                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-04-30 16:49:57                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12290      2018-04-30 16:50:44                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-04-30 16:50:44                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12290      2018-04-30 16:53:23                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-04-30 16:53:23                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12290      2018-04-30 16:53:33                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-04-30 16:53:33                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12545      2018-04-30 17:37:50                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x2e2de      ,   .  ,  ,  .        .  
      Audit Success   103        2018-04-30 17:37:51                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2018-04-30 18:12:26                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2018-04-30 18:12:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 18:12:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 18:12:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-04-30 18:12:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-04-30 18:12:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2018-04-30 18:12:26                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xdfb7  
      Audit Success   12544      2018-04-30 18:12:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 18:12:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-04-30 18:12:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-04-30 18:12:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-04-30 18:12:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-04-30 18:12:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-04-30 18:12:31                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Pavel     :  BEST   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x358    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2018-04-30 18:12:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x31708   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x358    :  C:\Windows\System32\winlogon.exe      :     : BEST     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 18:12:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-04-30 18:12:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x31708    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-04-30 18:12:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-04-30 18:12:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3cf15   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 18:12:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-04-30 18:12:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2018-04-30 18:12:53                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-04-30 18:12:53                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12290      2018-04-30 18:27:04                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-04-30 18:27:04                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12290      2018-04-30 18:33:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-04-30 18:33:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12290      2018-04-30 18:38:01                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-04-30 18:38:01                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12290      2018-04-30 18:40:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-04-30 18:40:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12290      2018-04-30 19:16:29                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-04-30 19:16:29                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12290      2018-04-30 19:17:47                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-04-30 19:17:47                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12544      2018-04-30 20:32:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-04-30 20:32:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-04-30 20:32:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-04-30 20:32:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2018-04-30 22:51:39                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x31708      ,   .  ,  ,  .        .  
      Audit Success   103        2018-04-30 22:51:40                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2018-05-01 20:28:32                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2018-05-01 20:28:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-01 20:28:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x350    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-01 20:28:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x350    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-01 20:28:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-01 20:28:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2018-05-01 20:28:32                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xe0ab  
      Audit Success   12544      2018-05-01 20:28:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x350    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-01 20:28:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x350    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-01 20:28:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x350    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-01 20:28:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-01 20:28:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-01 20:28:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-01 20:28:37                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Pavel     :  BEST   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x368    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2018-05-01 20:28:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x31eb6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x368    :  C:\Windows\System32\winlogon.exe      :     : BEST     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-01 20:28:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x350    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-01 20:28:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x31eb6    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-01 20:28:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-01 20:28:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3e0e0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-01 20:28:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x350    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-01 20:28:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2018-05-01 20:28:58                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-05-01 20:28:58                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12544      2018-05-01 20:33:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x350    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-01 20:33:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2018-05-01 21:08:57                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12545      2018-05-01 21:08:57                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x31eb6      ,   .  ,  ,  .        .  
      Audit Success   12288      2018-05-02 09:01:08                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2018-05-02 09:01:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-02 09:01:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x34c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-02 09:01:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x34c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 09:01:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-02 09:01:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2018-05-02 09:01:08                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xe0a0  
      Audit Success   12544      2018-05-02 09:01:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x34c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-02 09:01:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x34c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 09:01:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-02 09:01:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-02 09:01:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x34c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 09:01:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-02 09:01:13                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Pavel     :  BEST   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x364    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2018-05-02 09:01:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x328b0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x364    :  C:\Windows\System32\winlogon.exe      :     : BEST     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-02 09:01:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x34c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 09:01:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x328b0    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-02 09:01:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-02 09:01:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3ceeb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-02 09:01:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x34c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 09:01:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2018-05-02 09:01:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-05-02 09:01:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12544      2018-05-02 10:11:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x34c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-02 10:11:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x34c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 10:11:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-02 10:11:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-02 13:21:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x34c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 13:21:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-02 14:16:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x34c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 14:16:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-02 17:12:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x34c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 17:12:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-02 21:10:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x34c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 21:10:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2018-05-02 21:11:28                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x328b0      ,   .  ,  ,  .        .  
      Audit Success   103        2018-05-02 21:11:29                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2018-05-02 21:12:11                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2018-05-02 21:12:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-02 21:12:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-02 21:12:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-02 21:12:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 21:12:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-02 21:12:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-02 21:12:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2018-05-02 21:12:11                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xc927  
      Audit Success   12544      2018-05-02 21:12:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-02 21:12:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 21:12:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-02 21:12:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-02 21:12:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-02 21:12:13                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Pavel     :  BEST   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2018-05-02 21:12:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x37372   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :     : BEST     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 21:12:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-02 21:12:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x37372    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-02 21:12:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x411f8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-02 21:12:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 21:12:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2018-05-02 21:12:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-05-02 21:12:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12544      2018-05-02 21:14:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 21:14:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2018-05-02 21:14:36                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x37372      ,   .  ,  ,  .        .  
      Audit Success   103        2018-05-02 21:14:37                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2018-05-02 21:15:25                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2018-05-02 21:15:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-02 21:15:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-02 21:15:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 21:15:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-02 21:15:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2018-05-02 21:15:26                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xf222  
      Audit Success   12544      2018-05-02 21:15:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-02 21:15:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 21:15:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-02 21:15:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-02 21:15:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 21:15:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-02 21:15:31                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Pavel     :  BEST   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x394    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2018-05-02 21:15:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x37dca   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x394    :  C:\Windows\System32\winlogon.exe      :     : BEST     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-02 21:15:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 21:15:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x37dca    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-02 21:15:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-02 21:15:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x449c7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-02 21:15:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-02 21:15:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2018-05-02 21:15:52                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-05-02 21:15:52                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   103        2018-05-02 23:55:09                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12545      2018-05-02 23:55:09                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x37dca      ,   .  ,  ,  .        .  
      Audit Success   12288      2018-05-03 08:44:22                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2018-05-03 08:44:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-03 08:44:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-03 08:44:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2018-05-03 08:44:22                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xe3f5  
      Audit Success   12544      2018-05-03 08:44:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-03 08:44:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-03 08:44:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-03 08:44:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-03 08:44:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-03 08:44:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-03 08:44:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-03 08:44:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-03 08:44:28                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Pavel     :  BEST   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x364    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2018-05-03 08:44:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x332cb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x364    :  C:\Windows\System32\winlogon.exe      :     : BEST     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-03 08:44:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-03 08:44:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x332cb    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-03 08:44:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-03 08:44:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x44c26   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-03 08:44:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-03 08:44:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2018-05-03 08:44:49                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-05-03 08:44:49                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12544      2018-05-03 10:27:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-03 10:27:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-03 10:27:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-03 10:27:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2018-05-03 21:07:34                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2018-05-03 21:07:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-03 21:07:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x33c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-03 21:07:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2018-05-03 21:07:34                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xe3a7  
      Audit Success   12544      2018-05-03 21:07:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x33c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-03 21:07:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-03 21:07:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x33c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-03 21:07:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2018-05-03 21:07:39                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2018-05-03 21:07:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x33c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-03 21:07:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x33c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-03 21:07:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-03 21:07:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-03 21:07:40                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Pavel     :  BEST   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x35c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2018-05-03 21:07:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x33186   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x35c    :  C:\Windows\System32\winlogon.exe      :     : BEST     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-03 21:07:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x33c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-03 21:07:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x33186    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-03 21:07:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-03 21:07:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x44917   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-03 21:07:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x33c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-03 21:07:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2018-05-03 21:08:02                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-05-03 21:08:02                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   103        2018-05-03 21:30:33                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12545      2018-05-03 21:30:33                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x33186      ,   .  ,  ,  .        .  
      Audit Success   12288      2018-05-04 08:16:43                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2018-05-04 08:16:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-04 08:16:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-04 08:16:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2018-05-04 08:16:43                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xe322  
      Audit Success   12544      2018-05-04 08:16:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-04 08:16:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-04 08:16:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-04 08:16:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-04 08:16:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-04 08:16:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-04 08:16:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-04 08:16:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-04 08:16:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Pavel     :  BEST   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x364    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2018-05-04 08:16:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x330b4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x364    :  C:\Windows\System32\winlogon.exe      :     : BEST     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-04 08:16:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-04 08:16:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x330b4    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-04 08:16:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-04 08:16:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x44c12   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-04 08:16:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-04 08:16:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2018-05-04 08:17:11                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-05-04 08:17:11                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12544      2018-05-04 09:41:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-04 09:41:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-04 09:41:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-04 09:41:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2018-05-04 12:19:12                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x48c   :  C:\Windows\System32\svchost.exe     :  2018-05-04T09:08:47.567302400Z   :  2018-05-04T09:19:12.415786300Z          .    Windows,    ,    .           .  
      Audit Success   12288      2018-05-04 12:19:12                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x48c   :  C:\Windows\System32\svchost.exe     :  2018-05-04T09:19:12.415786300Z   :  2018-05-04T09:19:12.415000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2018-05-04 14:29:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-04 14:29:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-04 20:53:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-04 20:53:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2018-05-04 21:03:11                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2018-05-04 21:03:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2018-05-04 21:03:11                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xd687  
      Audit Success   12544      2018-05-04 21:03:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-04 21:03:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-04 21:03:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-04 21:03:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-04 21:03:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-04 21:03:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-04 21:03:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-04 21:03:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-04 21:03:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-04 21:03:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2018-05-04 21:03:16                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2018-05-04 21:03:17                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Pavel     :  BEST   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x3b0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2018-05-04 21:03:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x35232   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x3b0    :  C:\Windows\System32\winlogon.exe      :     : BEST     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-04 21:03:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-04 21:03:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x35232    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-04 21:03:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-04 21:03:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x44e34   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-04 21:03:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-04 21:03:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2018-05-04 21:03:41                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-05-04 21:03:41                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12544      2018-05-04 21:04:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-04 21:04:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-04 22:45:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-04 22:45:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-04 22:45:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-04 22:45:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2018-05-04 23:33:45                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12545      2018-05-04 23:33:45                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x35232      ,   .  ,  ,  .        .  
      Audit Success   12288      2018-05-05 07:39:43                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2018-05-05 07:39:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-05 07:39:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-05 07:39:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2018-05-05 07:39:43                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xe383  
      Audit Success   12544      2018-05-05 07:39:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-05 07:39:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-05 07:39:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-05 07:39:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-05 07:39:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-05 07:39:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-05 07:39:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-05 07:39:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-05 07:39:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Pavel     :  BEST   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x364    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2018-05-05 07:39:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x34004   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x364    :  C:\Windows\System32\winlogon.exe      :     : BEST     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-05 07:39:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-05 07:39:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x34004    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-05 07:39:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-05 07:39:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x4589e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-05 07:39:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-05 07:39:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2018-05-05 07:40:11                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-05-05 07:40:11                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12288      2018-05-05 09:18:22                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x488   :  C:\Windows\System32\svchost.exe     :  2018-05-05T05:58:03.518870500Z   :  2018-05-05T06:18:22.338391900Z          .    Windows,    ,    .           .  
      Audit Success   12288      2018-05-05 09:18:22                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x488   :  C:\Windows\System32\svchost.exe     :  2018-05-05T06:18:22.338391900Z   :  2018-05-05T06:18:22.338000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2018-05-05 14:24:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-05 14:24:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-05 14:24:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-05 14:24:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-05 19:33:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-05 19:33:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-06 00:00:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-06 00:00:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x344    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 00:00:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-06 00:00:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2018-05-06 00:11:32                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x34004      ,   .  ,  ,  .        .  
      Audit Success   103        2018-05-06 00:11:33                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2018-05-06 00:11:33                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x488   :  C:\Windows\System32\svchost.exe     :  2018-05-05T21:11:33.421710600Z   :  2018-05-05T21:11:33.421000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2018-05-06 08:00:13                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2018-05-06 08:00:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-06 08:00:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x33c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 08:00:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2018-05-06 08:00:13                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xe454  
      Audit Success   12544      2018-05-06 08:00:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x33c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 08:00:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-06 08:00:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x33c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-06 08:00:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x33c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 08:00:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-06 08:00:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-06 08:00:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x33c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 08:00:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-06 08:00:19                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Pavel     :  BEST   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x360    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2018-05-06 08:00:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x33c2f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x360    :  C:\Windows\System32\winlogon.exe      :     : BEST     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-06 08:00:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x33c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 08:00:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x33c2f    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-06 08:00:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-06 08:00:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x45536   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-06 08:00:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x33c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 08:00:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2018-05-06 08:00:40                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-05-06 08:00:40                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12544      2018-05-06 08:18:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x33c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 08:18:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2018-05-06 08:42:29                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x33c2f      ,   .  ,  ,  .        .  
      Audit Success   103        2018-05-06 08:42:30                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2018-05-06 10:14:14                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2018-05-06 10:14:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-06 10:14:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-06 10:14:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 10:14:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-06 10:14:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2018-05-06 10:14:14                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xdfa8  
      Audit Success   12544      2018-05-06 10:14:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-06 10:14:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-06 10:14:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 10:14:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-06 10:14:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-06 10:14:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-06 10:14:20                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Pavel     :  BEST   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x368    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2018-05-06 10:14:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x34125   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x368    :  C:\Windows\System32\winlogon.exe      :     : BEST     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-06 10:14:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 10:14:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x34125    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-06 10:14:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-06 10:14:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3ea92   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-06 10:14:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 10:14:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2018-05-06 10:14:41                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-05-06 10:14:41                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12288      2018-05-06 10:20:44                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x488   :  C:\Windows\System32\svchost.exe     :  2018-05-06T07:20:44.809231700Z   :  2018-05-06T07:20:44.809000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2018-05-06 10:20:53                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x488   :  C:\Windows\System32\svchost.exe     :  2018-05-06T07:20:53.419508200Z   :  2018-05-06T07:20:53.419000000Z          .    Windows,    ,    .           .  
      Audit Success   103        2018-05-06 10:48:49                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2018-05-06 10:48:49                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x488   :  C:\Windows\System32\svchost.exe     :  2018-05-06T07:48:49.594671600Z   :  2018-05-06T07:48:49.594000000Z          .    Windows,    ,    .           .  
      Audit Success   12545      2018-05-06 10:48:49                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x34125      ,   .  ,  ,  .        .  
      Audit Success   12288      2018-05-06 10:56:31                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2018-05-06 10:56:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-06 10:56:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 10:56:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2018-05-06 10:56:31                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xe38b  
      Audit Success   12544      2018-05-06 10:56:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 10:56:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-06 10:56:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-06 10:56:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-06 10:56:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 10:56:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-06 10:56:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-06 10:56:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-06 10:56:37                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Pavel     :  BEST   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x360    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2018-05-06 10:56:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x38c68   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x360    :  C:\Windows\System32\winlogon.exe      :     : BEST     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-06 10:56:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 10:56:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2195854686-2160364349-280899491-1001     :  Pavel     :  BEST    :  0x38c68    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-06 10:56:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2018-05-06 10:56:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x4549b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-06 10:56:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 10:56:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2018-05-06 10:56:58                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2018-05-06 10:56:58                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 86cff15e-6c59-491d-adb5-7a1173e24720    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33d92844ee556fd8b806cc43ea17f7e_8292f746-b142-498c-830e-5249dab4b79d   : %%2458    : 0x0  
      Audit Success   12544      2018-05-06 15:36:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2018-05-06 15:36:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  BEST$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x340    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2018-05-06 15:36:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2018-05-06 15:36:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
                            2018-04-29 21:51:43  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1012:        .  
                            2018-04-29 22:53:01  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1012:        .  
                  212        2018-04-30 08:38:47                           Microsoft-Windows-Kernel-PnP    219: 
                          2018-04-30 08:38:53  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     isatap.mytrinity.com.ua        DNS.  
                            2018-04-30 11:13:50                                  Service Control Manager         7024:  "  "  -   %%-2147023143.  
                          2018-04-30 11:16:53  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     www.msftncsi.com        DNS.  
                            2018-04-30 11:17:10                                  NetBT                           4321:  "WORKGROUP      :1d"       IP- 192.168.0.101.    IP- 192.168.0.100    ,    .  
                          2018-04-30 11:17:22                                  bowser                          8005:    , ,   BEST     .        .  
                          2018-04-30 11:21:24                                  bowser                          8005:    , ,   BEST     .        .  
                          2018-04-30 14:05:12  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     1.0.168.192.in-addr.arpa        DNS.  
                          2018-04-30 14:42:25  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     1.0.168.192.in-addr.arpa        DNS.  
                            2018-04-30 16:49:41                                  Service Control Manager         7024:  "  "  -   %%-2147023143.  
                          2018-04-30 16:49:41  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     ipv6.msftncsi.com        DNS.  
                          2018-04-30 16:49:44  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     isatap.mytrinity.com.ua        DNS.  
                          2018-04-30 16:50:51  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     1.0.168.192.in-addr.arpa        DNS.  
                          2018-04-30 16:53:22  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     www.msftncsi.com        DNS.  
                          2018-04-30 16:53:31  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     ipv6.msftncsi.com        DNS.  
                          2018-04-30 16:56:15  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     1.0.168.192.in-addr.arpa        DNS.  
                  212        2018-04-30 18:12:32                           Microsoft-Windows-Kernel-PnP    219: 
                            2018-04-30 18:12:42                                  Service Control Manager         7024:  "  "  -   %%-2147023143.  
                          2018-04-30 18:24:46  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     1.0.168.192.in-addr.arpa        DNS.  
                          2018-04-30 18:31:53  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     1.0.168.192.in-addr.arpa        DNS.  
                            2018-04-30 18:37:59                                  Server                          2505:      \Device\NetBT_Tcpip_{2D0B62B2-6548-487B-B9FC-86AA58F88944},         .    .  
                            2018-04-30 18:37:59                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-04-30 18:37:59                                  NetBT                           4321:  "BEST           :20"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                          2018-04-30 18:38:27  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     1.0.168.192.in-addr.arpa        DNS.  
                          2018-04-30 18:40:33  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     vk.com        DNS.  
                          2018-04-30 18:40:38  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     vk.com        DNS.  
                          2018-04-30 19:16:31  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     login.p6.worldoftanks.net        DNS.  
                          2018-04-30 21:18:40  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     1.0.168.192.in-addr.arpa        DNS.  
                  212        2018-05-01 20:28:38                           Microsoft-Windows-Kernel-PnP    219: 
                            2018-05-01 20:28:47                                  Service Control Manager         7024:  "  "  -   %%-2147023143.  
                          2018-05-01 20:31:06  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     1.0.168.192.in-addr.arpa        DNS.  
                            2018-05-02 09:01:13                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 09:01:14                                  Server                          2505:      \Device\NetBT_Tcpip_{2D0B62B2-6548-487B-B9FC-86AA58F88944},         .    .  
                            2018-05-02 09:01:14                                  NetBT                           4321:  "BEST           :20"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                  212        2018-05-02 09:01:14                           Microsoft-Windows-Kernel-PnP    219: 
                            2018-05-02 09:01:23                                  Service Control Manager         7024:  "  "  -   %%-2147023143.  
                            2018-05-02 09:05:28                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 09:05:28                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 09:05:28                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 09:11:27                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 09:18:57                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 09:31:23                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 12:00:30                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 12:00:30                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 12:33:23                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 12:33:23                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                          2018-05-02 13:21:59  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     1.0.168.192.in-addr.arpa        DNS.  
                            2018-05-02 13:22:50                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:23:09                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:23:09                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:23:32                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:23:32                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:24:19                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:24:19                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:24:25                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:24:25                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:24:35                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:24:35                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:24:47                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:24:47                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:25:47                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:25:47                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:29:45                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:29:45                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:30:00                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:30:00                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:39:30                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:39:30                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:40:10                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 13:40:10                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 14:16:02                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 14:16:03                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 14:16:34                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                          2018-05-02 14:21:18  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     1.0.168.192.in-addr.arpa        DNS.  
                            2018-05-02 15:12:00                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 15:12:00                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 15:20:24                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 15:20:24                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 15:25:09                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 16:25:07                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 16:25:07                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                          2018-05-02 17:09:55  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     1.0.168.192.in-addr.arpa        DNS.  
                            2018-05-02 17:12:32                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:12:32                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:12:32                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:12:32                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:12:54                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:12:54                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:13:46                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:13:46                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:13:55                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:13:56                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:14:05                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:14:05                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:15:53                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:15:53                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:16:09                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:16:09                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:20:51                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:20:52                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:27:39                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:27:39                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:29:36                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:29:36                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:30:38                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:30:38                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:41:31                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:41:31                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:41:49                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:42:01                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:42:01                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:42:09                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 17:42:09                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:00:07                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:00:07                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:01:26                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:01:26                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:04:27                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:40:53                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:40:53                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:41:21                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:41:21                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:43:07                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:43:07                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:43:54                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:43:54                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:45:05                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:45:06                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:45:14                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:45:14                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:45:24                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:45:24                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:51:13                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:51:13                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:52:02                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:52:02                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:58:05                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:58:05                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:58:30                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:58:30                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:58:42                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 18:58:42                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 19:40:51                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 19:40:51                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 19:41:39                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 19:41:39                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 20:22:28                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 20:22:28                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 20:28:08                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 20:28:08                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 21:11:00                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 21:11:00                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 21:12:13                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 21:12:14                                  Server                          2505:      \Device\NetBT_Tcpip_{2D0B62B2-6548-487B-B9FC-86AA58F88944},         .    .  
                            2018-05-02 21:12:14                                  NetBT                           4321:  "BEST           :20"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                  212        2018-05-02 21:12:14                           Microsoft-Windows-Kernel-PnP    219: 
                            2018-05-02 21:12:24                                  Service Control Manager         7024:  "  "  -   %%-2147023143.  
                            2018-05-02 21:15:31                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 21:15:32                                  Server                          2505:      \Device\NetBT_Tcpip_{2D0B62B2-6548-487B-B9FC-86AA58F88944},         .    .  
                            2018-05-02 21:15:32                                  NetBT                           4321:  "BEST           :20"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                  212        2018-05-02 21:15:33                           Microsoft-Windows-Kernel-PnP    219: 
                            2018-05-02 21:15:41                                  Service Control Manager         7024:  "  "  -   %%-2147023143.  
                            2018-05-02 21:17:24                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 21:17:24                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 21:17:24                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 21:46:06                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 21:46:06                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 21:46:56                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 21:46:56                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 21:48:17                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 21:48:17                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 21:48:19                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 21:54:26                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 21:54:26                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 22:16:45                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 22:16:45                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 22:17:15                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 22:17:15                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 22:45:01                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 22:45:01                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 22:46:05                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 22:46:06                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:04:15                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:04:15                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:06:16                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:06:16                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:08:04                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:08:04                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:09:01                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:09:01                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:09:13                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:09:13                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:28:32                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:28:32                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:30:50                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:30:50                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:36:00                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:39:26                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:39:26                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:54:59                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-02 23:55:00                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 08:44:28                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 08:44:29                                  Server                          2505:      \Device\NetBT_Tcpip_{2D0B62B2-6548-487B-B9FC-86AA58F88944},         .    .  
                            2018-05-03 08:44:29                                  NetBT                           4321:  "BEST           :20"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                  212        2018-05-03 08:44:30                           Microsoft-Windows-Kernel-PnP    219: 
                            2018-05-03 08:44:37                                  Service Control Manager         7024:  "  "  -   %%-2147023143.  
                            2018-05-03 08:46:10                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 08:46:10                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 08:46:10                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 08:54:52                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 09:02:09                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 09:45:45                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 12:18:09                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 12:18:09                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 12:26:02                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 12:26:02                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 14:41:17                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 14:41:17                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 14:42:12                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 14:42:12                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 15:48:23                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 15:48:23                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 19:44:31                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 19:44:31                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 19:45:55                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 19:45:55                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 19:53:19                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 19:53:19                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 20:43:36                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 20:43:36                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 20:44:30                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 20:44:30                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-03 21:07:38                                  EventLog                        6008:      20:59:32  ?03.?05.?2018  .  
                  212        2018-05-03 21:07:42                           Microsoft-Windows-Kernel-PnP    219: 
                            2018-05-03 21:07:50                                  Service Control Manager         7024:  "  "  -   %%-2147023143.  
                            2018-05-04 08:16:49                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 08:16:50                                  Server                          2505:      \Device\NetBT_Tcpip_{2D0B62B2-6548-487B-B9FC-86AA58F88944},         .    .  
                            2018-05-04 08:16:50                                  NetBT                           4321:  "BEST           :20"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                  212        2018-05-04 08:16:51                           Microsoft-Windows-Kernel-PnP    219: 
                            2018-05-04 08:16:58                                  Service Control Manager         7024:  "  "  -   %%-2147023143.  
                            2018-05-04 08:18:31                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 08:18:31                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 08:18:31                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 08:27:02                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 08:34:42                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 09:03:53                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 09:17:09                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 12:20:11                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 12:20:11                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 12:22:00                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 12:22:00                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 12:22:52                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 12:22:52                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 12:29:46                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 12:29:46                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 12:39:17                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 12:39:17                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 14:03:49                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 14:03:49                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 14:04:24                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 14:04:24                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 14:04:38                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 14:04:38                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 14:06:41                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 14:06:41                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 14:06:51                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 14:06:51                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 14:26:31                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 14:26:32                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 14:31:03                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 14:31:03                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 14:38:57                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 14:38:57                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 18:45:57                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 18:45:57                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 20:53:35                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 20:53:35                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 20:55:25                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 20:55:25                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 20:57:12                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 20:57:12                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 21:03:15                                  EventLog                        6008:      21:12:47  ?04.?05.?2018  .  
                  212        2018-05-04 21:03:19                           Microsoft-Windows-Kernel-PnP    219: 
                            2018-05-04 21:03:30                                  Service Control Manager         7024:  "  "  -   %%-2147023143.  
                            2018-05-04 21:04:13                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 21:04:13                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 21:05:01                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 21:05:01                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 21:07:32                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 21:07:32                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 21:09:54                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-04 21:09:54                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 07:39:49                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 07:39:50                                  Server                          2505:      \Device\NetBT_Tcpip_{2D0B62B2-6548-487B-B9FC-86AA58F88944},         .    .  
                            2018-05-05 07:39:50                                  NetBT                           4321:  "BEST           :20"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                  212        2018-05-05 07:39:51                           Microsoft-Windows-Kernel-PnP    219: 
                            2018-05-05 07:39:59                                  Service Control Manager         7024:  "  "  -   %%-2147023143.  
                            2018-05-05 07:50:04                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 07:51:04                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 07:51:04                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 07:51:04                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 08:10:18                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 09:31:39                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 09:31:39                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 09:31:58                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 09:43:17                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 09:43:17                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 09:50:26                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 09:50:26                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 09:50:44                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 09:50:45                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 09:50:53                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 09:50:54                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 09:51:19                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 09:51:19                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 09:58:31                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 09:58:31                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 10:19:43                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 10:19:43                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 10:20:55                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 10:20:55                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 10:22:16                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 10:22:16                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 10:37:34                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 10:37:34                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 10:38:33                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 10:38:34                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 12:21:12                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 12:21:12                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 12:22:17                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-05 12:22:17                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 08:00:19                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 08:00:20                                  Server                          2505:      \Device\NetBT_Tcpip_{2D0B62B2-6548-487B-B9FC-86AA58F88944},         .    .  
                            2018-05-06 08:00:20                                  NetBT                           4321:  "BEST           :20"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                  212        2018-05-06 08:00:21                           Microsoft-Windows-Kernel-PnP    219: 
                            2018-05-06 08:00:29                                  Service Control Manager         7024:  "  "  -   %%-2147023143.  
                            2018-05-06 08:03:04                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 08:03:04                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 08:03:04                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 08:10:34                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 08:19:14                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 08:30:31                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 10:14:20                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 10:14:21                                  Server                          2505:      \Device\NetBT_Tcpip_{2D0B62B2-6548-487B-B9FC-86AA58F88944},         .    .  
                            2018-05-06 10:14:21                                  NetBT                           4321:  "BEST           :20"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                  212        2018-05-06 10:14:21                           Microsoft-Windows-Kernel-PnP    219: 
                            2018-05-06 10:14:30                                  Service Control Manager         7024:  "  "  -   %%-2147023143.  
                            2018-05-06 10:16:02                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 10:16:02                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 10:16:02                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 10:24:42                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 10:56:37                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 10:56:38                                  Server                          2505:      \Device\NetBT_Tcpip_{2D0B62B2-6548-487B-B9FC-86AA58F88944},         .    .  
                            2018-05-06 10:56:38                                  NetBT                           4321:  "BEST           :20"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                  212        2018-05-06 10:56:39                           Microsoft-Windows-Kernel-PnP    219: 
                            2018-05-06 10:56:47                                  Service Control Manager         7024:  "  "  -   %%-2147023143.  
                            2018-05-06 10:58:19                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 10:58:19                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 10:58:19                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 11:07:00                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 11:15:09                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:18:33                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:18:33                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:18:35                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:18:35                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:19:02                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:19:02                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:19:54                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:19:54                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:22:00                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:22:00                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:23:23                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:23:23                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:23:34                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:23:34                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:23:58                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:23:58                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:25:15                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:25:15                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:25:28                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:25:28                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:25:45                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:25:45                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:25:46                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:25:46                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:25:58                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:25:58                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:26:14                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:26:14                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:27:04                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:27:04                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:28:02                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:28:02                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:28:23                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:28:23                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:50:25                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:50:25                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:51:27                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 13:51:27                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 14:14:06                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 14:14:07                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 14:15:32                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 14:15:32                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 14:48:47                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 14:48:47                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 14:49:37                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 14:49:37                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 18:49:44                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 18:49:44                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 18:49:46                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 18:54:59                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 18:56:48                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 18:56:48                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 19:07:28                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 19:07:28                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 19:08:12                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 19:08:12                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 19:08:30                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 19:08:30                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 20:16:56                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 20:16:56                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 20:17:47                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  
                            2018-05-06 20:17:47                                  NetBT                           4321:  "BEST           :0"       IP- 192.168.0.101.    IP- 192.168.0.102    ,    .  


------------------------------------------------------------------------------------------------------------------------

The names of actual companies and products mentioned herein may be the trademarks of their respective owners.
