| Reportname: | System Status Report. | |
| Additional functions: | Collapse All Nodes |Expand All Nodes | |
| Input Parameter 1 | Number of records being dtestayed: Top 2000 | |
| Input Parameter 2 | Limited DetailEvents: Limited to 100 detail records | |
| Reported generated at: | Tuesday, July 15, 2003 - 12:53:28 PM |
| From Host | Event Log Type | Event Source | Event Id | Min Date | Max Date | Message | NT Severity | Count |
| 1180 |
| 9 |
| 1 |
| 1 |
| 3 |
| 1 |
| 1 |
| 1 |
| 1 |
| 1 |
| 1 |
| 1 |
| 1 |
| 1 |
| 2 |
| 2 |
| 1153 |
| 1153 |
| 2 |
| 3 |
| 3 |
| Details limited to 100 | 571 | |||||||
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 268 Operation ID: {0,814254} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:45:21 AM | Jul 15, 2003 11:45:21 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 884 Operation ID: {0,397803} Process ID: 1904 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:48:58 AM | Jul 15, 2003 11:48:58 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10\MSOHEV.DLL New Handle ID: 916 Operation ID: {0,447161} Process ID: 2464 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE Execute/Traverse Privileges - | Information | 1 |
| Jul 15, 2003 12:24:09 PM | Jul 15, 2003 12:24:09 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 852 Operation ID: {0,789196} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:19:14 AM | Jul 15, 2003 11:19:14 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_DOMAIN Object Name: Builtin New Handle ID: 889984 Operation ID: {0,68965} Process ID: 232 Primary User Name: testWS02$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS02$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses GetLocalGroupMembership LookupIDs Privileges - | Information | 1 |
| Jul 15, 2003 11:19:14 AM | Jul 15, 2003 11:19:14 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_SERVER Object Name: SAM New Handle ID: 723144 Operation ID: {0,69229} Process ID: 232 Primary User Name: testWS02$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS02$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses EnumerateDomains LookupDomain Privileges - | Information | 1 |
| Jul 15, 2003 11:45:20 AM | Jul 15, 2003 11:45:20 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 184 Operation ID: {0,396550} Process ID: 1904 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:24:09 PM | Jul 15, 2003 12:24:09 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 848 Operation ID: {0,789037} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 808 Operation ID: {0,710111} Process ID: 2376 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 808 Operation ID: {0,710084} Process ID: 2376 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 268 Operation ID: {0,814123} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 896 Operation ID: {0,711278} Process ID: 2376 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:19:57 AM | Jul 15, 2003 11:19:57 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10\MSOHEV.DLL New Handle ID: 1208 Operation ID: {0,152851} Process ID: 1184 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE Execute/Traverse Privileges - | Information | 1 |
| Jul 15, 2003 12:24:05 PM | Jul 15, 2003 12:24:05 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 268 Operation ID: {0,785183} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 896 Operation ID: {0,711209} Process ID: 2376 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 896 Operation ID: {0,711134} Process ID: 2376 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:45:21 AM | Jul 15, 2003 11:45:21 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 184 Operation ID: {0,396790} Process ID: 1904 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:24:09 PM | Jul 15, 2003 12:24:09 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 852 Operation ID: {0,789109} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:19:24 AM | Jul 15, 2003 11:19:24 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Yahoo!\Messenger New Handle ID: 968 Operation ID: {0,88715} Process ID: 1184 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:48:48 AM | Jul 15, 2003 11:48:48 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10\MSOHEV.DLL New Handle ID: 896 Operation ID: {0,438668} Process ID: 2392 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE Execute/Traverse Privileges - | Information | 1 |
| Jul 15, 2003 11:19:14 AM | Jul 15, 2003 11:19:14 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10\OUTLLIB.DLL New Handle ID: 480 Operation ID: {0,69273} Process ID: 1184 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE Execute/Traverse Privileges - | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 992 Operation ID: {0,815383} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:45:20 AM | Jul 15, 2003 11:45:20 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 184 Operation ID: {0,396659} Process ID: 1904 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 896 Operation ID: {0,711197} Process ID: 2376 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:19:37 AM | Jul 15, 2003 11:19:37 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Yahoo!\Messenger\res_msgr.dll New Handle ID: 200 Operation ID: {0,109298} Process ID: 1896 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE Execute/Traverse Privileges - | Information | 1 |
| Jul 15, 2003 11:19:14 AM | Jul 15, 2003 11:19:14 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_SERVER Object Name: SAM New Handle ID: 723144 Operation ID: {0,68956} Process ID: 232 Primary User Name: testWS02$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS02$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses EnumerateDomains LookupDomain Privileges - | Information | 1 |
| Jul 15, 2003 11:19:28 AM | Jul 15, 2003 11:19:28 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Yahoo!\Messenger\XMLParse.dll New Handle ID: 32 Operation ID: {0,94561} Process ID: 1896 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE Execute/Traverse Privileges - | Information | 1 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 808 Operation ID: {0,710195} Process ID: 2376 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 268 Operation ID: {0,814242} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:41:46 AM | Jul 15, 2003 11:41:46 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1 New Handle ID: 1496 Operation ID: {0,345544} Process ID: 1184 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 260 Operation ID: {0,710072} Process ID: 2376 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:24:09 PM | Jul 15, 2003 12:24:09 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 776 Operation ID: {0,788108} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:45:20 AM | Jul 15, 2003 11:45:20 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 184 Operation ID: {0,396639} Process ID: 1904 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:24:09 PM | Jul 15, 2003 12:24:09 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 776 Operation ID: {0,788388} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:19:14 AM | Jul 15, 2003 11:19:14 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10\OUTLLIB.DLL New Handle ID: 484 Operation ID: {0,69292} Process ID: 1184 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses READ_CONTROL SYNCHRONIZE ReadData (or ListDirectory) ReadEA ReadAttributes Privileges - | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 268 Operation ID: {0,814359} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 268 Operation ID: {0,814126} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:45:21 AM | Jul 15, 2003 11:45:21 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 884 Operation ID: {0,397615} Process ID: 1904 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 268 Operation ID: {0,814135} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:49:38 AM | Jul 15, 2003 11:49:38 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10\FRONTPG.EXE New Handle ID: 1796 Operation ID: {0,460558} Process ID: 2464 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses READ_CONTROL SYNCHRONIZE ReadData (or ListDirectory) ReadEA ReadAttributes WriteAttributes Privileges - | Information | 1 |
| Jul 15, 2003 11:45:21 AM | Jul 15, 2003 11:45:21 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 884 Operation ID: {0,397642} Process ID: 1904 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:24:05 PM | Jul 15, 2003 12:24:05 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 268 Operation ID: {0,785027} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 992 Operation ID: {0,815230} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:24:05 PM | Jul 15, 2003 12:24:05 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 268 Operation ID: {0,785114} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:45:31 AM | Jul 15, 2003 11:45:31 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10\1033 New Handle ID: 260 Operation ID: {0,398956} Process ID: 1904 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 260 Operation ID: {0,710051} Process ID: 2376 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:45:21 AM | Jul 15, 2003 11:45:21 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 184 Operation ID: {0,396691} Process ID: 1904 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:45:31 AM | Jul 15, 2003 11:45:31 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10\1033\ID_028.DHS New Handle ID: 260 Operation ID: {0,398960} Process ID: 1904 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses READ_CONTROL SYNCHRONIZE ReadData (or ListDirectory) ReadEA ReadAttributes Privileges - | Information | 1 |
| Jul 15, 2003 11:19:07 AM | Jul 15, 2003 11:19:07 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\VMware\VMware Workstation\vmware-authd.exe New Handle ID: 2720 Operation ID: {0,61815} Process ID: 220 Primary User Name: testWS02$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE Execute/Traverse Privileges - | Information | 1 |
| Jul 15, 2003 11:18:50 AM | Jul 15, 2003 11:18:50 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_SERVER Object Name: SAM New Handle ID: 723144 Operation ID: {0,51908} Process ID: 232 Primary User Name: testWS02$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS02$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses DELETE READ_CONTROL WRITE_DAC WRITE_OWNER ConnectToServer ShutdownServer InitializeServer CreateDomain EnumerateDomains LookupDomain Privileges - | Information | 1 |
| Jul 15, 2003 11:45:21 AM | Jul 15, 2003 11:45:21 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10\INTLDATE.DLL New Handle ID: 244 Operation ID: {0,397243} Process ID: 1904 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE Execute/Traverse Privileges - | Information | 1 |
| Jul 15, 2003 11:52:00 AM | Jul 15, 2003 11:52:00 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10\MCPS.DLL New Handle ID: 1788 Operation ID: {0,485570} Process ID: 1184 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE Execute/Traverse Privileges - | Information | 1 |
| Jul 15, 2003 11:19:08 AM | Jul 15, 2003 11:19:08 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_DOMAIN Object Name: Builtin New Handle ID: 889672 Operation ID: {0,62982} Process ID: 232 Primary User Name: testWS02$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS02$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses GetLocalGroupMembership LookupIDs Privileges - | Information | 1 |
| Jul 15, 2003 11:41:31 AM | Jul 15, 2003 11:41:31 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10\MSOHEV.DLL New Handle ID: 1352 Operation ID: {0,327714} Process ID: 1184 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE Execute/Traverse Privileges - | Information | 1 |
| Jul 15, 2003 12:24:09 PM | Jul 15, 2003 12:24:09 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 852 Operation ID: {0,789124} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:24:09 PM | Jul 15, 2003 12:24:09 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 776 Operation ID: {0,788361} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:24:09 PM | Jul 15, 2003 12:24:09 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 848 Operation ID: {0,789028} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:24:09 PM | Jul 15, 2003 12:24:09 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 852 Operation ID: {0,789121} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:45:16 AM | Jul 15, 2003 11:45:16 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10\WINWORD.EXE New Handle ID: 1652 Operation ID: {0,392781} Process ID: 1184 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE Execute/Traverse Privileges - | Information | 1 |
| Jul 15, 2003 12:24:04 PM | Jul 15, 2003 12:24:04 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 780 Operation ID: {0,784978} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 896 Operation ID: {0,711170} Process ID: 2376 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:41:31 AM | Jul 15, 2003 11:41:31 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10\MSOHEV.DLL New Handle ID: 1348 Operation ID: {0,327717} Process ID: 1184 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE Execute/Traverse Privileges - | Information | 1 |
| Jul 15, 2003 12:24:09 PM | Jul 15, 2003 12:24:09 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 776 Operation ID: {0,788168} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:41:46 AM | Jul 15, 2003 11:41:46 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files New Handle ID: 1512 Operation ID: {0,345851} Process ID: 1184 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:24:00 PM | Jul 15, 2003 12:24:00 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10\1033 New Handle ID: 208 Operation ID: {0,780101} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 992 Operation ID: {0,815263} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:45:21 AM | Jul 15, 2003 11:45:21 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 184 Operation ID: {0,396766} Process ID: 1904 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:24:09 PM | Jul 15, 2003 12:24:09 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 852 Operation ID: {0,789085} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:24:05 PM | Jul 15, 2003 12:24:05 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 268 Operation ID: {0,785006} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 260 Operation ID: {0,710060} Process ID: 2376 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:06:59 AM | Jul 15, 2003 11:06:59 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Templates\1033 New Handle ID: 864 Operation ID: {0,809760} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10\INTLDATE.DLL New Handle ID: 888 Operation ID: {0,710796} Process ID: 2376 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE Execute/Traverse Privileges - | Information | 1 |
| Jul 15, 2003 12:23:59 PM | Jul 15, 2003 12:23:59 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 2328 Operation ID: {0,778830} Process ID: 1184 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:45:21 AM | Jul 15, 2003 11:45:21 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 884 Operation ID: {0,397602} Process ID: 1904 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 992 Operation ID: {0,815370} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:45:21 AM | Jul 15, 2003 11:45:21 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 184 Operation ID: {0,396715} Process ID: 1904 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:21:00 AM | Jul 15, 2003 11:21:00 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\VMware\VMware Workstation\vmeventmsg.dll New Handle ID: 420 Operation ID: {0,216268} Process ID: 724 Primary User Name: testWS02$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE Execute/Traverse Privileges - | Information | 1 |
| Jul 15, 2003 11:06:59 AM | Jul 15, 2003 11:06:59 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Templates\1033 New Handle ID: 888 Operation ID: {0,809914} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadAttributes Privileges - | Information | 1 |
| Jul 15, 2003 11:19:31 AM | Jul 15, 2003 11:19:31 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10\OSA.EXE New Handle ID: 1116 Operation ID: {0,98995} Process ID: 1184 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE Execute/Traverse Privileges - | Information | 1 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 896 Operation ID: {0,711221} Process ID: 2376 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 268 Operation ID: {0,814314} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:29:40 AM | Jul 15, 2003 11:29:40 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10\OUTLLIB.DLL New Handle ID: 1184 Operation ID: {0,277988} Process ID: 1880 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses READ_CONTROL SYNCHRONIZE ReadData (or ListDirectory) ReadEA ReadAttributes Privileges - | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10\INTLDATE.DLL New Handle ID: 984 Operation ID: {0,814777} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE Execute/Traverse Privileges - | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 992 Operation ID: {0,815130} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:45:21 AM | Jul 15, 2003 11:45:21 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 184 Operation ID: {0,396706} Process ID: 1904 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:19:14 AM | Jul 15, 2003 11:19:14 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_DOMAIN Object Name: testWS02 New Handle ID: 889984 Operation ID: {0,68828} Process ID: 232 Primary User Name: testWS02$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS02$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses LookupIDs Privileges - | Information | 1 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 808 Operation ID: {0,710207} Process ID: 2376 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 268 Operation ID: {0,814302} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:24:00 PM | Jul 15, 2003 12:24:00 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10\1033\ID_028.DPC New Handle ID: 208 Operation ID: {0,780103} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses READ_CONTROL SYNCHRONIZE ReadData (or ListDirectory) ReadEA ReadAttributes Privileges - | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 992 Operation ID: {0,815203} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 992 Operation ID: {0,815170} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:24:09 PM | Jul 15, 2003 12:24:09 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 848 Operation ID: {0,788965} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:24:09 PM | Jul 15, 2003 12:24:09 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10 New Handle ID: 776 Operation ID: {0,788188} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 808 Operation ID: {0,710147} Process ID: 2376 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:29:40 AM | Jul 15, 2003 11:29:40 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10\OUTLLIB.DLL New Handle ID: 1260 Operation ID: {0,277967} Process ID: 1880 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE Execute/Traverse Privileges - | Information | 1 |
| Jul 15, 2003 12:23:59 PM | Jul 15, 2003 12:23:59 PM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1\MICROS~1\Office10\Startup New Handle ID: 92 Operation ID: {0,779956} Process ID: 2616 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:06:59 AM | Jul 15, 2003 11:06:59 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Templates\1033 New Handle ID: 904 Operation ID: {0,810098} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadAttributes Privileges - | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 268 Operation ID: {0,814114} Process ID: 2292 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0x16639) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:41:46 AM | Jul 15, 2003 11:41:46 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\PROGRA~1 New Handle ID: 1496 Operation ID: {0,345895} Process ID: 1184 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Jul 15, 2003 11:45:21 AM | Jul 15, 2003 11:45:21 AM | Object Open: Object Server: Security Object Type: File Object Name: D:\Program Files\Microsoft Office\Office10 New Handle ID: 884 Operation ID: {0,397722} Process ID: 1904 Primary User Name: user2 Primary Domain: test Primary Logon ID: (0x0,0xD1E9) Client User Name: - Client Domain: - Client Logon ID: - Accesses SYNCHRONIZE ReadData (or ListDirectory) Privileges - | Information | 1 |
| Details limited to 100 | 572 | |||||||
| Jul 15, 2003 11:45:21 AM | Jul 15, 2003 11:45:21 AM | Handle Closed: Object Server: Security Handle ID: 884 Process ID: 1904 | Information | 40 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Handle Closed: Object Server: Security Handle ID: 896 Process ID: 2376 | Information | 40 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Handle Closed: Object Server: Security Handle ID: 992 Process ID: 2292 | Information | 40 |
| Jul 15, 2003 12:24:09 PM | Jul 15, 2003 12:24:09 PM | Handle Closed: Object Server: Security Handle ID: 776 Process ID: 2616 | Information | 40 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Handle Closed: Object Server: Security Handle ID: 268 Process ID: 2292 | Information | 38 |
| Jul 15, 2003 12:24:05 PM | Jul 15, 2003 12:24:05 PM | Handle Closed: Object Server: Security Handle ID: 268 Process ID: 2616 | Information | 38 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Handle Closed: Object Server: Security Handle ID: 808 Process ID: 2376 | Information | 30 |
| Jul 15, 2003 11:41:46 AM | Jul 15, 2003 11:41:46 AM | Handle Closed: Object Server: Security Handle ID: 1496 Process ID: 1184 | Information | 20 |
| Jul 15, 2003 12:24:09 PM | Jul 15, 2003 12:24:09 PM | Handle Closed: Object Server: Security Handle ID: 848 Process ID: 2616 | Information | 18 |
| Jul 15, 2003 11:18:50 AM | Jul 15, 2003 11:19:19 AM | Handle Closed: Object Server: Security Account Manager Handle ID: 723144 Process ID: 232 | Information | 8 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Handle Closed: Object Server: Security Handle ID: 260 Process ID: 2376 | Information | 8 |
| Jul 15, 2003 11:06:59 AM | Jul 15, 2003 11:06:59 AM | Handle Closed: Object Server: Security Handle ID: 864 Process ID: 2292 | Information | 7 |
| Jul 15, 2003 12:23:59 PM | Jul 15, 2003 12:23:59 PM | Handle Closed: Object Server: Security Handle ID: 2328 Process ID: 1184 | Information | 6 |
| Jul 15, 2003 11:19:24 AM | Jul 15, 2003 11:19:24 AM | Handle Closed: Object Server: Security Handle ID: 968 Process ID: 1184 | Information | 6 |
| Jul 15, 2003 11:19:08 AM | Jul 15, 2003 11:19:14 AM | Handle Closed: Object Server: Security Account Manager Handle ID: 889672 Process ID: 232 | Information | 5 |
| Jul 15, 2003 11:06:59 AM | Jul 15, 2003 11:07:00 AM | Handle Closed: Object Server: Security Handle ID: 176 Process ID: 2292 | Information | 3 |
| Jul 15, 2003 11:18:50 AM | Jul 15, 2003 11:19:08 AM | Handle Closed: Object Server: Security Account Manager Handle ID: 744824 Process ID: 232 | Information | 3 |
| Jul 15, 2003 12:18:59 PM | Jul 15, 2003 12:18:59 PM | Handle Closed: Object Server: Security Handle ID: 108 Process ID: 2376 | Information | 3 |
| Jul 15, 2003 11:48:58 AM | Jul 15, 2003 11:48:58 AM | Handle Closed: Object Server: Security Handle ID: 912 Process ID: 2464 | Information | 3 |
| Jul 15, 2003 11:19:27 AM | Jul 15, 2003 11:19:30 AM | Handle Closed: Object Server: Security Handle ID: 28 Process ID: 1896 | Information | 3 |
| Jul 15, 2003 11:55:51 AM | Jul 15, 2003 11:55:51 AM | Handle Closed: Object Server: Security Handle ID: 924 Process ID: 1588 | Information | 3 |
| Jul 15, 2003 11:19:13 AM | Jul 15, 2003 11:19:14 AM | Handle Closed: Object Server: Security Account Manager Handle ID: 869232 Process ID: 232 | Information | 3 |
| Jul 15, 2003 11:55:51 AM | Jul 15, 2003 11:55:51 AM | Handle Closed: Object Server: Security Handle ID: 920 Process ID: 1588 | Information | 3 |
| Jul 15, 2003 11:19:28 AM | Jul 15, 2003 11:19:31 AM | Handle Closed: Object Server: Security Handle ID: 32 Process ID: 1896 | Information | 3 |
| Jul 15, 2003 11:55:50 AM | Jul 15, 2003 11:55:50 AM | Handle Closed: Object Server: Security Handle ID: 852 Process ID: 1588 | Information | 2 |
| Jul 15, 2003 11:19:49 AM | Jul 15, 2003 11:19:49 AM | Handle Closed: Object Server: Security Handle ID: 348 Process ID: 684 | Information | 2 |
| Jul 15, 2003 11:48:48 AM | Jul 15, 2003 11:48:48 AM | Handle Closed: Object Server: Security Handle ID: 884 Process ID: 2392 | Information | 2 |
| Jul 15, 2003 11:19:49 AM | Jul 15, 2003 11:19:49 AM | Handle Closed: Object Server: Security Handle ID: 356 Process ID: 684 | Information | 2 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Handle Closed: Object Server: Security Handle ID: 800 Process ID: 2376 | Information | 2 |
| Jul 15, 2003 11:48:48 AM | Jul 15, 2003 11:48:48 AM | Handle Closed: Object Server: Security Handle ID: 888 Process ID: 2392 | Information | 2 |
| Jul 15, 2003 11:29:40 AM | Jul 15, 2003 11:29:40 AM | Handle Closed: Object Server: Security Handle ID: 1184 Process ID: 1880 | Information | 2 |
| Jul 15, 2003 11:45:16 AM | Jul 15, 2003 11:45:16 AM | Handle Closed: Object Server: Security Handle ID: 1652 Process ID: 1184 | Information | 2 |
| Jul 15, 2003 11:45:12 AM | Jul 15, 2003 11:45:12 AM | Handle Closed: Object Server: Security Handle ID: 560 Process ID: 1344 | Information | 2 |
| Jul 15, 2003 12:23:59 PM | Jul 15, 2003 12:23:59 PM | Handle Closed: Object Server: Security Handle ID: 2332 Process ID: 1184 | Information | 2 |
| Jul 15, 2003 11:48:48 AM | Jul 15, 2003 11:48:48 AM | Handle Closed: Object Server: Security Handle ID: 832 Process ID: 2392 | Information | 2 |
| Jul 15, 2003 11:45:20 AM | Jul 15, 2003 11:45:20 AM | Handle Closed: Object Server: Security Handle ID: 848 Process ID: 1904 | Information | 2 |
| Jul 15, 2003 11:06:58 AM | Jul 15, 2003 11:06:58 AM | Handle Closed: Object Server: Security Handle ID: 692 Process ID: 2292 | Information | 2 |
| Jul 15, 2003 11:21:00 AM | Jul 15, 2003 11:21:00 AM | Handle Closed: Object Server: Security Handle ID: 420 Process ID: 724 | Information | 2 |
| Jul 15, 2003 11:19:14 AM | Jul 15, 2003 11:19:14 AM | Handle Closed: Object Server: Security Handle ID: 484 Process ID: 1184 | Information | 2 |
| Jul 15, 2003 11:08:51 AM | Jul 15, 2003 11:08:51 AM | Handle Closed: Object Server: Security Handle ID: 596 Process ID: 2292 | Information | 2 |
| Jul 15, 2003 11:45:12 AM | Jul 15, 2003 11:45:12 AM | Handle Closed: Object Server: Security Handle ID: 556 Process ID: 1344 | Information | 2 |
| Jul 15, 2003 12:18:58 PM | Jul 15, 2003 12:18:58 PM | Handle Closed: Object Server: Security Handle ID: 132 Process ID: 1184 | Information | 2 |
| Jul 15, 2003 11:41:46 AM | Jul 15, 2003 11:41:46 AM | Handle Closed: Object Server: Security Handle ID: 1512 Process ID: 1184 | Information | 2 |
| Jul 15, 2003 12:24:05 PM | Jul 15, 2003 12:24:05 PM | Handle Closed: Object Server: Security Handle ID: 780 Process ID: 2616 | Information | 2 |
| Jul 15, 2003 11:21:57 AM | Jul 15, 2003 11:21:57 AM | Handle Closed: Object Server: Security Handle ID: 664 Process ID: 1764 | Information | 2 |
| Jul 15, 2003 11:19:31 AM | Jul 15, 2003 11:19:31 AM | Handle Closed: Object Server: Security Handle ID: 1000 Process ID: 1184 | Information | 2 |
| Jul 15, 2003 11:29:40 AM | Jul 15, 2003 11:29:40 AM | Handle Closed: Object Server: Security Handle ID: 1260 Process ID: 1880 | Information | 2 |
| Jul 15, 2003 11:48:58 AM | Jul 15, 2003 11:48:58 AM | Handle Closed: Object Server: Security Handle ID: 844 Process ID: 2464 | Information | 2 |
| Jul 15, 2003 11:19:14 AM | Jul 15, 2003 11:19:14 AM | Handle Closed: Object Server: Security Handle ID: 480 Process ID: 1184 | Information | 2 |
| Jul 15, 2003 11:48:48 AM | Jul 15, 2003 11:48:48 AM | Handle Closed: Object Server: Security Handle ID: 836 Process ID: 2392 | Information | 2 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Handle Closed: Object Server: Security Handle ID: 968 Process ID: 2292 | Information | 2 |
| Jul 15, 2003 11:45:17 AM | Jul 15, 2003 11:45:17 AM | Handle Closed: Object Server: Security Handle ID: 516 Process ID: 1904 | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Handle Closed: Object Server: Security Handle ID: 280 Process ID: 2292 | Information | 1 |
| Jul 15, 2003 11:19:57 AM | Jul 15, 2003 11:19:57 AM | Handle Closed: Object Server: Security Handle ID: 1208 Process ID: 1184 | Information | 1 |
| Jul 15, 2003 11:45:16 AM | Jul 15, 2003 11:45:16 AM | Handle Closed: Object Server: Security Handle ID: 284 Process ID: 1904 | Information | 1 |
| Jul 15, 2003 11:19:38 AM | Jul 15, 2003 11:19:38 AM | Handle Closed: Object Server: Security Handle ID: 396 Process ID: 1896 | Information | 1 |
| Jul 15, 2003 11:06:59 AM | Jul 15, 2003 11:06:59 AM | Handle Closed: Object Server: Security Handle ID: 888 Process ID: 2292 | Information | 1 |
| Jul 15, 2003 11:45:21 AM | Jul 15, 2003 11:45:21 AM | Handle Closed: Object Server: Security Handle ID: 872 Process ID: 1904 | Information | 1 |
| Jul 15, 2003 11:19:35 AM | Jul 15, 2003 11:19:35 AM | Handle Closed: Object Server: Security Handle ID: 1084 Process ID: 1184 | Information | 1 |
| Jul 15, 2003 12:48:02 PM | Jul 15, 2003 12:48:02 PM | Handle Closed: Object Server: Security Handle ID: 228 Process ID: 1848 | Information | 1 |
| Jul 15, 2003 11:08:51 AM | Jul 15, 2003 11:08:51 AM | Handle Closed: Object Server: Security Handle ID: 660 Process ID: 2292 | Information | 1 |
| Jul 15, 2003 11:45:21 AM | Jul 15, 2003 11:45:21 AM | Handle Closed: Object Server: Security Handle ID: 244 Process ID: 1904 | Information | 1 |
| Jul 15, 2003 12:18:58 PM | Jul 15, 2003 12:18:58 PM | Handle Closed: Object Server: Security Handle ID: 1076 Process ID: 1184 | Information | 1 |
| Jul 15, 2003 12:23:59 PM | Jul 15, 2003 12:23:59 PM | Handle Closed: Object Server: Security Handle ID: 476 Process ID: 2616 | Information | 1 |
| Jul 15, 2003 12:19:00 PM | Jul 15, 2003 12:19:00 PM | Handle Closed: Object Server: Security Handle ID: 264 Process ID: 2376 | Information | 1 |
| Jul 15, 2003 11:19:40 AM | Jul 15, 2003 11:19:40 AM | Handle Closed: Object Server: Security Handle ID: 1028 Process ID: 1184 | Information | 1 |
| Jul 15, 2003 12:23:59 PM | Jul 15, 2003 12:23:59 PM | Handle Closed: Object Server: Security Handle ID: 288 Process ID: 2616 | Information | 1 |
| Jul 15, 2003 11:19:38 AM | Jul 15, 2003 11:19:38 AM | Handle Closed: Object Server: Security Handle ID: 400 Process ID: 1896 | Information | 1 |
| Jul 15, 2003 12:23:59 PM | Jul 15, 2003 12:23:59 PM | Handle Closed: Object Server: Security Handle ID: 2320 Process ID: 1184 | Information | 1 |
| Jul 15, 2003 12:24:09 PM | Jul 15, 2003 12:24:09 PM | Handle Closed: Object Server: Security Handle ID: 832 Process ID: 2616 | Information | 1 |
| Jul 15, 2003 12:23:59 PM | Jul 15, 2003 12:23:59 PM | Handle Closed: Object Server: Security Handle ID: 164 Process ID: 2616 | Information | 1 |
| Jul 15, 2003 11:45:16 AM | Jul 15, 2003 11:45:16 AM | Handle Closed: Object Server: Security Handle ID: 476 Process ID: 1904 | Information | 1 |
| Jul 15, 2003 12:18:59 PM | Jul 15, 2003 12:18:59 PM | Handle Closed: Object Server: Security Handle ID: 516 Process ID: 2376 | Information | 1 |
| Jul 15, 2003 11:51:35 AM | Jul 15, 2003 11:51:35 AM | Handle Closed: Object Server: Security Handle ID: 1420 Process ID: 1764 | Information | 1 |
| Jul 15, 2003 11:51:35 AM | Jul 15, 2003 11:51:35 AM | Handle Closed: Object Server: Security Handle ID: 996 Process ID: 1764 | Information | 1 |
| Jul 15, 2003 11:07:01 AM | Jul 15, 2003 11:07:01 AM | Handle Closed: Object Server: Security Handle ID: 984 Process ID: 2292 | Information | 1 |
| Jul 15, 2003 12:18:59 PM | Jul 15, 2003 12:18:59 PM | Handle Closed: Object Server: Security Handle ID: 288 Process ID: 2376 | Information | 1 |
| Jul 15, 2003 11:52:00 AM | Jul 15, 2003 11:52:00 AM | Handle Closed: Object Server: Security Handle ID: 1788 Process ID: 1184 | Information | 1 |
| Jul 15, 2003 11:19:39 AM | Jul 15, 2003 11:19:39 AM | Handle Closed: Object Server: Security Handle ID: 404 Process ID: 1896 | Information | 1 |
| Jul 15, 2003 11:52:00 AM | Jul 15, 2003 11:52:00 AM | Handle Closed: Object Server: Security Handle ID: 1816 Process ID: 1184 | Information | 1 |
| Jul 15, 2003 12:18:59 PM | Jul 15, 2003 12:18:59 PM | Handle Closed: Object Server: Security Handle ID: 284 Process ID: 2376 | Information | 1 |
| Jul 15, 2003 11:19:35 AM | Jul 15, 2003 11:19:35 AM | Handle Closed: Object Server: Security Handle ID: 1012 Process ID: 1184 | Information | 1 |
| Jul 15, 2003 11:48:53 AM | Jul 15, 2003 11:48:53 AM | Handle Closed: Object Server: Security Handle ID: 1140 Process ID: 2392 | Information | 1 |
| Jul 15, 2003 11:19:27 AM | Jul 15, 2003 11:19:27 AM | Handle Closed: Object Server: Security Handle ID: 1004 Process ID: 1184 | Information | 1 |
| Jul 15, 2003 11:19:57 AM | Jul 15, 2003 11:19:57 AM | Handle Closed: Object Server: Security Handle ID: 1204 Process ID: 1184 | Information | 1 |
| Jul 15, 2003 12:24:09 PM | Jul 15, 2003 12:24:09 PM | Handle Closed: Object Server: Security Handle ID: 836 Process ID: 2616 | Information | 1 |
| Jul 15, 2003 11:19:27 AM | Jul 15, 2003 11:19:27 AM | Handle Closed: Object Server: Security Handle ID: 936 Process ID: 1184 | Information | 1 |
| Jul 15, 2003 11:19:30 AM | Jul 15, 2003 11:19:30 AM | Handle Closed: Object Server: Security Handle ID: 1020 Process ID: 1184 | Information | 1 |
| Jul 15, 2003 11:19:40 AM | Jul 15, 2003 11:19:40 AM | Handle Closed: Object Server: Security Handle ID: 100 Process ID: 1988 | Information | 1 |
| Jul 15, 2003 12:18:59 PM | Jul 15, 2003 12:18:59 PM | Handle Closed: Object Server: Security Handle ID: 476 Process ID: 2376 | Information | 1 |
| Jul 15, 2003 11:45:16 AM | Jul 15, 2003 11:45:16 AM | Handle Closed: Object Server: Security Handle ID: 120 Process ID: 1904 | Information | 1 |
| Jul 15, 2003 11:45:16 AM | Jul 15, 2003 11:45:16 AM | Handle Closed: Object Server: Security Handle ID: 124 Process ID: 1904 | Information | 1 |
| Jul 15, 2003 11:55:58 AM | Jul 15, 2003 11:55:58 AM | Handle Closed: Object Server: Security Handle ID: 1124 Process ID: 1588 | Information | 1 |
| Jul 15, 2003 11:19:37 AM | Jul 15, 2003 11:19:37 AM | Handle Closed: Object Server: Security Handle ID: 200 Process ID: 1896 | Information | 1 |
| Jul 15, 2003 11:19:07 AM | Jul 15, 2003 11:19:07 AM | Handle Closed: Object Server: Security Handle ID: 2720 Process ID: 220 | Information | 1 |
| Jul 15, 2003 11:49:38 AM | Jul 15, 2003 11:49:38 AM | Handle Closed: Object Server: Security Handle ID: 1796 Process ID: 2464 | Information | 1 |
| Jul 15, 2003 12:48:02 PM | Jul 15, 2003 12:48:02 PM | Handle Closed: Object Server: Security Handle ID: 224 Process ID: 1848 | Information | 1 |
| Jul 15, 2003 11:41:31 AM | Jul 15, 2003 11:41:31 AM | Handle Closed: Object Server: Security Handle ID: 1352 Process ID: 1184 | Information | 1 |
| Jul 15, 2003 11:06:59 AM | Jul 15, 2003 11:06:59 AM | Handle Closed: Object Server: Security Handle ID: 904 Process ID: 2292 | Information | 1 |
| Jul 15, 2003 11:48:48 AM | Jul 15, 2003 11:48:48 AM | Handle Closed: Object Server: Security Handle ID: 896 Process ID: 2392 | Information | 1 |
| 1 |
| 1 |
| 18 |
| 1 |
| 1 |
| 1 |
| 1 |
| 3 |
| 1 |
| 1 |
| 1 |
| 1 |
| 1 |
| 2 |
| 1 |
| 1 |
| 3 |
| 3 |
| 1 |
| 1 |
| 2 |
| 2 |
| 2 |
| 1 |
| 1 |
| 2 |
| 2 |
| 820 |
| 581 |
| 169 |
| 21 |
| 8 |
| 109 |
| 21 |
| 10 |
| 80 |
| 5 |
| 5 |
| 1 |
| 1 |
| 10 |
| 9 |
| 1 |
| 46 |
| 2 |
| 8 |
| 6 |
| 2 |
| 15 |
| 15 |
| 15 |
| 15 |
| 11 |
| 11 |
| 145 |
| 145 |
| Jun 26, 2003 05:10:11 PM | Jul 15, 2003 11:18:34 AM | 17052 : Recovery complete. | Warning | 15 |
| Jun 26, 2003 05:10:03 PM | Jul 15, 2003 11:18:26 AM | 17834 : Using 'SSNETLIB.DLL' version '8.0.194'. | Warning | 15 |
| Jun 26, 2003 05:10:04 PM | Jul 15, 2003 11:18:27 AM | 17126 : SQL Server is ready for client connections | Warning | 15 |
| Jun 26, 2003 05:10:04 PM | Jul 15, 2003 11:18:27 AM | 19013 : SQL server listening on TCP, Shared Memory, Named Pipes, Rpc. | Warning | 15 |
| Jun 26, 2003 05:10:04 PM | Jul 15, 2003 11:18:27 AM | 19013 : SQL server listening on 192.168.123.4:1433, 1.0.0.1:1433, 127.0.0.1:1433. | Warning | 14 |
| Jun 26, 2003 06:04:58 PM | Jul 15, 2003 11:18:21 AM | 17162 : SQL Server is starting at priority class 'normal'(1 CPU detected). | Warning | 14 |
| Jun 26, 2003 06:04:59 PM | Jul 15, 2003 11:18:22 AM | 17124 : SQL Server configured for thread mode processing. | Warning | 14 |
| Jun 26, 2003 06:04:59 PM | Jul 15, 2003 11:18:22 AM | 17125 : Using dynamic lock allocation. [2500] Lock Blocks, [5000] Lock Owner Blocks. | Warning | 14 |
| Jun 26, 2003 06:04:58 PM | Jul 15, 2003 11:18:21 AM | 17052 : Microsoft SQL Server 2000 - 8.00.194 (Intel X86) Aug 6 2000 00:57:48 Copyright (c) 1988-2000 Microsoft Corporation Developer Edition on Windows NT 5.0 (Build 2195: Service Pack 3) | Warning | 14 |
| Jun 26, 2003 06:04:58 PM | Jul 08, 2003 09:30:15 AM | 17104 : Server Process ID is 732. | Warning | 3 |
| Jul 04, 2003 10:42:51 AM | Jul 10, 2003 09:47:19 AM | 17104 : Server Process ID is 724. | Warning | 3 |
| Jul 11, 2003 09:21:01 AM | Jul 14, 2003 09:22:00 AM | 17104 : Server Process ID is 720. | Warning | 2 |
| Jun 30, 2003 11:32:24 AM | Jun 30, 2003 11:32:24 AM | 19013 : SQL server listening on 192.168.123.4:1433, 127.0.0.1:1433. | Warning | 1 |
| Jul 07, 2003 12:01:39 PM | Jul 07, 2003 12:01:39 PM | 17104 : Server Process ID is 696. | Warning | 1 |
| Jul 03, 2003 10:54:41 AM | Jul 03, 2003 10:54:41 AM | 17104 : Server Process ID is 736. | Warning | 1 |
| Jun 30, 2003 11:32:13 AM | Jun 30, 2003 11:32:13 AM | 17104 : Server Process ID is 740. | Warning | 1 |
| Jul 01, 2003 10:34:29 AM | Jul 01, 2003 10:34:29 AM | 17104 : Server Process ID is 704. | Warning | 1 |
| Jul 15, 2003 09:45:27 AM | Jul 15, 2003 09:45:27 AM | 17104 : Server Process ID is 716. | Warning | 1 |
| Jul 15, 2003 11:18:21 AM | Jul 15, 2003 11:18:21 AM | 17104 : Server Process ID is 744. | Warning | 1 |
| 56 |
| 45 |
| Jun 26, 2003 06:05:07 PM | Jul 08, 2003 09:30:21 AM | RPC Net-Library listening on: ncacn_np:\\\\testWS03[\\pipe\\000002dc.000]. | Warning | 3 |
| Jul 04, 2003 10:43:01 AM | Jul 10, 2003 09:47:25 AM | RPC Net-Library listening on: ncalrpc:testWS03[LRPC000002d4.00000001]. | Warning | 3 |
| Jun 26, 2003 06:05:07 PM | Jul 08, 2003 09:30:21 AM | RPC Net-Library listening on: ncalrpc:testWS03[LRPC000002dc.00000001]. | Warning | 3 |
| Jul 04, 2003 10:43:01 AM | Jul 10, 2003 09:47:25 AM | RPC Net-Library listening on: ncacn_np:\\\\testWS03[\\pipe\\000002d4.000]. | Warning | 3 |
| Jul 03, 2003 10:54:45 AM | Jul 04, 2003 10:43:01 AM | RPC Net-Library listening on: ncacn_ip_tcp:testws03.Testsoft.com.pk[1119]. | Warning | 2 |
| Jul 11, 2003 09:21:06 AM | Jul 14, 2003 09:22:05 AM | RPC Net-Library listening on: ncacn_np:\\\\testWS03[\\pipe\\000002d0.000]. | Warning | 2 |
| Jul 09, 2003 09:21:01 AM | Jul 11, 2003 09:21:06 AM | RPC Net-Library listening on: ncacn_ip_tcp:testws03.Testsoft.com.pk[1121]. | Warning | 2 |
| Jul 14, 2003 09:22:05 AM | Jul 15, 2003 09:45:32 AM | RPC Net-Library listening on: ncacn_ip_tcp:testws03.Testsoft.com.pk[1129]. | Warning | 2 |
| Jul 11, 2003 09:21:06 AM | Jul 14, 2003 09:22:05 AM | RPC Net-Library listening on: ncalrpc:testWS03[LRPC000002d0.00000001]. | Warning | 2 |
| Jul 07, 2003 12:01:44 PM | Jul 07, 2003 12:01:44 PM | RPC Net-Library listening on: ncacn_np:\\\\testWS03[\\pipe\\000002b8.000]. | Warning | 1 |
| Jul 01, 2003 10:34:35 AM | Jul 01, 2003 10:34:35 AM | RPC Net-Library listening on: ncacn_ip_tcp:testws03.Testsoft.com.pk[1106]. | Warning | 1 |
| Jun 26, 2003 05:10:04 PM | Jun 26, 2003 05:10:04 PM | RPC Net-Library listening on: ncacn_ip_tcp:testws03.Testsoft.com.pk[1085]. | Warning | 1 |
| Jul 03, 2003 10:54:45 AM | Jul 03, 2003 10:54:45 AM | RPC Net-Library listening on: ncalrpc:testWS03[LRPC000002e0.00000001]. | Warning | 1 |
| Jul 15, 2003 09:45:32 AM | Jul 15, 2003 09:45:32 AM | RPC Net-Library listening on: ncacn_np:\\\\testWS03[\\pipe\\000002cc.000]. | Warning | 1 |
| Jun 30, 2003 11:32:24 AM | Jun 30, 2003 11:32:24 AM | RPC Net-Library listening on: ncacn_np:\\\\testWS03[\\pipe\\000002e4.000]. | Warning | 1 |
| Jul 08, 2003 09:30:21 AM | Jul 08, 2003 09:30:21 AM | RPC Net-Library listening on: ncacn_ip_tcp:testws03.Testsoft.com.pk[1127]. | Warning | 1 |
| Jun 26, 2003 05:10:04 PM | Jun 26, 2003 05:10:04 PM | RPC Net-Library listening on: ncalrpc:testWS03[LRPC000002ec.00000001]. | Warning | 1 |
| Jul 15, 2003 11:18:27 AM | Jul 15, 2003 11:18:27 AM | RPC Net-Library listening on: ncacn_ip_tcp:testws03.Testsoft.com.pk[1083]. | Warning | 1 |
| Jun 26, 2003 05:10:04 PM | Jun 26, 2003 05:10:04 PM | RPC Net-Library listening on: ncacn_np:\\\\testWS03[\\pipe\\000002ec.000]. | Warning | 1 |
| Jun 26, 2003 06:05:07 PM | Jun 26, 2003 06:05:07 PM | RPC Net-Library listening on: ncacn_ip_tcp:testws03.Testsoft.com.pk[1107]. | Warning | 1 |
| Jul 15, 2003 09:45:32 AM | Jul 15, 2003 09:45:32 AM | RPC Net-Library listening on: ncalrpc:testWS03[LRPC000002cc.00000001]. | Warning | 1 |
| Jun 30, 2003 11:32:24 AM | Jun 30, 2003 11:32:24 AM | RPC Net-Library listening on: ncacn_ip_tcp:testws03.Testsoft.com.pk[1084]. | Warning | 1 |
| Jul 01, 2003 10:34:35 AM | Jul 01, 2003 10:34:35 AM | RPC Net-Library listening on: ncalrpc:testWS03[LRPC000002c0.00000001]. | Warning | 1 |
| Jul 15, 2003 11:18:27 AM | Jul 15, 2003 11:18:27 AM | RPC Net-Library listening on: ncacn_np:\\\\testWS03[\\pipe\\000002e8.000]. | Warning | 1 |
| Jun 30, 2003 11:32:24 AM | Jun 30, 2003 11:32:24 AM | RPC Net-Library listening on: ncalrpc:testWS03[LRPC000002e4.00000001]. | Warning | 1 |
| Jul 03, 2003 10:54:45 AM | Jul 03, 2003 10:54:45 AM | RPC Net-Library listening on: ncacn_np:\\\\testWS03[\\pipe\\000002e0.000]. | Warning | 1 |
| Jul 07, 2003 12:01:44 PM | Jul 07, 2003 12:01:44 PM | RPC Net-Library listening on: ncacn_ip_tcp:testws03.Testsoft.com.pk[1039]. | Warning | 1 |
| Jul 02, 2003 10:38:01 AM | Jul 02, 2003 10:38:01 AM | RPC Net-Library listening on: ncacn_ip_tcp:testws03.Testsoft.com.pk[1124]. | Warning | 1 |
| Jul 10, 2003 09:47:25 AM | Jul 10, 2003 09:47:25 AM | RPC Net-Library listening on: ncacn_ip_tcp:testws03.Testsoft.com.pk[1130]. | Warning | 1 |
| Jul 15, 2003 11:18:27 AM | Jul 15, 2003 11:18:27 AM | RPC Net-Library listening on: ncalrpc:testWS03[LRPC000002e8.00000001]. | Warning | 1 |
| Jul 01, 2003 10:34:35 AM | Jul 01, 2003 10:34:35 AM | RPC Net-Library listening on: ncacn_np:\\\\testWS03[\\pipe\\000002c0.000]. | Warning | 1 |
| Jul 07, 2003 12:01:44 PM | Jul 07, 2003 12:01:44 PM | RPC Net-Library listening on: ncalrpc:testWS03[LRPC000002b8.00000001]. | Warning | 1 |
| 11 |
| 14 |
| 14 |
| 15 |
| 15 |
| 12 |
| 12 |
| 11 |
| 11 |
| 15 |
| 15 |
| 15 |
| 15 |
| 230 |
| 230 |
| 1 |
| 5 |
| Jul 15, 2003 11:17:52 AM | Jul 15, 2003 11:17:52 AM | An authentication package has been loaded by the Local Security Authority. This authentication package will be used to authenticate logon attempts. Authentication Package Name: C:\WINNT\system32\msv1_0.dll : MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 | Information | 1 |
| Jul 15, 2003 11:17:52 AM | Jul 15, 2003 11:17:52 AM | An authentication package has been loaded by the Local Security Authority. This authentication package will be used to authenticate logon attempts. Authentication Package Name: C:\WINNT\system32\kerberos.dll : Kerberos | Information | 1 |
| Jul 15, 2003 11:17:52 AM | Jul 15, 2003 11:17:52 AM | An authentication package has been loaded by the Local Security Authority. This authentication package will be used to authenticate logon attempts. Authentication Package Name: C:\WINNT\system32\schannel.dll : Microsoft Unified Security Protocol Provider | Information | 1 |
| Jul 15, 2003 11:17:52 AM | Jul 15, 2003 11:17:52 AM | An authentication package has been loaded by the Local Security Authority. This authentication package will be used to authenticate logon attempts. Authentication Package Name: C:\WINNT\system32\msv1_0.dll : NTLM | Information | 1 |
| Jul 15, 2003 11:17:52 AM | Jul 15, 2003 11:17:52 AM | An authentication package has been loaded by the Local Security Authority. This authentication package will be used to authenticate logon attempts. Authentication Package Name: C:\WINNT\system32\LSASRV.dll : Negotiate | Information | 1 |
| 15 |
| Jul 15, 2003 11:14:16 AM | Jul 15, 2003 11:20:13 AM | A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: KSecDD | Information | 8 |
| Jul 15, 2003 11:17:52 AM | Jul 15, 2003 11:17:52 AM | A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: Winlogon\MSGina | Information | 1 |
| Jul 15, 2003 11:18:19 AM | Jul 15, 2003 11:18:19 AM | A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: Protected Storage Service | Information | 1 |
| Jul 15, 2003 11:18:46 AM | Jul 15, 2003 11:18:46 AM | A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: REMOTE_ACCESS | Information | 1 |
| Jul 15, 2003 11:17:54 AM | Jul 15, 2003 11:17:54 AM | A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: LAN Manager Workstation Service | Information | 1 |
| Jul 15, 2003 11:19:16 AM | Jul 15, 2003 11:19:16 AM | A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: IAS | Information | 1 |
| Jul 15, 2003 11:17:52 AM | Jul 15, 2003 11:17:52 AM | A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: Service Control Manager | Information | 1 |
| Jul 15, 2003 11:18:44 AM | Jul 15, 2003 11:18:44 AM | A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: RASMAN | Information | 1 |
| 1 |
| 2 |
| 3 |
| 3 |
| 18 |
| Jul 15, 2003 11:19:25 AM | Jul 15, 2003 11:19:25 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_SERVER Object Name: SAM New Handle ID: 723008 Operation ID: {0,212133} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses EnumerateDomains LookupDomain Privileges - | Information | 1 |
| Jul 15, 2003 11:18:12 AM | Jul 15, 2003 11:18:12 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_DOMAIN Object Name: testWS03 New Handle ID: 818640 Operation ID: {0,46260} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses DELETE READ_CONTROL WRITE_DAC WRITE_OWNER ReadPasswordParameters WritePasswordParameters ReadOtherParameters WriteOtherParameters CreateUser CreateLocalGroup GetLocalGroupMembership ListAccounts LookupIDs AdministerServer Privileges - | Information | 1 |
| Jul 15, 2003 11:19:25 AM | Jul 15, 2003 11:19:25 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_USER Object Name: DOMAINS\Account\Users\000003E9 New Handle ID: 781232 Operation ID: {0,212281} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses READ_CONTROL ReadGeneralInformation ReadPreferences ReadLogon ReadAccount ListGroups Privileges - | Information | 1 |
| Jul 15, 2003 11:19:25 AM | Jul 15, 2003 11:19:25 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_SERVER Object Name: SAM New Handle ID: 723008 Operation ID: {0,212268} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses EnumerateDomains LookupDomain Privileges - | Information | 1 |
| Jul 15, 2003 11:19:16 AM | Jul 15, 2003 11:19:16 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_SERVER Object Name: SAM New Handle ID: 723008 Operation ID: {0,191279} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses LookupDomain Privileges - | Information | 1 |
| Jul 15, 2003 11:19:25 AM | Jul 15, 2003 11:19:25 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_DOMAIN Object Name: testWS03 New Handle ID: 779816 Operation ID: {0,212271} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses LookupIDs Privileges - | Information | 1 |
| Jul 15, 2003 11:19:25 AM | Jul 15, 2003 11:19:25 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_DOMAIN Object Name: testWS03 New Handle ID: 780920 Operation ID: {0,212136} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses LookupIDs Privileges - | Information | 1 |
| Jul 15, 2003 11:19:25 AM | Jul 15, 2003 11:19:25 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_USER Object Name: DOMAINS\Account\Users\000003EA New Handle ID: 781232 Operation ID: {0,212051} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses READ_CONTROL ReadGeneralInformation ReadPreferences ReadLogon ReadAccount ListGroups Privileges - | Information | 1 |
| Jul 15, 2003 11:19:25 AM | Jul 15, 2003 11:19:25 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_DOMAIN Object Name: testWS03 New Handle ID: 779816 Operation ID: {0,212041} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses LookupIDs Privileges - | Information | 1 |
| Jul 15, 2003 11:19:25 AM | Jul 15, 2003 11:19:25 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_DOMAIN Object Name: Builtin New Handle ID: 780920 Operation ID: {0,212044} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses GetLocalGroupMembership LookupIDs Privileges - | Information | 1 |
| Jul 15, 2003 11:18:12 AM | Jul 15, 2003 11:18:12 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_SERVER Object Name: SAM New Handle ID: 723008 Operation ID: {0,46257} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses DELETE READ_CONTROL WRITE_DAC WRITE_OWNER ConnectToServer ShutdownServer InitializeServer CreateDomain EnumerateDomains LookupDomain Privileges - | Information | 1 |
| Jul 15, 2003 11:19:25 AM | Jul 15, 2003 11:19:25 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_DOMAIN Object Name: Builtin New Handle ID: 780920 Operation ID: {0,212274} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses GetLocalGroupMembership LookupIDs Privileges - | Information | 1 |
| Jul 15, 2003 11:19:25 AM | Jul 15, 2003 11:19:25 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_SERVER Object Name: SAM New Handle ID: 723008 Operation ID: {0,212038} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses EnumerateDomains LookupDomain Privileges - | Information | 1 |
| Jul 15, 2003 11:19:25 AM | Jul 15, 2003 11:19:25 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_USER Object Name: DOMAINS\Account\Users\000003E9 New Handle ID: 781232 Operation ID: {0,212146} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses READ_CONTROL ReadGeneralInformation ReadPreferences ReadLogon ReadAccount ListGroups Privileges - | Information | 1 |
| Jul 15, 2003 11:19:16 AM | Jul 15, 2003 11:19:16 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_DOMAIN Object Name: Builtin New Handle ID: 901192 Operation ID: {0,191285} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses GetLocalGroupMembership LookupIDs Privileges - | Information | 1 |
| Jul 15, 2003 11:19:25 AM | Jul 15, 2003 11:19:25 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_DOMAIN Object Name: Builtin New Handle ID: 779816 Operation ID: {0,212139} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses GetLocalGroupMembership LookupIDs Privileges - | Information | 1 |
| Jul 15, 2003 11:19:16 AM | Jul 15, 2003 11:19:16 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_USER Object Name: DOMAINS\Account\Users\000001F5 New Handle ID: 723008 Operation ID: {0,191297} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses ReadGeneralInformation Privileges - | Information | 1 |
| Jul 15, 2003 11:19:16 AM | Jul 15, 2003 11:19:16 AM | Object Open: Object Server: Security Account Manager Object Type: SAM_DOMAIN Object Name: testWS03 New Handle ID: 818640 Operation ID: {0,191282} Process ID: 224 Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Accesses ReadPasswordParameters GetLocalGroupMembership LookupIDs Privileges - | Information | 1 |
| 16 |
| Jul 15, 2003 11:18:12 AM | Jul 15, 2003 11:19:25 AM | Handle Closed: Object Server: Security Account Manager Handle ID: 723008 Process ID: 224 | Information | 6 |
| Jul 15, 2003 11:19:25 AM | Jul 15, 2003 11:19:25 AM | Handle Closed: Object Server: Security Account Manager Handle ID: 781232 Process ID: 224 | Information | 3 |
| Jul 15, 2003 11:19:25 AM | Jul 15, 2003 11:19:25 AM | Handle Closed: Object Server: Security Account Manager Handle ID: 779816 Process ID: 224 | Information | 3 |
| Jul 15, 2003 11:19:25 AM | Jul 15, 2003 11:19:25 AM | Handle Closed: Object Server: Security Account Manager Handle ID: 780920 Process ID: 224 | Information | 3 |
| Jul 15, 2003 11:18:12 AM | Jul 15, 2003 11:18:12 AM | Handle Closed: Object Server: Security Account Manager Handle ID: 818640 Process ID: 224 | Information | 1 |
| 6 |
| Jul 15, 2003 11:18:07 AM | Jul 15, 2003 11:18:07 AM | Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0xA815) Assigned: SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeChangeNotifyPrivilege | Information | 1 |
| Jul 15, 2003 11:18:07 AM | Jul 15, 2003 11:18:07 AM | Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0xA652) Assigned: SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeChangeNotifyPrivilege | Information | 1 |
| Jul 15, 2003 11:18:07 AM | Jul 15, 2003 11:18:07 AM | Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0xA745) Assigned: SeChangeNotifyPrivilege | Information | 1 |
| Jul 15, 2003 11:18:35 AM | Jul 15, 2003 11:18:35 AM | Special privileges assigned to new logon: User Name: administrator Domain: test Logon ID: (0x0,0x16A17) Assigned: SeChangeNotifyPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege | Information | 1 |
| Jul 15, 2003 11:14:15 AM | Jul 15, 2003 11:14:15 AM | Special privileges assigned to new logon: User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) Assigned: SeChangeNotifyPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege | Information | 1 |
| Jul 15, 2003 11:18:20 AM | Jul 15, 2003 11:18:20 AM | Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0xC87C) Assigned: SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeChangeNotifyPrivilege | Information | 1 |
| 58 |
| Jul 15, 2003 11:17:52 AM | Jul 15, 2003 11:24:17 AM | Privileged Service Called: Server: NT Local Security Authority / Authentication Service Service: LsaRegisterLogonProcess() Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: testWS03$ Client Domain: test Client Logon ID: (0x0,0x3E7) Privileges: SeTcbPrivilege | Information | 22 |
| Jul 15, 2003 11:18:55 AM | Jul 15, 2003 11:19:20 AM | Privileged Service Called: Server: Security Service: - Primary User Name: administrator Primary Domain: test Primary Logon ID: (0x0,0x16A17) Client User Name: - Client Domain: - Client Logon ID: - Privileges: SeIncreaseBasePriorityPrivilege | Information | 13 |
| Jul 15, 2003 11:14:19 AM | Jul 15, 2003 11:14:30 AM | Privileged Service Called: Server: Security Service: - Primary User Name: administrator Primary Domain: test Primary Logon ID: (0x0,0x6CB77) Client User Name: - Client Domain: - Client Logon ID: - Privileges: SeIncreaseBasePriorityPrivilege | Information | 13 |
| Jul 15, 2003 11:11:44 AM | Jul 15, 2003 11:13:25 AM | Privileged Service Called: Server: Security Service: - Primary User Name: administrator Primary Domain: test Primary Logon ID: (0x0,0x3412C) Client User Name: - Client Domain: - Client Logon ID: - Privileges: SeIncreaseBasePriorityPrivilege | Information | 6 |
| Jul 15, 2003 11:14:16 AM | Jul 15, 2003 11:14:16 AM | Privileged Service Called: Server: Security Service: - Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: administrator Client Domain: test Client Logon ID: (0x0,0x6CB77) Privileges: SeShutdownPrivilege | Information | 2 |
| Jul 15, 2003 11:18:38 AM | Jul 15, 2003 11:18:38 AM | Privileged Service Called: Server: Security Service: - Primary User Name: testWS03$ Primary Domain: test Primary Logon ID: (0x0,0x3E7) Client User Name: administrator Client Domain: test Client Logon ID: (0x0,0x16A17) Privileges: SeShutdownPrivilege | Information | 2 |
| 2 |
| 66 |
| Jul 15, 2003 12:49:39 PM | Jul 15, 2003 12:49:39 PM | A new process has been created: New Process ID: 1892 Image File Name: \WINNT\system32\taskmgr.exe Creator Process ID: 184 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:14:20 AM | Jul 15, 2003 11:14:20 AM | A new process has been created: New Process ID: 1840 Image File Name: \Program Files\Microsoft Office\Office10\OSA.EXE Creator Process ID: 1940 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:18:57 AM | Jul 15, 2003 11:18:57 AM | A new process has been created: New Process ID: 1644 Image File Name: \Program Files\GetRight\getright.exe Creator Process ID: 548 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:18:53 AM | Jul 15, 2003 11:18:53 AM | A new process has been created: New Process ID: 1576 Image File Name: \WINNT\loadqm.exe Creator Process ID: 548 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:18:14 AM | Jul 15, 2003 11:18:14 AM | A new process has been created: New Process ID: 744 Image File Name: \PROGRA~1\MICROS~4\MSSQL\Binn\sqlservr.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:11:44 AM | Jul 15, 2003 11:11:44 AM | A new process has been created: New Process ID: 1736 Image File Name: \Program Files\MonitorWare\Agent\MWClient.exe Creator Process ID: 1532 User Name: administrator Domain: test Logon ID: (0x0,0x3412C) | Information | 1 |
| Jul 15, 2003 11:18:07 AM | Jul 15, 2003 11:18:07 AM | A new process has been created: New Process ID: 660 Image File Name: \Program Files\Microsoft SQL Server\MSSQL$VSdotNET\Binn\sqlservr.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:18:28 AM | Jul 15, 2003 11:18:28 AM | A new process has been created: New Process ID: 1192 Image File Name: \WINNT\system32\svchost.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:14:16 AM | Jul 15, 2003 11:14:16 AM | A new process has been created: New Process ID: 1940 Image File Name: \WINNT\explorer.exe Creator Process ID: 1868 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:18:53 AM | Jul 15, 2003 11:18:53 AM | A new process has been created: New Process ID: 1592 Image File Name: \WINNT\system32\pwstray.exe Creator Process ID: 548 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:14:19 AM | Jul 15, 2003 11:14:19 AM | A new process has been created: New Process ID: 1948 Image File Name: \WINNT\system32\CMD.EXE Creator Process ID: 1868 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:18:40 AM | Jul 15, 2003 11:18:40 AM | A new process has been created: New Process ID: 1392 Image File Name: \WINNT\system32\CMD.EXE Creator Process ID: 1360 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:18:17 AM | Jul 15, 2003 11:18:17 AM | A new process has been created: New Process ID: 828 Image File Name: \WINNT\system32\PGPsdkServ.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:13:34 AM | Jul 15, 2003 11:13:34 AM | A new process has been created: New Process ID: 1972 Image File Name: \WINNT\system32\taskmgr.exe Creator Process ID: 184 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:14:25 AM | Jul 15, 2003 11:14:25 AM | A new process has been created: New Process ID: 1808 Image File Name: \Program Files\Java\j2re1.4.0_01\bin\rmiregistry.exe Creator Process ID: 1728 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:19:04 AM | Jul 15, 2003 11:19:04 AM | A new process has been created: New Process ID: 1684 Image File Name: \WINNT\system32\mobsync.exe Creator Process ID: 412 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:18:39 AM | Jul 15, 2003 11:18:39 AM | A new process has been created: New Process ID: 1360 Image File Name: \WINNT\system32\USERINIT.EXE Creator Process ID: 184 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:19:04 AM | Jul 15, 2003 11:19:04 AM | A new process has been created: New Process ID: 1712 Image File Name: \Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe Creator Process ID: 548 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:18:27 AM | Jul 15, 2003 11:18:27 AM | A new process has been created: New Process ID: 1180 Image File Name: \WINNT\system32\MsPMSPSv.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:18:35 AM | Jul 15, 2003 11:18:35 AM | A new process has been created: New Process ID: 1320 Image File Name: \WINNT\system32\ipconfig.exe Creator Process ID: 1232 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:18:18 AM | Jul 15, 2003 11:18:18 AM | A new process has been created: New Process ID: 892 Image File Name: \WINNT\system32\mstask.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:14:16 AM | Jul 15, 2003 11:14:16 AM | A new process has been created: New Process ID: 1868 Image File Name: \WINNT\system32\USERINIT.EXE Creator Process ID: 184 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:18:25 AM | Jul 15, 2003 11:18:25 AM | A new process has been created: New Process ID: 1076 Image File Name: \OfficeScan NT\tmlisten.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:18:52 AM | Jul 15, 2003 11:18:52 AM | A new process has been created: New Process ID: 1564 Image File Name: \WINNT\system32\mobsync.exe Creator Process ID: 548 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:17:53 AM | Jul 15, 2003 11:17:53 AM | A new process has been created: New Process ID: 444 Image File Name: \WINNT\system32\spoolsv.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:14:20 AM | Jul 15, 2003 11:14:20 AM | A new process has been created: New Process ID: 1728 Image File Name: \Program Files\Java\j2re1.4.0_01\bin\javaw.exe Creator Process ID: 1940 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:14:19 AM | Jul 15, 2003 11:14:19 AM | A new process has been created: New Process ID: 1820 Image File Name: \Program Files\GetRight\getright.exe Creator Process ID: 1940 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:18:04 AM | Jul 15, 2003 11:18:04 AM | A new process has been created: New Process ID: 540 Image File Name: \PROGRA~1\MONITO~1\Agent\mwagent.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:14:17 AM | Jul 15, 2003 11:14:17 AM | A new process has been created: New Process ID: 1620 Image File Name: \WINNT\loadqm.exe Creator Process ID: 1940 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:24:59 AM | Jul 15, 2003 11:24:59 AM | A new process has been created: New Process ID: 1492 Image File Name: \WINNT\system32\cidaemon.exe Creator Process ID: 560 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:13:25 AM | Jul 15, 2003 11:13:25 AM | A new process has been created: New Process ID: 1976 Image File Name: \WINNT\system32\mmc.exe Creator Process ID: 1532 User Name: administrator Domain: test Logon ID: (0x0,0x3412C) | Information | 1 |
| Jul 15, 2003 11:18:24 AM | Jul 15, 2003 11:18:24 AM | A new process has been created: New Process ID: 1056 Image File Name: \WINNT\system32\stisvc.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:25:25 AM | Jul 15, 2003 11:25:25 AM | A new process has been created: New Process ID: 2020 Image File Name: \WINNT\system32\cidaemon.exe Creator Process ID: 560 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:14:17 AM | Jul 15, 2003 11:14:17 AM | A new process has been created: New Process ID: 1904 Image File Name: \WINNT\system32\mobsync.exe Creator Process ID: 1940 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:18:26 AM | Jul 15, 2003 11:18:26 AM | A new process has been created: New Process ID: 1100 Image File Name: \WINNT\system32\wbem\WinMgmt.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:18:38 AM | Jul 15, 2003 11:18:38 AM | A new process has been created: New Process ID: 1344 Image File Name: \WINNT\system32\wbem\WinMgmt.exe Creator Process ID: 1100 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:14:18 AM | Jul 15, 2003 11:14:18 AM | A new process has been created: New Process ID: 1744 Image File Name: \WINNT\system32\pwstray.exe Creator Process ID: 1940 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:25:23 AM | Jul 15, 2003 11:25:23 AM | A new process has been created: New Process ID: 1988 Image File Name: \WINNT\system32\cidaemon.exe Creator Process ID: 560 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:18:16 AM | Jul 15, 2003 11:18:16 AM | A new process has been created: New Process ID: 768 Image File Name: \OfficeScan NT\ntrtscan.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:19:11 AM | Jul 15, 2003 11:19:11 AM | A new process has been created: New Process ID: 1764 Image File Name: \Program Files\MonitorWare\Agent\MWClient.exe Creator Process ID: 548 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:19:02 AM | Jul 15, 2003 11:19:02 AM | A new process has been created: New Process ID: 1680 Image File Name: \Program Files\Java\j2re1.4.0_01\bin\javaw.exe Creator Process ID: 548 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:18:40 AM | Jul 15, 2003 11:18:40 AM | A new process has been created: New Process ID: 548 Image File Name: \WINNT\explorer.exe Creator Process ID: 1360 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:19:31 AM | Jul 15, 2003 11:19:31 AM | A new process has been created: New Process ID: 1728 Image File Name: \Program Files\Java\j2re1.4.0_01\bin\rmiregistry.exe Creator Process ID: 1680 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:14:20 AM | Jul 15, 2003 11:14:20 AM | A new process has been created: New Process ID: 1804 Image File Name: \Program Files\Network Associates\PGP for Windows 2000\PGPtray.exe Creator Process ID: 1940 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:18:54 AM | Jul 15, 2003 11:18:54 AM | A new process has been created: New Process ID: 1620 Image File Name: \OfficeScan NT\PccNTMon.exe Creator Process ID: 548 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:18:06 AM | Jul 15, 2003 11:18:06 AM | A new process has been created: New Process ID: 608 Image File Name: \Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:18:32 AM | Jul 15, 2003 11:18:32 AM | A new process has been created: New Process ID: 1248 Image File Name: \WINNT\system32\ipconfig.exe Creator Process ID: 1232 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:18:28 AM | Jul 15, 2003 11:18:28 AM | A new process has been created: New Process ID: 1220 Image File Name: \Program Files\Intel\Intel(R) Active Monitor\imonNT.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:19:00 AM | Jul 15, 2003 11:19:00 AM | A new process has been created: New Process ID: 1664 Image File Name: \Program Files\Microsoft Office\Office10\OSA.EXE Creator Process ID: 548 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:14:30 AM | Jul 15, 2003 11:14:30 AM | A new process has been created: New Process ID: 1488 Image File Name: \WINNT\system32\mmc.exe Creator Process ID: 1940 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 10:37:26 AM | Jul 15, 2003 10:37:26 AM | A new process has been created: New Process ID: 1856 Image File Name: \PROGRA~1\MONITO~1\Agent\mwagent.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:18:55 AM | Jul 15, 2003 11:18:55 AM | A new process has been created: New Process ID: 1636 Image File Name: \Program Files\Messenger\msmsgs.exe Creator Process ID: 548 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:14:20 AM | Jul 15, 2003 11:14:20 AM | A new process has been created: New Process ID: 1768 Image File Name: \Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe Creator Process ID: 1940 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:12:18 AM | Jul 15, 2003 11:12:18 AM | A new process has been created: New Process ID: 1576 Image File Name: \WINNT\system32\mmc.exe Creator Process ID: 1532 User Name: administrator Domain: test Logon ID: (0x0,0x3412C) | Information | 1 |
| Jul 15, 2003 11:14:19 AM | Jul 15, 2003 11:14:19 AM | A new process has been created: New Process ID: 1844 Image File Name: \Program Files\Messenger\msmsgs.exe Creator Process ID: 1940 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:18:18 AM | Jul 15, 2003 11:18:18 AM | A new process has been created: New Process ID: 876 Image File Name: \WINNT\system32\regsvc.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:18:05 AM | Jul 15, 2003 11:18:05 AM | A new process has been created: New Process ID: 560 Image File Name: \WINNT\system32\cisvc.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:19:21 AM | Jul 15, 2003 11:19:21 AM | A new process has been created: New Process ID: 1900 Image File Name: \WINNT\system32\inetsrv\inetinfo.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:18:30 AM | Jul 15, 2003 11:18:30 AM | A new process has been created: New Process ID: 1232 Image File Name: \Program Files\Network Associates\PGP for Windows 2000\PGPservice.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:20:02 AM | Jul 15, 2003 11:20:02 AM | A new process has been created: New Process ID: 1724 Image File Name: \WINNT\system32\wuauclt.exe Creator Process ID: 1192 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:14:18 AM | Jul 15, 2003 11:14:18 AM | A new process has been created: New Process ID: 1832 Image File Name: \OfficeScan NT\PccNTMon.exe Creator Process ID: 1940 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:19:03 AM | Jul 15, 2003 11:19:03 AM | A new process has been created: New Process ID: 1572 Image File Name: \Program Files\Network Associates\PGP for Windows 2000\PGPtray.exe Creator Process ID: 548 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:14:08 AM | Jul 15, 2003 11:14:08 AM | A new process has been created: New Process ID: 1656 Image File Name: \WINNT\system32\mobsync.exe Creator Process ID: 184 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:14:21 AM | Jul 15, 2003 11:14:21 AM | A new process has been created: New Process ID: 1780 Image File Name: \WINNT\system32\wuauclt.exe Creator Process ID: 1164 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:18:05 AM | Jul 15, 2003 11:18:05 AM | A new process has been created: New Process ID: 588 Image File Name: \WINNT\system32\svchost.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:17:53 AM | Jul 15, 2003 11:17:53 AM | A new process has been created: New Process ID: 412 Image File Name: \WINNT\system32\svchost.exe Creator Process ID: 212 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| 33 |
| Jul 15, 2003 11:15:01 AM | Jul 15, 2003 11:15:01 AM | A process has exited: Process ID: 1744 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:19:14 AM | Jul 15, 2003 11:19:14 AM | A process has exited: Process ID: 1664 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:18:35 AM | Jul 15, 2003 11:18:35 AM | A process has exited: Process ID: 1248 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:14:05 AM | Jul 15, 2003 11:14:05 AM | A process has exited: Process ID: 1732 User Name: administrator Domain: test Logon ID: (0x0,0x3412C) | Information | 1 |
| Jul 15, 2003 11:14:00 AM | Jul 15, 2003 11:14:00 AM | A process has exited: Process ID: 1972 User Name: administrator Domain: test Logon ID: (0x0,0x3412C) | Information | 1 |
| Jul 15, 2003 11:14:05 AM | Jul 15, 2003 11:14:05 AM | A process has exited: Process ID: 1888 User Name: administrator Domain: test Logon ID: (0x0,0x3412C) | Information | 1 |
| Jul 15, 2003 11:19:04 AM | Jul 15, 2003 11:19:04 AM | A process has exited: Process ID: 1684 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:14:04 AM | Jul 15, 2003 11:14:04 AM | A process has exited: Process ID: 1676 User Name: administrator Domain: test Logon ID: (0x0,0x3412C) | Information | 1 |
| Jul 15, 2003 11:14:21 AM | Jul 15, 2003 11:14:21 AM | A process has exited: Process ID: 1904 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:14:05 AM | Jul 15, 2003 11:14:05 AM | A process has exited: Process ID: 1576 User Name: administrator Domain: test Logon ID: (0x0,0x3412C) | Information | 1 |
| Jul 15, 2003 11:19:02 AM | Jul 15, 2003 11:19:02 AM | A process has exited: Process ID: 1564 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:14:20 AM | Jul 15, 2003 11:14:20 AM | A process has exited: Process ID: 1948 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:14:21 AM | Jul 15, 2003 11:14:21 AM | A process has exited: Process ID: 1840 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:15:05 AM | Jul 15, 2003 11:15:05 AM | A process has exited: Process ID: 1728 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:15:01 AM | Jul 15, 2003 11:15:01 AM | A process has exited: Process ID: 1820 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:13:30 AM | Jul 15, 2003 11:13:30 AM | A process has exited: Process ID: 1976 User Name: administrator Domain: test Logon ID: (0x0,0x3412C) | Information | 1 |
| Jul 15, 2003 11:14:08 AM | Jul 15, 2003 11:14:08 AM | A process has exited: Process ID: 1656 User Name: administrator Domain: test Logon ID: (0x0,0x3412C) | Information | 1 |
| Jul 15, 2003 11:14:24 AM | Jul 15, 2003 11:14:24 AM | A process has exited: Process ID: 1620 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:15:01 AM | Jul 15, 2003 11:15:01 AM | A process has exited: Process ID: 1832 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:15:01 AM | Jul 15, 2003 11:15:01 AM | A process has exited: Process ID: 1768 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:14:04 AM | Jul 15, 2003 11:14:04 AM | A process has exited: Process ID: 1644 User Name: administrator Domain: test Logon ID: (0x0,0x3412C) | Information | 1 |
| Jul 15, 2003 11:14:04 AM | Jul 15, 2003 11:14:04 AM | A process has exited: Process ID: 1488 User Name: administrator Domain: test Logon ID: (0x0,0x3412C) | Information | 1 |
| Jul 15, 2003 11:14:23 AM | Jul 15, 2003 11:14:23 AM | A process has exited: Process ID: 1804 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:14:05 AM | Jul 15, 2003 11:14:05 AM | A process has exited: Process ID: 1852 User Name: administrator Domain: test Logon ID: (0x0,0x3412C) | Information | 1 |
| Jul 15, 2003 11:15:01 AM | Jul 15, 2003 11:15:01 AM | A process has exited: Process ID: 1780 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:15:05 AM | Jul 15, 2003 11:15:05 AM | A process has exited: Process ID: 1808 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| Jul 15, 2003 11:14:05 AM | Jul 15, 2003 11:14:05 AM | A process has exited: Process ID: 1748 User Name: administrator Domain: test Logon ID: (0x0,0x3412C) | Information | 1 |
| Jul 15, 2003 11:18:41 AM | Jul 15, 2003 11:18:41 AM | A process has exited: Process ID: 1392 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:19:03 AM | Jul 15, 2003 11:19:03 AM | A process has exited: Process ID: 1576 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:18:35 AM | Jul 15, 2003 11:18:35 AM | A process has exited: Process ID: 1320 User Name: testWS03$ Domain: test Logon ID: (0x0,0x3E7) | Information | 1 |
| Jul 15, 2003 11:19:19 AM | Jul 15, 2003 11:19:19 AM | A process has exited: Process ID: 1572 User Name: administrator Domain: test Logon ID: (0x0,0x16A17) | Information | 1 |
| Jul 15, 2003 11:13:56 AM | Jul 15, 2003 11:13:56 AM | A process has exited: Process ID: 1736 User Name: administrator Domain: test Logon ID: (0x0,0x3412C) | Information | 1 |
| Jul 15, 2003 11:14:37 AM | Jul 15, 2003 11:14:37 AM | A process has exited: Process ID: 1488 User Name: administrator Domain: test Logon ID: (0x0,0x6CB77) | Information | 1 |
| 1 |
| 9 |
| 3 |
| 1 |
| 1 |
| 1 |
| 3 |
| 2 |
| 1 |
| 1 |
| 1 |
| 2 |
| 2 |
| 2000 |
| Timeanalysis | |
| Database Query Time: | 0 minutes, 0 seconds |
| Report Processing Time: | 0 minutes, 1 seconds |
| Total Processing Time: | 0 minutes, 1 seconds |