AIDA64 Extreme

 
Version  AIDA64 v4.00.2700
Benchmark Module  4.1.591-x32
Homepage  http://www.aida64.com/
Report Type  Quick Report [ TRIAL VERSION ]
Computer  T100
Generator  Transformer T100
Operating System  Microsoft Windows 8.1 6.3.9600.16384 (Win8.1 RTM)
Date  2013-11-29
Time  02:46


Summary

 
Computer:
Computer Type  ACPI x86-based PC
Operating System  Microsoft Windows 8.1
OS Service Pack  [ TRIAL VERSION ]
Internet Explorer  11.0.9600.16384 (IE 11.0)
DirectX  DirectX 11.0
Computer Name  T100
User Name  Transformer T100
Logon Domain  [ TRIAL VERSION ]
Date / Time  2013-11-29 / 02:46
 
Motherboard:
CPU Type  QuadCore Intel Atom Z3740, 1866 MHz (14 x 133)
Motherboard Name  Asus Transformer Book T100TA
Motherboard Chipset  Intel Bay Trail-T
System Memory  [ TRIAL VERSION ]
BIOS Type  Unknown (09/22/2013)
 
Display:
Video Adapter  Intel(R) HD Graphics (1055352 KB)
Video Adapter  Intel(R) HD Graphics (1055352 KB)
3D Accelerator  Intel HD Graphics
Monitor  Generic PnP Monitor [NoDB]
Monitor  Intel Imaging Signal Processor 2400
 
Storage:
Storage Controller  Microsoft Storage Spaces Controller
Storage Controller  SD Storage Class Controller
Disk Drive  Hynix HCG8e (58 GB)
SMART Hard Disks Status  Unknown
 
Partitions:
C: (NTFS)  [ TRIAL VERSION ]
Total Size  [ TRIAL VERSION ]
 
Input:
Keyboard  HID Keyboard Device
Keyboard  HID Keyboard Device
Mouse  ASUS Touchpad
 
Network:
Primary IP Address  [ TRIAL VERSION ]
Primary MAC Address  74-D0-2B-69-F0-B1
Network Adapter  Bluetooth Device (Personal Area Network)
Network Adapter  Broadcom 802.11abgn Wireless SDIO Adapter (192. [ TRIAL VERSION ])
Network Adapter  Microsoft Wi-Fi Direct Virtual Adapter
 
Peripherals:
Printer  Fax
Printer  Microsoft XPS Document Writer
USB3 Controller  Intel Bay Trail SoC - USB 3.0 xHCI Host Controller
USB Device  USB Composite Device
USB Device  USB Input Device
USB Device  USB Input Device
USB Device  USB Input Device
Battery  Microsoft AC Adapter
Battery  Microsoft ACPI-Compliant Control Method Battery
 
DMI:
DMI BIOS Vendor  American Megatrends Inc.
DMI BIOS Version  T100TA.214
DMI System Manufacturer  ASUSTeK COMPUTER INC.
DMI System Product  T100TA
DMI System Version  1.0
DMI System Serial Number  [ TRIAL VERSION ]
DMI System UUID  [ TRIAL VERSION ]
DMI Motherboard Manufacturer  ASUSTeK COMPUTER INC.
DMI Motherboard Product  T100TA
DMI Motherboard Version  1.0
DMI Motherboard Serial Number  [ TRIAL VERSION ]
DMI Chassis Manufacturer  ASUSTeK COMPUTER INC.
DMI Chassis Version  1.0
DMI Chassis Serial Number  [ TRIAL VERSION ]
DMI Chassis Asset Tag  [ TRIAL VERSION ]
DMI Chassis Type  Notebook


Computer Name

 
Type  Class  Computer Name
Computer Comment  Logical  
NetBIOS Name  Logical  T100
DNS Host Name  Logical  T100
DNS Domain Name  Logical  
Fully Qualified DNS Name  Logical  T100
NetBIOS Name  Physical  T100
DNS Host Name  Physical  T100
DNS Domain Name  Physical  
Fully Qualified DNS Name  Physical  T100


DMI

 
[ BIOS ]
 
BIOS Properties:
Vendor  American Megatrends Inc.
Version  T100TA.214
Release Date  09/22/2013
Size  1 MB
System BIOS Version  5.6
Boot Devices  Floppy Disk, Hard Disk, CD-ROM
Capabilities  Flash BIOS, Shadow BIOS, Selectable Boot, EDD, BBS, Smart Battery
Supported Standards  DMI, ACPI, UEFI
Expansion Capabilities  PCI, USB
Virtual Machine  No
 
BIOS Manufacturer:
Company Name  American Megatrends Inc.
Product Information  http://www.ami.com/amibios
BIOS Upgrades  http://www.aida64.com/bios-updates
 
[ System ]
 
System Properties:
Manufacturer  ASUSTeK COMPUTER INC.
Product  T100TA
Version  1.0
Serial Number  [ TRIAL VERSION ]
SKU#  ASUS-TabletSKU
Family  T
Universal Unique ID  [ TRIAL VERSION ]
Wake-Up Type  Power Switch
 
[ Motherboard ]
 
Motherboard Properties:
Manufacturer  ASUSTeK COMPUTER INC.
Product  T100TA
Version  1.0
Serial Number  [ TRIAL VERSION ]
Asset Tag  [ TRIAL VERSION ]
Asset Tag  [ TRIAL VERSION ]
Asset Tag  [ TRIAL VERSION ]
 
Motherboard Manufacturer:
Company Name  ASUSTeK Computer Inc.
Product Information  http://www.asus.com/Motherboards
BIOS Download  http://support.asus.com/download/download.aspx?SLanguage=en-us
Driver Update  http://www.aida64.com/driver-updates
BIOS Upgrades  http://www.aida64.com/bios-updates
 
[ Chassis ]
 
Chassis Properties:
Manufacturer  ASUSTeK COMPUTER INC.
Version  1.0
Serial Number  [ TRIAL VERSION ]
Asset Tag  [ TRIAL VERSION ]
Chassis Type  Notebook
Boot-Up State  Safe
Power Supply State  Safe
Thermal State  Safe
Security Status  None
 
[ Processors / Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz ]
 
Processor Properties:
Manufacturer  Intel
Version  Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz
Asset Tag  Fill By OEM
Part Number  Fill By OEM
External Clock  133 MHz
Maximum Clock  2400 MHz
Current Clock  1330 MHz
Type  Central Processor
Voltage  1.2 V
Status  Enabled
Upgrade  Socket LGA1155
Socket Designation  SOCKET 0
HTT / CMP Units  1 / 4
Capabilities  64-bit
 
CPU Manufacturer:
Company Name  Intel Corporation
Product Information  http://ark.intel.com/search.aspx?q=Intel Atom Z3740
Driver Update  http://www.aida64.com/driver-updates
 
[ Caches / CPU Internal L1 ]
 
Cache Properties:
Type  Internal
Status  Enabled
Operational Mode  Write-Back
Maximum Size  224 KB
Installed Size  224 KB
Error Correction  Single-bit ECC
Socket Designation  CPU Internal L1
 
[ Caches / CPU Internal L2 ]
 
Cache Properties:
Type  Internal
Status  Enabled
Operational Mode  Write-Back
Associativity  16-way Set-Associative
Maximum Size  1024 KB
Installed Size  1024 KB
Error Correction  Single-bit ECC
Socket Designation  CPU Internal L2
 
[ Memory Arrays / System Memory ]
 
Memory Array Properties:
Location  Motherboard
Memory Array Function  System Memory
Error Correction  Multi-bit ECC
Max. Memory Capacity  64 GB
Memory Devices  2
 
[ Memory Devices / A1_DIMM0 ]
 
Memory Device Properties:
Form Factor  DIMM
Type  DDR3
Size  1 GB
Max. Clock Speed  1066 MHz
Current Clock Speed  1066 MHz
Total Width  8-bit
Data Width  64-bit
Device Locator  A1_DIMM0
Bank Locator  A1_BANK0
Manufacturer  A1_Manufacturer0
Serial Number  A1_SerNum0
Asset Tag  A1_AssetTagNum0
Part Number  Array1_PartNumber0
 
[ Memory Devices / A1_DIMM1 ]
 
Memory Device Properties:
Form Factor  DIMM
Type  DDR3
Size  1 GB
Max. Clock Speed  1066 MHz
Current Clock Speed  1066 MHz
Total Width  8-bit
Data Width  64-bit
Device Locator  A1_DIMM1
Bank Locator  A1_BANK1
Manufacturer  A1_Manufacturer1
Serial Number  A1_SerNum1
Asset Tag  A1_AssetTagNum1
Part Number  Array1_PartNumber1
 
[ On-Board Devices / VGA ]
 
On-Board Device Properties:
Description  VGA
Type  Video
Status  Enabled
 
[ On-Board Devices / GLAN ]
 
On-Board Device Properties:
Description  GLAN
Type  Ethernet
Status  Enabled
 
[ On-Board Devices / WLAN ]
 
On-Board Device Properties:
Description  WLAN
Type  Ethernet
Status  Enabled
 
[ Intel vPro ]
 
Intel vPro Properties:
ME Firmware Version  1.0.0.1057
AMT  Not Supported
Anti-Theft  Not Supported
Anti-Theft PBA for Recovery  Supported
Anti-Theft WWAN  Not Supported
BIOS TXT  Not Supported
BIOS VT-d  Not Supported
BIOS VT-x  Not Supported
CPU VT-x  Not Supported
CPU TXT  Not Supported
KVM  Not Supported
Local Wakeup Timer  Not Supported
Management Engine  Enabled
Small Business Advantage  Not Supported
Standard Manageability  Not Supported
 
[ Miscellaneous ]
 
Miscellaneous:
OEM String  90NB0451-S00020
System Configuration Option  SMI:00B2CA


Overclock

 
CPU Properties:
CPU Type  QuadCore Intel Atom Z3740
CPU Alias  Bay Trail-T
CPU Stepping  B2
Engineering Sample  No
CPUID CPU Name  Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz
CPUID Revision  00030673h
CPU VID  0.3900 V
 
CPU Speed:
CPU Clock  1866.7 MHz (original: [ TRIAL VERSION ] MHz, overclock: 40%)
CPU Multiplier  14x
CPU FSB  133.3 MHz (original: 133 MHz)
Memory Bus  533.3 MHz
DRAM:FSB Ratio  16:4
 
CPU Cache:
L1 Code Cache  32 KB per core
L1 Data Cache  [ TRIAL VERSION ]
L2 Cache  2x 1 MB (On-Die, ECC, Full-Speed)
 
Motherboard Properties:
Motherboard ID  <DMI>
Motherboard Name  Asus Transformer Book T100TA
 
Chipset Properties:
Motherboard Chipset  Intel Bay Trail-T
Memory Timings  8-10-8-32 (CL-RCD-RP-RAS)
Command Rate (CR)  [ TRIAL VERSION ]
 
BIOS Properties:
System BIOS Date  09/22/2013
Video BIOS Date  Unknown
DMI BIOS Version  T100TA.214
 
Graphics Processor Properties:
Video Adapter  Intel Bay Trail-T SoC - Integrated Graphics Controller
GPU Code Name  Bay Trail-T (Integrated 8086 / 0F31, Rev 09)
GPU Clock  400 MHz


Power Management

 
Power Management Properties:
Current Power Source  Battery
Battery Status  99 % (High Level)
Full Battery Lifetime  Unknown
Remaining Battery Lifetime  45896 sec (12 hours, 44 min, 56 sec)
 
Battery Properties:
Device Name  SR Real Battery
Manufacturer  Intel SR 1
Serial Number  123456789
Unique ID  123456789Intel SR 1SR Real Battery
Battery Type  Rechargeable Li-Ion
Designed Capacity  30675 mWh
Fully Charged Capacity  30435 mWh
Current Capacity  30086 mWh (99 %)
Battery Voltage  4.239 V
Charge-Discharge Cycle Count  4
Wear Level  0 %
Power State  Discharging
Discharge Rate  2445 mW


Portable Computer

 
Centrino (Carmel) Platform Compliancy:
CPU: Intel Pentium M (Banias/Dothan)  No (Intel Atom Z3740)
Chipset: Intel i855GM/PM  No (Intel Bay Trail-T)
WLAN: Intel PRO/Wireless  No
System: Centrino Compliant  No
 
Centrino (Sonoma) Platform Compliancy:
CPU: Intel Pentium M (Dothan)  No (Intel Atom Z3740)
Chipset: Intel i915GM/PM  No (Intel Bay Trail-T)
WLAN: Intel PRO/Wireless 2200/2915  No
System: Centrino Compliant  No
 
Centrino (Napa) Platform Compliancy:
CPU: Intel Core (Yonah) / Core 2 (Merom)  No (Intel Atom Z3740)
Chipset: Intel i945GM/PM  No (Intel Bay Trail-T)
WLAN: Intel PRO/Wireless 3945/3965  No
System: Centrino Compliant  No
 
Centrino (Santa Rosa) Platform Compliancy:
CPU: Intel Core 2 (Merom/Penryn)  No (Intel Atom Z3740)
Chipset: Intel GM965/PM965  No (Intel Bay Trail-T)
WLAN: Intel Wireless WiFi Link 4965  No
System: Centrino Compliant  No
 
Centrino 2 (Montevina) Platform Compliancy:
CPU: Intel Core 2 (Penryn)  No (Intel Atom Z3740)
Chipset: Mobile Intel 4 Series  No (Intel Bay Trail-T)
WLAN: Intel WiFi Link 5000 Series  No
System: Centrino 2 Compliant  No
 
Centrino (Calpella) Platform Compliancy:
CPU: Intel Core i3/i5/i7 (Arrandale/Clarksfield)  No (Intel Atom Z3740)
Chipset: Mobile Intel 5 Series  No (Intel Bay Trail-T)
WLAN: Intel Centrino Advanced-N / Ultimate-N / Wireless-N  No
System: Centrino Compliant  No
 
Centrino (Huron River) Platform Compliancy:
CPU: Intel Core i3/i5/i7 (Sandy Bridge-MB)  No (Intel Atom Z3740)
Chipset: Mobile Intel 6 Series  No (Intel Bay Trail-T)
WLAN: Intel Centrino Advanced-N / Ultimate-N / Wireless-N  No
System: Centrino Compliant  No
 
Centrino (Chief River) Platform Compliancy:
CPU: Intel Core i3/i5/i7 (Ivy Bridge-MB)  No (Intel Atom Z3740)
Chipset: Mobile Intel 7 Series  No (Intel Bay Trail-T)
WLAN: Intel Centrino Advanced-N / Ultimate-N / Wireless-N  No
System: Centrino Compliant  No
 
Centrino (Shark Bay-MB) Platform Compliancy:
CPU: Intel Core i3/i5/i7 (Haswell-MB)  No (Intel Atom Z3740)
Chipset: Mobile Intel 8 Series  No (Intel Bay Trail-T)
WLAN: Intel Centrino Advanced-N / Ultimate-N / Wireless-N  No
System: Centrino Compliant  No


Sensor

 
Sensor Properties:
Sensor Type  Intel DPTF (ACPI)
 
Temperatures:
Motherboard  29 °C (84 °F)
CPU  32 °C (90 °F)
CPU GT Cores  9 °C (48 °F)
CPU #1 / Core #1  9 °C (48 °F)
CPU #1 / Core #2  9 °C (48 °F)
CPU #1 / Core #3  10 °C (50 °F)
CPU #1 / Core #4  10 °C (50 °F)
Temperature #1  29 °C (84 °F)
Temperature #2  25 °C (77 °F)
Temperature #3  32 °C (90 °F)
Temperature #4  51 °C (124 °F)
 
Voltage Values:
CPU Core  0.460 V
Battery  4.239 V
 
Power Values:
CPU Package  0.13 W
CPU IA Cores  0.00 W
CPU GT Cores  0.13 W
Battery Charge Rate  -2.44 W


CPU

 
CPU Properties:
CPU Type  QuadCore Intel Atom Z3740, 1866 MHz (14 x 133)
CPU Alias  Bay Trail-T
CPU Stepping  B2
Instruction Set  x86, x86-64, MMX, SSE, SSE2, SSE3, SSSE3, SSE4.1, SSE4.2, AES
Original Clock  [ TRIAL VERSION ]
Engineering Sample  No
L1 Code Cache  32 KB per core
L1 Data Cache  [ TRIAL VERSION ]
L2 Cache  2x 1 MB (On-Die, ECC, Full-Speed)
 
CPU Physical Info:
Package Type  1380 Ball FCBGA
Package Size  17 mm x 17 mm
Process Technology  22 nm, CMOS, Cu, High-K + Metal Gate
Die Size  [ TRIAL VERSION ] mm2
 
CPU Manufacturer:
Company Name  Intel Corporation
Product Information  http://ark.intel.com/search.aspx?q=Intel Atom Z3740
Driver Update  http://www.aida64.com/driver-updates
 
Multi CPU:
CPU #1  Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz, 1333 MHz
CPU #2  Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz, 1333 MHz
CPU #3  Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz, 1333 MHz
CPU #4  Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz, 1333 MHz
 
CPU Utilization:
CPU #1 / Core #1  0 %
CPU #1 / Core #2  0 %
CPU #1 / Core #3  0 %
CPU #1 / Core #4  0 %


CPUID

 
CPUID Properties:
CPUID Manufacturer  GenuineIntel
CPUID CPU Name  Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz
CPUID Revision  00030673h
IA Brand ID  00h (Unknown)
Platform ID  34h / MC 02h (FCBGA1380)
Microcode Update Revision  312h
HTT / CMP Units  0 / 4
Tjmax Temperature  64 °C (147 °F)
CPU Power Limit 1 (Long Duration)  5 W / 2.00 sec (Unlocked)
Max Turbo Boost Multipliers  1C: 14x, 2C: 14x, 3C: 14x, 4C: 14x
 
Instruction Set:
64-bit x86 Extension (AMD64, Intel64)  Supported
AMD 3DNow!  Not Supported
AMD 3DNow! Professional  Not Supported
AMD 3DNowPrefetch  Supported
AMD Enhanced 3DNow!  Not Supported
AMD Extended MMX  Not Supported
AMD FMA4  Not Supported
AMD MisAligned SSE  Not Supported
AMD SSE4A  Not Supported
AMD XOP  Not Supported
Cyrix Extended MMX  Not Supported
Enhanced REP MOVSB/STOSB  Supported
Float-16 Conversion Instructions  Not Supported
IA-64  Not Supported
IA AES Extensions  Supported
IA AVX  Not Supported
IA AVX2  Not Supported
IA AVX-512  Not Supported
IA AVX-512 Conflict Detection Instructions  Not Supported
IA AVX-512 Exponential and Reciprocal Instructions  Not Supported
IA AVX-512 Prefetch Instructions  Not Supported
IA BMI1  Not Supported
IA BMI2  Not Supported
IA FMA  Not Supported
IA MMX  Supported
IA SHA Extensions  Not Supported
IA SSE  Supported
IA SSE2  Supported
IA SSE3  Supported
IA Supplemental SSE3  Supported
IA SSE4.1  Supported
IA SSE4.2  Supported
VIA Alternate Instruction Set  Not Supported
ADCX / ADOX Instruction  Not Supported
CLFLUSH Instruction  Supported
CMPXCHG8B Instruction  Supported
CMPXCHG16B Instruction  Supported
Conditional Move Instruction  Supported
INVPCID Instruction  Not Supported
LAHF / SAHF Instruction  Supported
LZCNT Instruction  Not Supported
MONITOR / MWAIT Instruction  Supported
MOVBE Instruction  Supported
PCLMULQDQ Instruction  Supported
POPCNT Instruction  Supported
PREFETCHWT1 Instruction  Not Supported
RDFSBASE / RDGSBASE / WRFSBASE / WRGSBASE Instruction  Not Supported
RDRAND Instruction  Supported
RDSEED Instruction  Not Supported
RDTSCP Instruction  Supported
SKINIT / STGI Instruction  Not Supported
SYSCALL / SYSRET Instruction  Not Supported
SYSENTER / SYSEXIT Instruction  Supported
Trailing Bit Manipulation Instructions  Not Supported
VIA FEMMS Instruction  Not Supported
 
Security Features:
Advanced Cryptography Engine (ACE)  Not Supported
Advanced Cryptography Engine 2 (ACE2)  Not Supported
Data Execution Prevention (DEP, NX, EDB)  Supported
Hardware Random Number Generator (RNG)  Not Supported
Hardware Random Number Generator 2 (RNG2)  Not Supported
Memory Protection Extensions (MPX)  Not Supported
PadLock Hash Engine (PHE)  Not Supported
PadLock Hash Engine 2 (PHE2)  Not Supported
PadLock Montgomery Multiplier (PMM)  Not Supported
PadLock Montgomery Multiplier 2 (PMM2)  Not Supported
Processor Serial Number (PSN)  Not Supported
Safer Mode Extensions (SMX)  Not Supported
Supervisor Mode Access Prevention (SMAP)  Not Supported
Supervisor Mode Execution Protection (SMEP)  Supported
 
Power Management Features:
Application Power Management (APM)  Not Supported
Automatic Clock Control  Supported
Core C6 State (CC6)  Not Supported
Digital Thermometer  Supported
Dynamic FSB Frequency Switching  Not Supported
Enhanced Halt State (C1E)  Supported, Enabled
Enhanced SpeedStep Technology (EIST, ESS)  Supported, Enabled
Frequency ID Control  Not Supported
Hardware P-State Control  Not Supported
Hardware Thermal Control (HTC)  Not Supported
LongRun  Not Supported
LongRun Table Interface  Not Supported
Overstress  Not Supported
Package C6 State (PC6)  Not Supported
Parallax  Not Supported
PowerSaver 1.0  Not Supported
PowerSaver 2.0  Not Supported
PowerSaver 3.0  Not Supported
Processor Duty Cycle Control  Supported
Software Thermal Control  Not Supported
Temperature Sensing Diode  Not Supported
Thermal Monitor 1  Supported
Thermal Monitor 2  Supported
Thermal Monitor 3  Not Supported
Thermal Monitoring  Not Supported
Thermal Trip  Not Supported
Voltage ID Control  Not Supported
 
Virtualization Features:
Extended Page Table (EPT)  Supported
Hypervisor  Not Present
INVEPT Instruction  Supported
INVVPID Instruction  Supported
Nested Paging (NPT, RVI)  Not Supported
Secure Virtual Machine (SVM, Pacifica)  Not Supported
Virtual Machine Extensions (VMX, Vanderpool)  Supported
Virtual Processor ID (VPID)  Supported
 
CPUID Features:
1 GB Page Size  Not Supported
36-bit Page Size Extension  Supported
64-bit DS Area  Supported
Adaptive Overclocking  Not Supported
Address Region Registers (ARR)  Not Supported
Configurable TDP (cTDP)  Not Supported
Core Performance Boost (CPB)  Not Supported
Core Performance Counters  Not Supported
CPL Qualified Debug Store  Supported
Data Breakpoint Extension  Not Supported
Debug Trace Store  Supported
Debugging Extension  Supported
Deprecated FPU CS and FPU DS  Supported
Direct Cache Access  Not Supported
Dynamic Acceleration Technology (IDA)  Not Supported
Dynamic Configurable TDP (DcTDP)  Not Supported
Extended APIC Register Space  Not Supported
Fast Save & Restore  Supported
Hardware Lock Elision (HLE)  Not Supported
Hybrid Boost  Not Supported
Hyper-Threading Technology (HTT)  Not Supported
Instruction Based Sampling  Not Supported
Invariant Time Stamp Counter  Supported
L1 Context ID  Not Supported
L2I Performance Counters  Not Supported
Lightweight Profiling  Not Supported
Local APIC On Chip  Supported
Machine Check Architecture (MCA)  Supported
Machine Check Exception (MCE)  Supported
Memory Configuration Registers (MCR)  Not Supported
Memory Type Range Registers (MTRR)  Supported
Model Specific Registers (MSR)  Supported
NB Performance Counters  Not Supported
Page Attribute Table (PAT)  Supported
Page Global Extension  Supported
Page Size Extension (PSE)  Supported
Pending Break Event (PBE)  Supported
Performance Time Stamp Counter (PTSC)  Not Supported
Physical Address Extension (PAE)  Supported
Process Context Identifiers (PCID)  Not Supported
Processor Feedback Interface  Not Supported
Processor Trace (PT)  Not Supported
Quality of Service Monitoring (QM)  Not Supported
Restricted Transactional Memory (RTM)  Not Supported
Self-Snoop  Supported
Time Stamp Counter (TSC)  Supported
Turbo Boost  Supported, Enabled
Virtual Mode Extension  Supported
Watchdog Timer  Not Supported
x2APIC  Not Supported
XGETBV / XSETBV OS Enabled  Not Supported
XSAVE / XRSTOR / XSETBV / XGETBV Extended States  Not Supported
XSAVEOPT  Not Supported
 
CPUID Registers (CPU #1):
CPUID 00000000  0000000B-756E6547-6C65746E-49656E69
CPUID 00000001  00030673-00100800-43D8E3BF-BFEBFBFF
CPUID 00000002  61B3A001-0000FFC2-00000000-00000000
CPUID 00000003  00000000-00000000-00000000-00000000
CPUID 00000004  1C000121-0140003F-0000003F-00000001
CPUID 00000004  1C000122-01C0003F-0000003F-00000001
CPUID 00000004  1C00C143-03C0003F-000003FF-00000001
CPUID 00000005  00000040-00000040-00000003-33000020
CPUID 00000006  00000007-00000002-00000009-00000000
CPUID 00000007  00000000-00002282-00000000-00000000
CPUID 00000008  00000000-00000000-00000000-00000000
CPUID 00000009  00000000-00000000-00000000-00000000
CPUID 0000000A  07280203-00000000-00000000-00004503
CPUID 0000000B  00000001-00000001-00000100-00000000
CPUID 0000000B  00000004-00000004-00000201-00000000
CPUID 80000000  80000008-00000000-00000000-00000000
CPUID 80000001  00000000-00000000-00000101-28100000
CPUID 80000002  20202020-20202020-65746E49-2952286C
CPUID 80000003  6F744120-4D54286D-50432029-5A202055
CPUID 80000004  30343733-20402020-33332E31-007A4847
CPUID 80000005  00000000-00000000-00000000-00000000
CPUID 80000006  00000000-00000000-04008040-00000000
CPUID 80000007  00000000-00000000-00000000-00000100
CPUID 80000008  00003024-00000000-00000000-00000000
 
CPUID Registers (CPU #2):
CPUID 00000000  0000000B-756E6547-6C65746E-49656E69
CPUID 00000001  00030673-02100800-43D8E3BF-BFEBFBFF
CPUID 00000002  61B3A001-0000FFC2-00000000-00000000
CPUID 00000003  00000000-00000000-00000000-00000000
CPUID 00000004  1C000121-0140003F-0000003F-00000001
CPUID 00000004  1C000122-01C0003F-0000003F-00000001
CPUID 00000004  1C00C143-03C0003F-000003FF-00000001
CPUID 00000005  00000040-00000040-00000003-33000020
CPUID 00000006  00000007-00000002-00000009-00000000
CPUID 00000007  00000000-00002282-00000000-00000000
CPUID 00000008  00000000-00000000-00000000-00000000
CPUID 00000009  00000000-00000000-00000000-00000000
CPUID 0000000A  07280203-00000000-00000000-00004503
CPUID 0000000B  00000001-00000001-00000100-00000002
CPUID 0000000B  00000004-00000004-00000201-00000002
CPUID 80000000  80000008-00000000-00000000-00000000
CPUID 80000001  00000000-00000000-00000101-28100000
CPUID 80000002  20202020-20202020-65746E49-2952286C
CPUID 80000003  6F744120-4D54286D-50432029-5A202055
CPUID 80000004  30343733-20402020-33332E31-007A4847
CPUID 80000005  00000000-00000000-00000000-00000000
CPUID 80000006  00000000-00000000-04008040-00000000
CPUID 80000007  00000000-00000000-00000000-00000100
CPUID 80000008  00003024-00000000-00000000-00000000
 
CPUID Registers (CPU #3):
CPUID 00000000  0000000B-756E6547-6C65746E-49656E69
CPUID 00000001  00030673-04100800-43D8E3BF-BFEBFBFF
CPUID 00000002  61B3A001-0000FFC2-00000000-00000000
CPUID 00000003  00000000-00000000-00000000-00000000
CPUID 00000004  1C000121-0140003F-0000003F-00000001
CPUID 00000004  1C000122-01C0003F-0000003F-00000001
CPUID 00000004  1C00C143-03C0003F-000003FF-00000001
CPUID 00000005  00000040-00000040-00000003-33000020
CPUID 00000006  00000007-00000002-00000009-00000000
CPUID 00000007  00000000-00002282-00000000-00000000
CPUID 00000008  00000000-00000000-00000000-00000000
CPUID 00000009  00000000-00000000-00000000-00000000
CPUID 0000000A  07280203-00000000-00000000-00004503
CPUID 0000000B  00000001-00000001-00000100-00000004
CPUID 0000000B  00000004-00000004-00000201-00000004
CPUID 80000000  80000008-00000000-00000000-00000000
CPUID 80000001  00000000-00000000-00000101-28100000
CPUID 80000002  20202020-20202020-65746E49-2952286C
CPUID 80000003  6F744120-4D54286D-50432029-5A202055
CPUID 80000004  30343733-20402020-33332E31-007A4847
CPUID 80000005  00000000-00000000-00000000-00000000
CPUID 80000006  00000000-00000000-04008040-00000000
CPUID 80000007  00000000-00000000-00000000-00000100
CPUID 80000008  00003024-00000000-00000000-00000000
 
CPUID Registers (CPU #4):
CPUID 00000000  0000000B-756E6547-6C65746E-49656E69
CPUID 00000001  00030673-06100800-43D8E3BF-BFEBFBFF
CPUID 00000002  61B3A001-0000FFC2-00000000-00000000
CPUID 00000003  00000000-00000000-00000000-00000000
CPUID 00000004  1C000121-0140003F-0000003F-00000001
CPUID 00000004  1C000122-01C0003F-0000003F-00000001
CPUID 00000004  1C00C143-03C0003F-000003FF-00000001
CPUID 00000005  00000040-00000040-00000003-33000020
CPUID 00000006  00000007-00000002-00000009-00000000
CPUID 00000007  00000000-00002282-00000000-00000000
CPUID 00000008  00000000-00000000-00000000-00000000
CPUID 00000009  00000000-00000000-00000000-00000000
CPUID 0000000A  07280203-00000000-00000000-00004503
CPUID 0000000B  00000001-00000001-00000100-00000006
CPUID 0000000B  00000004-00000004-00000201-00000006
CPUID 80000000  80000008-00000000-00000000-00000000
CPUID 80000001  00000000-00000000-00000101-28100000
CPUID 80000002  20202020-20202020-65746E49-2952286C
CPUID 80000003  6F744120-4D54286D-50432029-5A202055
CPUID 80000004  30343733-20402020-33332E31-007A4847
CPUID 80000005  00000000-00000000-00000000-00000000
CPUID 80000006  00000000-00000000-04008040-00000000
CPUID 80000007  00000000-00000000-00000000-00000100
CPUID 80000008  00003024-00000000-00000000-00000000
 
MSR Registers:
MSR 00000017  0004-0000-9014-0E3F [PlatID = 1]
MSR 0000001B  0000-0000-FEE0-0900
MSR 0000002A  0000-0000-4008-0000
MSR 00000035  < FAILED >
MSR 0000008B  0000-0312-0000-0000
MSR 000000CD  0000-0000-0000-0002
MSR 000000CE  0000-0400-0000-0A00
MSR 000000E7  0000-0000-0075-F3A0
MSR 000000E8  0000-0000-00A5-4916
MSR 000000EE  0000-0000-0238-0002
MSR 0000011E  0000-0000-7E28-01FF
MSR 00000194  0000-0000-0000-0000
MSR 00000198  0000-6800-0000-0E3F
MSR 00000199  0000-0000-0000-0E3F
MSR 0000019A  0000-0000-0000-0000
MSR 0000019B  0000-0000-0080-5A01
MSR 0000019C  0000-0000-8836-00C0
MSR 0000019D  0000-0000-0000-0427
MSR 000001A0  0000-0000-0085-0089
MSR 000001A2  0000-0000-0040-0000
MSR 000001A4  < FAILED >
MSR 000001AA  < FAILED >
MSR 000001AC  < FAILED >
MSR 000001AD  0000-0000-0000-0000
MSR 000001B0  0000-0000-0000-0009
MSR 000001B1  < FAILED >
MSR 000001B2  < FAILED >
MSR 000001FC  0000-0000-0000-0002
MSR 00000300  < FAILED >
MSR 00000480  00DA-0400-0000-0002
MSR 00000481  0000-007F-0000-0016
MSR 00000482  FFF9-FFFE-0401-E172
MSR 00000483  007F-FFFF-0003-6DFF
MSR 00000484  0000-FFFF-0000-11FF
MSR 00000485  0000-0000-0004-81E6
MSR 00000486  0000-0000-8000-0021
MSR 00000487  0000-0000-FFFF-FFFF
MSR 00000488  0000-0000-0000-2000
MSR 00000489  0000-0000-0010-27FF
MSR 0000048A  0000-0000-0000-002E
MSR 0000048B  0000-28EF-0000-0000
MSR 0000048C  0000-0F01-0611-4141
MSR 0000048D  0000-007F-0000-0016
MSR 0000048E  FFF9-FFFE-0400-6172
MSR 0000048F  007F-FFFF-0003-6DFB
MSR 00000490  0000-FFFF-0000-11FB
MSR 00000601  0000-0000-0000-0000
MSR 00000602  < FAILED >
MSR 00000603  < FAILED >
MSR 00000604  < FAILED >
MSR 00000606  0000-0000-0000-0505
MSR 0000060A  < FAILED >
MSR 0000060B  < FAILED >
MSR 0000060C  < FAILED >
MSR 0000060D  0000-0000-0000-0000
MSR 00000610  0000-0000-0002-80A0
MSR 00000611  0000-0000-075C-433A
MSR 00000613  < FAILED >
MSR 00000614  < FAILED >
MSR 00000618  < FAILED >
MSR 00000619  < FAILED >
MSR 0000061B  < FAILED >
MSR 0000061C  < FAILED >
MSR 00000638  0000-0000-0000-0000
MSR 00000639  0000-0000-0034-3017
MSR 0000063A  < FAILED >
MSR 0000063B  < FAILED >
MSR 00000640  < FAILED >
MSR 00000641  < FAILED >
MSR 00000642  < FAILED >
MSR 0000066A  0000-0000-000A-0402
MSR 0000066B  0000-0000-0034-2727
MSR 0000066C  0000-0000-0E0E-0E0E
MSR 00000676  0000-0000-0000-0000


Motherboard

 
Motherboard Properties:
Motherboard ID  <DMI>
Motherboard Name  Asus Transformer Book T100TA
 
Front Side Bus Properties:
Bus Type  BCLK
Real Clock  133 MHz
Effective Clock  133 MHz
 
Memory Bus Properties:
Bus Type  Dual DDR3 SDRAM
Bus Width  128-bit
DRAM:FSB Ratio  16:4
Real Clock  533 MHz (DDR)
Effective Clock  1066 MHz
Bandwidth  [ TRIAL VERSION ] MB/s
 
Chipset Bus Properties:
Bus Type  Intel Direct Media Interface
 
Motherboard Manufacturer:
Company Name  ASUSTeK Computer Inc.
Product Information  http://www.asus.com/Motherboards
BIOS Download  http://support.asus.com/download/download.aspx?SLanguage=en-us
Driver Update  http://www.aida64.com/driver-updates
BIOS Upgrades  http://www.aida64.com/bios-updates


Memory

 
Physical Memory:
Total  [ TRIAL VERSION ]
Used  [ TRIAL VERSION ]
Free  813 MB
Utilization  [ TRIAL VERSION ]
 
Swap Space:
Total  3277 MB
Used  2437 MB
Free  840 MB
Utilization  74 %
 
Virtual Memory:
Total  5210 MB
Used  3557 MB
Free  1653 MB
Utilization  68 %
 
Paging File:
Paging File  C:\pagefile.sys
Current Size  1344 MB
Current / Peak Usage  1226 MB / 1296 MB
Utilization  91 %
 
Physical Address Extension (PAE):
Supported by Operating System  Yes
Supported by CPU  Yes
Active  Yes


Chipset

 
[ North Bridge: Intel Bay Trail-T IMC ]
 
North Bridge Properties:
North Bridge  Intel Bay Trail-T IMC
Intel Platform  Bay Trail-T
Supported Memory Types  DDR3-800, DDR3-1066, DDR3-1333 SDRAM
Maximum Memory Amount  4 GB
Revision  09
Process Technology  22 nm
Debug Info  Reg00 = 00C440A1h
Debug Info  Reg01 = 13003551h
Debug Info  Reg02 = 12990301h
Debug Info  Reg03 = 00C60022h
Debug Info  Reg04 = 16C04612h
Debug Info  Reg08 = 02222DDDh
Debug Info  Reg60 = 00000000h
Debug Info  RegB1 = 0000B5B6h
 
Memory Controller:
Type  Dual Channel (128-bit)
Active Mode  Dual Channel (128-bit)
 
Memory Timings:
CAS Latency (CL)  8T
RAS To CAS Delay (tRCD)  10T
RAS Precharge (tRP)  8T
RAS Active Time (tRAS)  32T
Command Rate (CR)  1T
RAS To RAS Delay (tRRD)  4T
Read To Precharge Delay (tRTP)  4T
Write To Precharge Delay (tWTP)  18T
Four Activate Window Delay (tFAW)  41T
 
Error Correction:
ECC  Not Supported
ChipKill ECC  Not Supported
RAID  Not Supported
ECC Scrubbing  Not Supported
 
Memory Slots:
DRAM Slot #1  2 GB (LPDDR3 SDRAM)
 
Integrated Graphics Controller:
Graphics Controller Type  Intel HD Graphics
Graphics Controller Status  Enabled
 
Chipset Manufacturer:
Company Name  Intel Corporation
Product Information  http://www.intel.com/products/chipsets
Driver Download  http://support.intel.com/support/chipsets
BIOS Upgrades  http://www.aida64.com/bios-updates
Driver Update  http://www.aida64.com/driver-updates


BIOS

 
BIOS Properties:
BIOS Type  Unknown
BIOS Version  T100TA.214
System BIOS Date  09/22/2013
Video BIOS Date  Unknown


ACPI

 
[ APIC: Multiple APIC Description Table ]
 
ACPI Table Properties:
ACPI Signature  APIC
Table Description  Multiple APIC Description Table
Memory Address  78D7B000h
Table Length  108 bytes
OEM ID  _ASUS_
OEM Revision  00000003h
Creator ID  AMI
Creator Revision  0100000Dh
Local APIC Address  FEE00000h
 
Processor Local APIC:
ACPI Processor ID  01h
APIC ID  00h
Status  Enabled
 
Processor Local APIC:
ACPI Processor ID  02h
APIC ID  02h
Status  Enabled
 
Processor Local APIC:
ACPI Processor ID  03h
APIC ID  04h
Status  Enabled
 
Processor Local APIC:
ACPI Processor ID  04h
APIC ID  06h
Status  Enabled
 
I/O APIC:
I/O APIC ID  08h
I/O APIC Address  FEC00000h
Global System Interrupt Base  00000000h
 
Interrupt Source Override:
Bus  ISA
Source  IRQ0
Global System Interrupt  00000002h
Polarity  Conforms to the specifications of the bus
Trigger Mode  Conforms to the specifications of the bus
 
Interrupt Source Override:
Bus  ISA
Source  IRQ9
Global System Interrupt  00000009h
Polarity  Active High
Trigger Mode  Level-Triggered
 
[ BGRT: Boot Graphics Resource Table ]
 
ACPI Table Properties:
ACPI Signature  BGRT
Table Description  Boot Graphics Resource Table
Memory Address  78D5F000h
Table Length  56 bytes
OEM ID  _ASUS_
OEM Table ID  Notebook
OEM Revision  01072009h
Creator ID  AMI
Creator Revision  00010013h
 
[ CSRT: Core System Resource Table ]
 
ACPI Table Properties:
ACPI Signature  CSRT
Table Description  Core System Resource Table
Memory Address  78D5E000h
Table Length  332 bytes
OEM ID  ALASKA
OEM Table ID  A M I
OEM Revision  00000005h
Creator ID  MSFT
Creator Revision  0100000Dh
 
[ DBG2: Debug Port Table Type 2 ]
 
ACPI Table Properties:
ACPI Signature  DBG2
Table Description  Debug Port Table Type 2
Memory Address  78D7F000h
Table Length  114 bytes
OEM ID  _ASUS_
OEM Table ID  INTLDBG2
OEM Revision  00000003h
Creator ID  AMI
Creator Revision  0100000Dh
 
[ DSDT: Differentiated System Description Table ]
 
ACPI Table Properties:
ACPI Signature  DSDT
Table Description  Differentiated System Description Table
Memory Address  78D6B000h
Table Length  60729 bytes
OEM ID  _ASUS_
OEM Table ID  Notebook
OEM Revision  00000003h
Creator ID  AMI
Creator Revision  0100000Dh
 
nVIDIA SLI:
SLI Certification  Not Present
PCI 0-0-0-0 (Direct I/O)  8086-0F00 (Intel)
PCI 0-0-0-0 (HAL)  8086-0F00 (Intel)
 
Lucid Virtu:
Virtu Certification  Not Present
 
[ FACP: Fixed ACPI Description Table ]
 
ACPI Table Properties:
ACPI Signature  FACP
Table Description  Fixed ACPI Description Table
Memory Address  78D7E000h
Table Length  268 bytes
OEM ID  _ASUS_
OEM Table ID  A M I
OEM Revision  00000003h
Creator ID  AMI
Creator Revision  0100000Dh
FACS Address  78F00000h / 00000000-78F00000h
DSDT Address  78D6B000h / 00000000-78D6B000h
SMI Command Port  000000B2h
 
[ FACS: Firmware ACPI Control Structure ]
 
ACPI Table Properties:
ACPI Signature  FACS
Table Description  Firmware ACPI Control Structure
Memory Address  78F00000h
Table Length  64 bytes
Hardware Signature  00000000h
Waking Vector  00000000h
Global Lock  00000000h
 
[ FBPT: Firmware Basic Boot Performance Table ]
 
ACPI Table Properties:
ACPI Signature  FBPT
Table Description  Firmware Basic Boot Performance Table
Memory Address  00000000-79A1F848h
Table Length  56 bytes
 
[ FPDT: Firmware Performance Data Table ]
 
ACPI Table Properties:
ACPI Signature  FPDT
Table Description  Firmware Performance Data Table
Memory Address  78D65000h
Table Length  68 bytes
OEM ID  A M I
OEM Table ID  ALASKA
OEM Revision  01072009h
Creator ID  AMI
Creator Revision  00010013h
FBPT Address  00000000-79A1F848h
S3PT Address  00000000-79A1F828h
 
[ HPET: IA-PC High Precision Event Timer Table ]
 
ACPI Table Properties:
ACPI Signature  HPET
Table Description  IA-PC High Precision Event Timer Table
Memory Address  78D7D000h
Table Length  56 bytes
OEM ID  _ASUS_
OEM Table ID  A M I
OEM Revision  00000003h
Creator ID  AMI
Creator Revision  0100000Dh
HPET Address  00000000-FED00000h
Vendor ID  8086h
Revision ID  01h
Number of Timers  3
Counter Size  64-bit
Minimum Clock Ticks  128
Page Protection  No Guarantee
OEM Attribute  0h
LegacyReplacement IRQ Routing  Supported
 
[ LPIT: Low-Power Idle Table ]
 
ACPI Table Properties:
ACPI Signature  LPIT
Table Description  Low-Power Idle Table
Memory Address  78D7C000h
Table Length  260 bytes
OEM ID  _ASUS_
OEM Revision  00000003h
Creator ID  AMI
Creator Revision  0100000Dh
 
[ MCFG: Memory Mapped Configuration Space Base Address Description Table ]
 
ACPI Table Properties:
ACPI Signature  MCFG
Table Description  Memory Mapped Configuration Space Base Address Description Table
Memory Address  78D7A000h
Table Length  60 bytes
OEM ID  _ASUS_
OEM Revision  00000003h
Creator ID  AMI
Creator Revision  0100000Dh
Config Space Address  00000000-E0000000h
PCI Segment  0000h
Start Bus Number  00h
End Bus Number  FFh
 
[ MSDM: Microsoft Data Management Table ]
 
ACPI Table Properties:
ACPI Signature  MSDM
Table Description  Microsoft Data Management Table
Memory Address  00000000-78D53F90h
Table Length  85 bytes
OEM ID  _ASUS_
OEM Table ID  Notebook
OEM Revision  00000000h
Creator ID  ASUS
Creator Revision  00000001h
SLS Version  1
SLS Data Type  1
SLS Data Length  29
SLS Data  2M8YJ-N9996-KD2JQ-J7C9H-9BRWQ
 
[ RSD PTR: Root System Description Pointer ]
 
ACPI Table Properties:
ACPI Signature  RSD PTR
Table Description  Root System Description Pointer
Memory Address  000F0000h
Table Length  36 bytes
OEM ID  _ASUS_
RSDP Revision  2 (ACPI 2.0+)
RSDT Address  78D81074h
XSDT Address  00000000-78D810E8h
 
[ RSDT: Root System Description Table ]
 
ACPI Table Properties:
ACPI Signature  RSDT
Table Description  Root System Description Table
Memory Address  78D81074h
Table Length  116 bytes
OEM ID  _ASUS_
OEM Table ID  A M I
OEM Revision  00000003h
Creator ID  MSFT
Creator Revision  0100000Dh
RSDT Entry #0  78D7E000h (FACP)
RSDT Entry #1  78D80000h (TCPA)
RSDT Entry #2  79303000h (UEFI)
RSDT Entry #3  78D7F000h (DBG2)
RSDT Entry #4  78D7D000h (HPET)
RSDT Entry #5  78D7C000h (LPIT)
RSDT Entry #6  78D7B000h (APIC)
RSDT Entry #7  78D7A000h (MCFG)
RSDT Entry #8  78D6A000h (SSDT)
RSDT Entry #9  78D68000h (SSDT)
RSDT Entry #10  78D67000h (SSDT)
RSDT Entry #11  78D66000h (SSDT)
RSDT Entry #12  78D65000h (FPDT)
RSDT Entry #13  78D64000h (SSDT)
RSDT Entry #14  78D63000h (SSDT)
RSDT Entry #15  78D62000h (SSDT)
RSDT Entry #16  78D61000h (SSDT)
RSDT Entry #17  78D60000h (TPM2)
RSDT Entry #18  78D5F000h (BGRT)
RSDT Entry #19  78D5E000h (CSRT)
 
[ S3PT: S3 Performance Table ]
 
ACPI Table Properties:
ACPI Signature  S3PT
Table Description  S3 Performance Table
Memory Address  00000000-79A1F828h
Table Length  32 bytes
 
[ SSDT: Secondary System Description Table ]
 
ACPI Table Properties:
ACPI Signature  SSDT
Table Description  Secondary System Description Table
Memory Address  78D50C10h
Table Length  933 bytes
OEM ID  PmRef
OEM Table ID  Cpu0Cst
OEM Revision  00003001h
Creator ID  INTL
Creator Revision  20061109h
 
[ SSDT: Secondary System Description Table ]
 
ACPI Table Properties:
ACPI Signature  SSDT
Table Description  Secondary System Description Table
Memory Address  78D51A90h
Table Length  851 bytes
OEM ID  PmRef
OEM Table ID  Cpu0Ist
OEM Revision  00003000h
Creator ID  INTL
Creator Revision  20061109h
 
[ SSDT: Secondary System Description Table ]
 
ACPI Table Properties:
ACPI Signature  SSDT
Table Description  Secondary System Description Table
Memory Address  78D52D90h
Table Length  351 bytes
OEM ID  PmRef
OEM Table ID  ApIst
OEM Revision  00003000h
Creator ID  INTL
Creator Revision  20061109h
 
[ SSDT: Secondary System Description Table ]
 
ACPI Table Properties:
ACPI Signature  SSDT
Table Description  Secondary System Description Table
Memory Address  78D52F10h
Table Length  141 bytes
OEM ID  PmRef
OEM Table ID  ApCst
OEM Revision  00003000h
Creator ID  INTL
Creator Revision  20061109h
 
[ SSDT: Secondary System Description Table ]
 
ACPI Table Properties:
ACPI Signature  SSDT
Table Description  Secondary System Description Table
Memory Address  78D61000h
Table Length  1063 bytes
OEM ID  Intel_
OEM Table ID  Tpm2Tabl
OEM Revision  00001000h
Creator ID  INTL
Creator Revision  20061109h
 
[ SSDT: Secondary System Description Table ]
 
ACPI Table Properties:
ACPI Signature  SSDT
Table Description  Secondary System Description Table
Memory Address  78D62000h
Table Length  378 bytes
OEM ID  PmRef
OEM Table ID  ApTst
OEM Revision  00003000h
Creator ID  INTL
Creator Revision  20061109h
 
[ SSDT: Secondary System Description Table ]
 
ACPI Table Properties:
ACPI Signature  SSDT
Table Description  Secondary System Description Table
Memory Address  78D63000h
Table Length  656 bytes
OEM ID  PmRef
OEM Table ID  Cpu0Tst
OEM Revision  00003000h
Creator ID  INTL
Creator Revision  20061109h
 
[ SSDT: Secondary System Description Table ]
 
ACPI Table Properties:
ACPI Signature  SSDT
Table Description  Secondary System Description Table
Memory Address  78D64000h
Table Length  1891 bytes
OEM ID  PmRef
OEM Table ID  CpuPm
OEM Revision  00003000h
Creator ID  INTL
Creator Revision  20061109h
 
[ SSDT: Secondary System Description Table ]
 
ACPI Table Properties:
ACPI Signature  SSDT
Table Description  Secondary System Description Table
Memory Address  78D66000h
Table Length  255 bytes
OEM ID  _ASUS_
OEM Table ID  SoCDptf
OEM Revision  00000003h
Creator ID  AMI
Creator Revision  0100000Dh
 
[ SSDT: Secondary System Description Table ]
 
ACPI Table Properties:
ACPI Signature  SSDT
Table Description  Secondary System Description Table
Memory Address  78D67000h
Table Length  88 bytes
OEM ID  _ASUS_
OEM Table ID  LowPwrM
OEM Revision  00000003h
Creator ID  AMI
Creator Revision  0100000Dh
 
[ SSDT: Secondary System Description Table ]
 
ACPI Table Properties:
ACPI Signature  SSDT
Table Description  Secondary System Description Table
Memory Address  78D68000h
Table Length  6735 bytes
OEM ID  _ASUS_
OEM Table ID  DptfTab
OEM Revision  00000003h
Creator ID  AMI
Creator Revision  0100000Dh
 
[ SSDT: Secondary System Description Table ]
 
ACPI Table Properties:
ACPI Signature  SSDT
Table Description  Secondary System Description Table
Memory Address  78D6A000h
Table Length  1520 bytes
OEM ID  _ASUS_
OEM Table ID  CpuDptf
OEM Revision  00000003h
Creator ID  AMI
Creator Revision  0100000Dh
 
[ TCPA: Trusted Computing Platform Alliance Capabilities Table ]
 
ACPI Table Properties:
ACPI Signature  TCPA
Table Description  Trusted Computing Platform Alliance Capabilities Table
Memory Address  78D80000h
Table Length  50 bytes
OEM Revision  00000000h
Creator Revision  00000000h
 
[ TPM2: TPM 2.0 Hardware Interface Table ]
 
ACPI Table Properties:
ACPI Signature  TPM2
Table Description  TPM 2.0 Hardware Interface Table
Memory Address  78D60000h
Table Length  52 bytes
OEM Revision  00000000h
Creator Revision  00000000h
 
[ UEFI: UEFI ACPI Boot Optimization Table ]
 
ACPI Table Properties:
ACPI Signature  UEFI
Table Description  UEFI ACPI Boot Optimization Table
Memory Address  79303000h
Table Length  66 bytes
OEM Revision  00000000h
Creator Revision  00000000h
 
[ XSDT: Extended System Description Table ]
 
ACPI Table Properties:
ACPI Signature  XSDT
Table Description  Extended System Description Table
Memory Address  00000000-78D810E8h
Table Length  204 bytes
OEM ID  _ASUS_
OEM Table ID  A M I
OEM Revision  00000003h
Creator ID  MSFT
Creator Revision  0100000Dh
XSDT Entry #0  00000000-78D7E000h (FACP)
XSDT Entry #1  00000000-78D80000h (TCPA)
XSDT Entry #2  00000000-79303000h (UEFI)
XSDT Entry #3  00000000-78D7F000h (DBG2)
XSDT Entry #4  00000000-78D7D000h (HPET)
XSDT Entry #5  00000000-78D7C000h (LPIT)
XSDT Entry #6  00000000-78D7B000h (APIC)
XSDT Entry #7  00000000-78D7A000h (MCFG)
XSDT Entry #8  00000000-78D6A000h (SSDT)
XSDT Entry #9  00000000-78D68000h (SSDT)
XSDT Entry #10  00000000-78D67000h (SSDT)
XSDT Entry #11  00000000-78D66000h (SSDT)
XSDT Entry #12  00000000-78D65000h (FPDT)
XSDT Entry #13  00000000-78D64000h (SSDT)
XSDT Entry #14  00000000-78D63000h (SSDT)
XSDT Entry #15  00000000-78D62000h (SSDT)
XSDT Entry #16  00000000-78D61000h (SSDT)
XSDT Entry #17  00000000-78D60000h (TPM2)
XSDT Entry #18  00000000-78D5F000h (BGRT)
XSDT Entry #19  00000000-78D5E000h (CSRT)
XSDT Entry #20  00000000-78D53F90h (MSDM)


Operating System

 
Operating System Properties:
OS Name  Microsoft Windows 8.1
OS Language  English (United States)
OS Installer Language  English (United States)
OS Kernel Type  Multiprocessor Free (32-bit)
OS Version  6.3.9600.16384 (Win8.1 RTM)
OS Service Pack  [ TRIAL VERSION ]
OS Installation Date  2013.11.07.
OS Root  C:\Windows
 
License Information:
Registered Owner  Transformer T100
Registered Organization  
Product ID  00258-60000-05619-AAOEM
Product Key  2M8YJ- [ TRIAL VERSION ]
Product Activation (WPA)  Not Required
 
Current Session:
Computer Name  T100
User Name  Transformer T100
Logon Domain  [ TRIAL VERSION ]
UpTime  28195 sec (0 days, 7 hours, 49 min, 55 sec)
 
Components Version:
Common Controls  6.16
Internet Explorer Updates  [ TRIAL VERSION ]
Windows Mail  6.3.9600.16384 (winblue_rtm.130821-1623)
Windows Media Player  12.0.9600.16384 (winblue_rtm.130821-1623)
Windows Messenger  -
MSN Messenger  -
Internet Information Services (IIS)  [ TRIAL VERSION ]
.NET Framework  4.0.30319.33440 built by: FX45W81RTMREL
Novell Client  -
DirectX  DirectX 11.0
OpenGL  6.3.9600.16384 (winblue_rtm.130821-1623)
ASPI  -
 
Operating System Features:
Debug Version  No
DBCS Version  No
Domain Controller  No
Security Present  No
Network Present  Yes
Remote Session  No
Safe Mode  No
Slow Processor  No
Terminal Services  Yes


Processes

 
Process Name  Process File Name  Type  Used Memory  Used Swap
ACReminderSrv.exe  C:\Program Files\ASUS\ASUS AC Reminder\ACReminderSrv.exe  32-bit  576 KB  828 KB
aida64.exe  C:\Program Files\FinalWire\AIDA64 Extreme\aida64.exe  32-bit  48764 KB  39468 KB
AsPatchTouchPanel.exe  C:\ProgramData\AsTouchPanel\AsPatchTouchPanel.exe  32-bit  844 KB  844 KB
AsusTPCenter.exe  C:\Program Files\ASUS\ASUS Smart Gesture\AsTPCenter\x86\AsusTPCenter.exe  32-bit  1968 KB  4736 KB
AsusTPHelper.exe  C:\Program Files\ASUS\ASUS Smart Gesture\AsTPCenter\x86\AsusTPHelper.exe  32-bit  708 KB  2972 KB
AsusTPLoader.exe  C:\Program Files\ASUS\ASUS Smart Gesture\AsTPCenter\x86\AsusTPLoader.exe  32-bit  884 KB  3580 KB
AsusWSPanel.exe  C:\Program Files\ASUS\WebStorage\2.0.3.226\AsusWSPanel.exe  32-bit  21840 KB  15572 KB
ATKOSD2.exe  C:\Program Files\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe  32-bit  8616 KB  1828 KB
browserchoice.exe  C:\Windows\BrowserChoice\browserchoice.exe  32-bit  1168 KB  1512 KB
DMedia.exe  C:\Program Files\ASUS\ATK Package\ATK Media\DMedia.exe  32-bit  3760 KB  864 KB
DptfPolicyLpmServiceHelper.exe  C:\Windows\System32\DptfPolicyLpmServiceHelper.exe  32-bit  1972 KB  396 KB
Explorer.EXE  C:\Windows\Explorer.EXE  32-bit  67740 KB  39108 KB
FlashUtil_ActiveX.exe  C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe  32-bit  6996 KB  1996 KB
hkcmd.exe  C:\Windows\System32\hkcmd.exe  32-bit  4704 KB  1156 KB
iexplore.exe  C:\Program Files\Internet Explorer\iexplore.exe  32-bit  111 MB  85456 KB
iexplore.exe  C:\Program Files\Internet Explorer\iexplore.exe  32-bit  34884 KB  14304 KB
iexplore.exe  C:\Program Files\Internet Explorer\iexplore.exe  32-bit  184 MB  142 MB
igfxext.exe  C:\Windows\system32\igfxext.exe  32-bit  4392 KB  908 KB
igfxpers.exe  C:\Windows\System32\igfxpers.exe  32-bit  5156 KB  1236 KB
igfxsrvc.exe  C:\Windows\system32\igfxsrvc.exe  32-bit  5440 KB  2164 KB
igfxtray.exe  C:\Windows\System32\igfxtray.exe  32-bit  4640 KB  1248 KB
LiveUpdate.exe  C:\Program Files\ASUS\ASUS Live Update\LiveUpdate.exe  32-bit  3776 KB  31008 KB
QuickGesture.exe  C:\Program Files\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe  32-bit  1012 KB  3584 KB
ReadingModeWatchDogx86.exe  C:\Program Files\ASUS\ASUS Reading Mode\ReadingModeWatchDogx86.exe  32-bit  21172 KB  24104 KB
RtkNGUI.exe  C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe  32-bit  5544 KB  1516 KB
RuntimeBroker.exe  C:\Windows\System32\RuntimeBroker.exe  32-bit  5584 KB  1452 KB
TabTip.exe  C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe  32-bit  6780 KB  1868 KB
taskhostex.exe  C:\Windows\system32\taskhostex.exe  32-bit  10492 KB  4804 KB
WSHost.exe  C:\Windows\WinStore\WSHost.exe  32-bit  14404 KB  4560 KB
WWAHost.exe  C:\Windows\System32\WWAHost.exe  32-bit  5952 KB  7296 KB
WWAHost.exe  C:\Windows\System32\WWAHost.exe  32-bit  24668 KB  10956 KB


System Drivers

 
Driver Name  Driver Description  File Name  Version  Type  State
1394ohci  1394 OHCI Compliant Host Controller  1394ohci.sys  6.3.9600.16384  Kernel Driver  Stopped
3ware  3ware  3ware.sys  5.1.0.51  Kernel Driver  Stopped
ACPI  Microsoft ACPI Driver  ACPI.sys  6.3.9600.16384  Kernel Driver  Running
acpiex  Microsoft ACPIEx Driver  acpiex.sys  6.3.9600.16384  Kernel Driver  Running
acpipagr  ACPI Processor Aggregator Driver  acpipagr.sys  6.3.9600.16384  Kernel Driver  Running
AcpiPmi  ACPI Power Meter Driver  acpipmi.sys  6.3.9600.16384  Kernel Driver  Stopped
acpitime  ACPI Wake Alarm Driver  acpitime.sys  6.3.9600.16384  Kernel Driver  Stopped
ADP80XX  ADP80XX  ADP80XX.SYS  1.0.0.254  Kernel Driver  Stopped
AFD  Ancillary Function Driver for Winsock  afd.sys  6.3.9600.16384  Kernel Driver  Running
AgereSoftModem  Agere Systems Soft Modem  AGRSM.sys  2.2.89.2  Kernel Driver  Stopped
agp440  Intel AGP Bus Filter  agp440.sys  6.3.9600.16384  Kernel Driver  Stopped
ahcache  Application Compatibility Cache  ahcache.sys  6.3.9600.16384  Kernel Driver  Running
AIDA64Driver  FinalWire AIDA64 Kernel Driver  kerneld.x32    Kernel Driver  Running
amdagp  AMD AGP Bus Filter Driver  amdagp.sys  6.3.9600.16384  Kernel Driver  Stopped
AmdK8  AMD K8 Processor Driver  amdk8.sys  6.3.9600.16384  Kernel Driver  Stopped
AmdPPM  AMD Processor Driver  amdppm.sys  6.3.9600.16384  Kernel Driver  Stopped
amdsata  amdsata  amdsata.sys  1.1.4.14  Kernel Driver  Stopped
amdsbs  amdsbs  amdsbs.sys  3.7.1540.43  Kernel Driver  Stopped
amdxata  amdxata  amdxata.sys  1.1.4.14  Kernel Driver  Stopped
AppID  AppID Driver  appid.sys  6.3.9600.16384  Kernel Driver  Stopped
arcsas  Adaptec SAS/SATA-II RAID Storport's Miniport Driver  arcsas.sys  7.2.0.30261  Kernel Driver  Stopped
ASMMAP  ASMMAP  ASMMAP.sys  1.0.9.1  Kernel Driver  Running
AsusHID  ASUS HID Service  AsusHID.sys  3.0.0.13  Kernel Driver  Running
atapi  IDE Channel  atapi.sys  6.3.9600.16384  Kernel Driver  Stopped
ATKWMIACPIIO  ATKWMIACPI Driver  atkwmiacpi.sys  1.0.5.1  Kernel Driver  Running
BasicDisplay  BasicDisplay  BasicDisplay.sys  6.3.9600.16384  Kernel Driver  Running
BasicRender  BasicRender  BasicRender.sys  6.3.9600.16384  Kernel Driver  Running
bcmfn2  bcmfn2 Service  bcmfn2.sys  6.3.9391.6  Kernel Driver  Running
BCMSDH43XX  Broadcom 802.11 SDIO Network Adapter Driver  bcmdhd63.sys  5.93.97.187  Kernel Driver  Running
Beep  Beep      Kernel Driver  Running
bowser  Browser Support Driver  bowser.sys  6.3.9600.16384  File System Driver  Running
BthAvrcpTg  Bluetooth Audio/Video Remote Control HID  BthAvrcpTg.sys  6.3.9600.16384  Kernel Driver  Stopped
BthEnum  Bluetooth Enumerator Service  BthEnum.sys  6.3.9600.16384  Kernel Driver  Running
BthHFEnum  Bluetooth Hands-Free Audio and Call Control HID Enumerator  bthhfenum.sys  6.3.9600.16384  Kernel Driver  Stopped
bthhfhid  Bluetooth Hands-Free Call Control HID  BthHFHid.sys  6.3.9600.16384  Kernel Driver  Stopped
BthLEEnum  Bluetooth Low Energy Driver  BthLEEnum.sys  6.3.9600.16384  Kernel Driver  Running
BthMini  Bluetooth Radio Driver  BTHMINI.sys  6.3.9600.16384  Kernel Driver  Running
BTHMODEM  Bluetooth Serial Communications Driver  bthmodem.sys  6.3.9600.16384  Kernel Driver  Stopped
BthPan  Bluetooth Device (Personal Area Network)  bthpan.sys  6.3.9600.16384  Kernel Driver  Running
BTHPORT  Bluetooth Port Driver  BTHport.sys  6.3.9600.16384  Kernel Driver  Stopped
btwampfl  btwampfl  btwampfl.sys  12.0.0.7403  Kernel Driver  Stopped
BtwSerialBus  Broadcom Serial Bus Driver over UART Bus Enumerator  BtwSerialBus.sys  12.0.0.7010  Kernel Driver  Running
camera  Intel(R) Imaging Signal Processor 2400  camera.sys  6.3.9471.0  Kernel Driver  Running
cdfs  CD/DVD File System Reader  cdfs.sys  6.3.9600.16384  File System Driver  Stopped
cdrom  CD-ROM Driver  cdrom.sys  6.3.9600.16384  Kernel Driver  Stopped
circlass  Consumer IR Devices  circlass.sys  6.3.9600.16384  Kernel Driver  Stopped
CLFS  Common Log (CLFS)  CLFS.sys  6.3.9600.16384  Kernel Driver  Running
CM3218x  CM3218x SPB Driver  WUDFRd.sys  6.3.9600.16384  Kernel Driver  Running
CmBatt  Microsoft ACPI Control Method Battery Driver  CmBatt.sys  6.3.9600.16384  Kernel Driver  Running
CNG  CNG  cng.sys  6.3.9600.16384  Kernel Driver  Running
cnghwassist  CNG Hardware Assist algorithm provider  cnghwassist.sys  6.3.9600.16384  Kernel Driver  Stopped
CompositeBus  Composite Bus Enumerator Driver  CompositeBus.sys  6.3.9600.16384  Kernel Driver  Running
condrv  Console Driver  condrv.sys  6.3.9600.16384  Kernel Driver  Running
CPLMACPI  Capella Micro CPLMACPI Sensor Filter  CPLMACPI.sys  1.0.2.0  Kernel Driver  Running
dam  Desktop Activity Moderator Driver  dam.sys  6.3.9600.16384  Kernel Driver  Running
Dfsc  DFS Namespace Client Driver  dfsc.sys  6.3.9600.16384  File System Driver  Running
disk  Disk Driver  disk.sys  6.3.9600.16384  Kernel Driver  Running
dmvsc  dmvsc  dmvsc.sys  6.3.9600.16384  Kernel Driver  Stopped
DptfDevDBPT  DptfDevDBPT  DptfDevPower.sys  7.1.0.144  Kernel Driver  Running
DptfDevDisplay  DptfDevDisplay  DptfDevDisplay.sys  7.1.0.144  Kernel Driver  Running
DptfDevGen  DptfDevGen  DptfDevGen.sys  7.1.0.144  Kernel Driver  Running
DptfDevProc  DptfDevProc  DptfDevProc.sys  7.1.0.144  Kernel Driver  Running
DptfManager  DptfManager  DptfManager.sys  7.1.0.144  Kernel Driver  Running
drmkaud  Microsoft Trusted Audio Drivers  drmkaud.sys  6.3.9600.16384  Kernel Driver  Stopped
DXGKrnl  LDDM Graphics Subsystem  dxgkrnl.sys  6.3.9600.16384  Kernel Driver  Running
e1iexpress  Intel(R) PRO/1000 PCI Express Network Connection Driver I  e1i6332.sys  12.6.47.0  Kernel Driver  Stopped
EhStorClass  Enhanced Storage Filter Driver  EhStorClass.sys  6.3.9600.16384  Kernel Driver  Running
EhStorTcgDrv  Microsoft driver for storage devices supporting IEEE 1667 and TCG protocols  EhStorTcgDrv.sys  6.3.9600.16384  Kernel Driver  Stopped
ErrDev  Microsoft Hardware Error Device Driver  errdev.sys  6.3.9600.16384  Kernel Driver  Stopped
exfat  exFAT File System Driver      File System Driver  Stopped
fastfat  FAT12/16/32 File System Driver      File System Driver  Running
fdc  Floppy Disk Controller Driver  fdc.sys  6.3.9600.16384  Kernel Driver  Stopped
FileInfo  File Information FS MiniFilter  fileinfo.sys  6.3.9600.16384  File System Driver  Running
Filetrace  Filetrace  filetrace.sys  6.3.9600.16384  File System Driver  Stopped
flpydisk  Floppy Disk Driver  flpydisk.sys  6.3.9600.16384  Kernel Driver  Stopped
FltMgr  FltMgr  fltmgr.sys  6.3.9600.16384  File System Driver  Running
FsDepends  File System Dependency Minifilter  FsDepends.sys  6.3.9600.16384  File System Driver  Stopped
fvevol  BitLocker Drive Encryption Filter Driver  fvevol.sys  6.3.9600.16384  Kernel Driver  Running
FxPPM  Power Framework Processor Driver  fxppm.sys  6.3.9600.16384  Kernel Driver  Stopped
gagp30kx  Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms  gagp30kx.sys  6.3.9600.16384  Kernel Driver  Stopped
gencounter  Microsoft Hyper-V Generation Counter  vmgencounter.sys  6.3.9600.16384  Kernel Driver  Stopped
GPIO  Intel SoC GPIO Controller Driver  iaiogpio.sys  603.9477.2067.21807  Kernel Driver  Running
GPIOClx0101  Microsoft GPIO Class Extension Driver  msgpioclx.sys  6.3.9600.16384  Kernel Driver  Running
GpioVirtual  GPED Virtual GPIO controller driver  iaiogpiovirtual.sys  6.3.9456.0  Kernel Driver  Running
HdAudAddService  Microsoft 1.1 UAA Function Driver for High Definition Audio Service  HdAudio.sys  6.3.9600.16384  Kernel Driver  Stopped
HDAudBus  Microsoft UAA Bus Driver for High Definition Audio  HDAudBus.sys  6.3.9600.16384  Kernel Driver  Stopped
HidBatt  HID UPS Battery Driver  HidBatt.sys  6.3.9600.16384  Kernel Driver  Stopped
HidBth  Microsoft Bluetooth HID Miniport  hidbth.sys  6.3.9600.16384  Kernel Driver  Stopped
hidi2c  Microsoft I2C HID Miniport Driver  hidi2c.sys  6.3.9600.16384  Kernel Driver  Running
HidIr  Microsoft Infrared HID Driver  hidir.sys  6.3.9600.16384  Kernel Driver  Stopped
HIDSwitch  ASUS Wireless Radio Control  AsHIDSwitch.sys  1.0.0.1  Kernel Driver  Running
HidUsb  Microsoft HID Class Driver  hidusb.sys  6.3.9600.16384  Kernel Driver  Running
HpSAMD  HpSAMD  HpSAMD.sys  8.0.4.0  Kernel Driver  Stopped
HTTP  HTTP Service  HTTP.sys  6.3.9600.16384  Kernel Driver  Running
hwpolicy  Hardware Policy Driver  hwpolicy.sys  6.3.9600.16384  Kernel Driver  Stopped
hyperkbd  hyperkbd  hyperkbd.sys  6.3.9600.16384  Kernel Driver  Stopped
HyperVideo  HyperVideo  HyperVideo.sys  6.3.9600.16384  Kernel Driver  Stopped
i8042prt  i8042 Keyboard and PS/2 Mouse Port Driver  i8042prt.sys  6.3.9600.16384  Kernel Driver  Stopped
iaioi2c  Intel(R) Atom(TM) Processor I2C Controller Service  iaioi2c.sys  603.9477.2067.21806  Kernel Driver  Running
iaiospi  Intel(R) Atom(TM) Processor SPI Controller Service  iaiospi.sys  603.9477.2067.21808  Kernel Driver  Running
iaiouart  Intel(R) Atom(TM) Processor UART Controller  iaiouart.sys  6.3.9456.0  Kernel Driver  Running
iaStorA  iaStorA  iaStorA.sys  12.8.0.1016  Kernel Driver  Stopped
iaStorAV  Intel(R) SATA RAID Controller Windows  iaStorAV.sys  12.0.1.1018  Kernel Driver  Stopped
iaStorV  Intel RAID Controller Windows 7  iaStorV.sys  8.6.2.1019  Kernel Driver  Stopped
igfx  igfx  igdkmd32.sys  10.18.10.3286  Kernel Driver  Running
intaud_WaveExtensible  Intel WiDi Audio Device  intelaud.sys  4.5.23.0  Kernel Driver  Stopped
intelide  intelide  intelide.sys  6.3.9600.16384  Kernel Driver  Stopped
intelpep  Intel(R) Power Engine Plug-in Driver  intelpep.sys  6.3.9600.16384  Kernel Driver  Running
intelppm  Intel Processor Driver  intelppm.sys  6.3.9600.16384  Kernel Driver  Running
IntelSST  Intel SST Audio Device (WDM)  isstrtc.sys  603.9477.1948.22218  Kernel Driver  Running
INVN_MotionApps  InvenSense MotionApps Driver  WUDFRd.sys  6.3.9600.16384  Kernel Driver  Running
IpFilterDriver  IP Traffic Filter Driver  ipfltdrv.sys  6.3.9600.16384  Kernel Driver  Stopped
IPMIDRV  IPMIDRV  IPMIDrv.sys  6.3.9600.16384  Kernel Driver  Stopped
IPNAT  IP Network Address Translator  ipnat.sys  6.3.9600.16384  Kernel Driver  Stopped
IRENUM  IR Bus Enumerator  irenum.sys  6.3.9600.16384  Kernel Driver  Stopped
isapnp  isapnp  isapnp.sys  6.3.9600.16384  Kernel Driver  Stopped
iScsiPrt  iScsiPort Driver  msiscsi.sys  6.3.9600.16384  Kernel Driver  Stopped
iwdbus  IWD Bus Enumerator  iwdbus.sys  4.5.23.0  Kernel Driver  Running
kbdclass  Keyboard Class Driver  kbdclass.sys  6.3.9600.16384  Kernel Driver  Running
kbdhid  Keyboard HID Driver  kbdhid.sys  6.3.9600.16384  Kernel Driver  Running
kdnic  Microsoft Kernel Debug Network Miniport (NDIS 6.20)  kdnic.sys  6.1.0.0  Kernel Driver  Running
KSecDD  KSecDD  ksecdd.sys  6.3.9600.16384  Kernel Driver  Running
KSecPkg  KSecPkg  ksecpkg.sys  6.3.9600.16384  Kernel Driver  Running
lltdio  Link-Layer Topology Discovery Mapper I/O Driver  lltdio.sys  6.3.9600.16384  Kernel Driver  Running
LSI_SAS  LSI_SAS  lsi_sas.sys  1.34.3.82  Kernel Driver  Stopped
LSI_SAS2  LSI_SAS2  lsi_sas2.sys  2.0.60.82  Kernel Driver  Stopped
LSI_SAS3  LSI_SAS3  lsi_sas3.sys  2.50.65.1  Kernel Driver  Stopped
LSI_SSS  LSI_SSS  lsi_sss.sys  2.10.61.81  Kernel Driver  Stopped
luafv  UAC File Virtualization  luafv.sys  6.3.9600.16384  File System Driver  Running
MBI  Intel(R) Sideband Fabric Device Service  MBI.sys  6.3.9448.0  Kernel Driver  Running
megasas  megasas  megasas.sys  6.3.9466.0  Kernel Driver  Stopped
megasr  megasr  megasr.sys  15.2.2013.129  Kernel Driver  Stopped
Modem  Modem  modem.sys  6.3.9600.16384  Kernel Driver  Stopped
monitor  Microsoft Monitor Class Function Driver Service  monitor.sys  6.3.9600.16384  Kernel Driver  Running
mouclass  Mouse Class Driver  mouclass.sys  6.3.9600.16384  Kernel Driver  Running
mouhid  Mouse HID Driver  mouhid.sys  6.3.9600.16384  Kernel Driver  Running
mountmgr  Mount Point Manager  mountmgr.sys  6.3.9600.16384  Kernel Driver  Running
mpsdrv  Windows Firewall Authorization Driver  mpsdrv.sys  6.3.9600.16384  Kernel Driver  Running
MRxDAV  WebDav Client Redirector Driver  mrxdav.sys  6.3.9600.16384  File System Driver  Stopped
mrxsmb  SMB MiniRedirector Wrapper and Engine  mrxsmb.sys  6.3.9600.16384  File System Driver  Running
mrxsmb10  SMB 1.x MiniRedirector  mrxsmb10.sys  6.3.9600.16384  File System Driver  Running
mrxsmb20  SMB 2.0 MiniRedirector  mrxsmb20.sys  6.3.9600.16384  File System Driver  Running
MsBridge  Microsoft MAC Bridge  bridge.sys  6.3.9600.16384  Kernel Driver  Stopped
Msfs  Msfs      File System Driver  Running
msgpiowin32  Common Driver for Buttons, DockMode and Laptop/Slate Indicator  msgpiowin32.sys  6.3.9600.16384  Kernel Driver  Running
mshidkmdf  Pass-through HID to KMDF Filter Driver  mshidkmdf.sys  6.3.9600.16384  Kernel Driver  Running
mshidumdf  Pass-through HID to UMDF Driver  mshidumdf.sys  6.3.9600.16384  Kernel Driver  Stopped
msisadrv  msisadrv  msisadrv.sys  6.3.9600.16384  Kernel Driver  Running
MSKSSRV  Microsoft Streaming Service Proxy  MSKSSRV.sys  6.3.9600.16384  Kernel Driver  Stopped
MsLldp  Microsoft Link-Layer Discovery Protocol  mslldp.sys  6.3.9600.16384  Kernel Driver  Stopped
MSPCLOCK  Microsoft Streaming Clock Proxy  MSPCLOCK.sys  6.3.9600.16384  Kernel Driver  Stopped
MSPQM  Microsoft Streaming Quality Manager Proxy  MSPQM.sys  6.3.9600.16384  Kernel Driver  Stopped
MsRPC  MsRPC      Kernel Driver  Stopped
mssmbios  Microsoft System Management BIOS Driver  mssmbios.sys  6.3.9600.16384  Kernel Driver  Running
MSTEE  Microsoft Streaming Tee/Sink-to-Sink Converter  MSTEE.sys  6.3.9600.16384  Kernel Driver  Stopped
MT9M114  Camera Sensor MT9M114  MT9M114.sys  6.3.9471.0  Kernel Driver  Running
MTConfig  Microsoft Input Configuration Driver  MTConfig.sys  6.3.9600.16384  Kernel Driver  Stopped
Mup  Mup  mup.sys  6.3.9600.16384  File System Driver  Running
mvumis  mvumis  mvumis.sys  1.0.5.1015  Kernel Driver  Stopped
NativeWifiP  NativeWiFi Filter  nwifi.sys  6.3.9600.16384  Kernel Driver  Running
NDIS  NDIS System Driver  ndis.sys  6.3.9600.16384  Kernel Driver  Running
NdisCap  Microsoft NDIS Capture  ndiscap.sys  6.3.9600.16384  Kernel Driver  Stopped
NdisImPlatform  Microsoft Network Adapter Multiplexor Protocol  NdisImPlatform.sys  6.3.9600.16384  Kernel Driver  Stopped
NdisTapi  Remote Access NDIS TAPI Driver  ndistapi.sys  6.3.9600.16384  Kernel Driver  Stopped
Ndisuio  NDIS Usermode I/O Protocol  ndisuio.sys  6.3.9600.16384  Kernel Driver  Running
NdisVirtualBus  Microsoft Virtual Network Adapter Enumerator  NdisVirtualBus.sys  6.3.9600.16384  Kernel Driver  Running
NdisWan  Remote Access NDIS WAN Driver  ndiswan.sys  6.3.9600.16384  Kernel Driver  Stopped
NdisWanLegacy  Remote Access LEGACY NDIS WAN Driver  ndiswan.sys  6.3.9600.16384  Kernel Driver  Stopped
NDProxy  NDIS Proxy      Kernel Driver  Stopped
Ndu  Windows Network Data Usage Monitoring Driver  Ndu.sys  6.3.9600.16384  Kernel Driver  Running
NetBIOS  NetBIOS Interface  netbios.sys  6.3.9600.16384  File System Driver  Running
NetBT  NetBT  netbt.sys  6.3.9600.16384  Kernel Driver  Running
netvsc  netvsc  netvsc63.sys  6.3.9600.16384  Kernel Driver  Stopped
NETwNs32  @netwsn00.inf,___ %NIC_Service_DispName_WIN7%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit  Netwsn00.sys  15.4.1.1  Kernel Driver  Stopped
Npfs  Npfs      File System Driver  Running
npsvctrig  Named pipe service trigger provider  npsvctrig.sys  6.3.9600.16384  Kernel Driver  Running
nsiproxy  NSI Proxy Service Driver  nsiproxy.sys  6.3.9600.16384  Kernel Driver  Running
Ntfs  Ntfs      File System Driver  Running
Null  Null      Kernel Driver  Running
nv_agp  NVIDIA nForce AGP Bus Filter  nv_agp.sys  6.3.9600.16384  Kernel Driver  Stopped
nvraid  nvraid  nvraid.sys  10.6.0.22  Kernel Driver  Stopped
nvstor  nvstor  nvstor.sys  10.6.0.22  Kernel Driver  Stopped
Parport  Parallel port driver  parport.sys  6.3.9600.16384  Kernel Driver  Stopped
partmgr  Partition Manager  partmgr.sys  6.3.9600.16384  Kernel Driver  Running
Parvdm  Parvdm  parvdm.sys  6.3.9600.16384  Kernel Driver  Stopped
pci  PCI Bus Driver  pci.sys  6.3.9600.16384  Kernel Driver  Running
pciide  pciide  pciide.sys  6.3.9600.16384  Kernel Driver  Stopped
pcmcia  pcmcia  pcmcia.sys  6.3.9600.16384  Kernel Driver  Stopped
pcw  Performance Counters for Windows Driver  pcw.sys  6.3.9600.16384  Kernel Driver  Running
pdc  pdc  pdc.sys  6.3.9600.16384  Kernel Driver  Running
PEAUTH  PEAUTH  peauth.sys  6.3.9600.16384  Kernel Driver  Running
PMIC  Intel(R) Power Management IC Device Service  PMIC.sys  6.3.9456.0  Kernel Driver  Running
Processor  Processor Driver  processr.sys  6.3.9600.16384  Kernel Driver  Stopped
Psched  QoS Packet Scheduler  pacer.sys  6.3.9600.16384  Kernel Driver  Running
QWAVEdrv  QWAVE driver  qwavedrv.sys  6.3.9600.16384  Kernel Driver  Stopped
RasAcd  Remote Access Auto Connection Driver  rasacd.sys  6.3.9600.16384  Kernel Driver  Stopped
RasPppoe  Remote Access PPPOE Driver  raspppoe.sys  6.3.9600.16384  Kernel Driver  Stopped
rdbss  Redirected Buffering Sub System  rdbss.sys  6.3.9600.16384  File System Driver  Running
rdpbus  Remote Desktop Device Redirector Bus Driver  rdpbus.sys  6.3.9600.16384  Kernel Driver  Running
RDPDR  Remote Desktop Device Redirector Driver  rdpdr.sys  6.3.9600.16384  Kernel Driver  Stopped
RdpVideoMiniport  Remote Desktop Video Miniport Driver  rdpvideominiport.sys  6.3.9600.16384  Kernel Driver  Stopped
rdyboost  ReadyBoost  rdyboost.sys  6.3.9600.16384  Kernel Driver  Running
RFCOMM  Bluetooth Device (RFCOMM Protocol TDI)  rfcomm.sys  6.3.9600.16384  Kernel Driver  Running
rspndr  Link-Layer Topology Discovery Responder  rspndr.sys  6.3.9600.16384  Kernel Driver  Running
rtii2sac  Realtek I2S Audio Codec Device Driver  rtii2sac.sys  6.2.9400.4028  Kernel Driver  Running
RTLU3E8023-W8-32  Realtek USB GBE NIC Family Windows8 32bit Driver  rtu30x86w8.sys  8.3.513.2013  Kernel Driver  Stopped
s3cap  s3cap  vms3cap.sys  6.3.9600.16384  Kernel Driver  Stopped
sbp2port  SBP-2 Transport/Protocol Bus Driver  sbp2port.sys  6.3.9600.16384  Kernel Driver  Stopped
scfilter  Smart card PnP Class Filter Driver  scfilter.sys  6.3.9600.16384  Kernel Driver  Stopped
sdbus  sdbus  sdbus.sys  6.3.9600.16384  Kernel Driver  Running
sdstor  SD Storage Port Driver  sdstor.sys  6.3.9600.16384  Kernel Driver  Running
secdrv  Security Driver      Kernel Driver  Running
SensorsServiceDriver  UMDF Reflector service for SensorsServiceDriver  WUDFRd.sys  6.3.9600.16384  Kernel Driver  Running
SerCx  Serial UART Support Library  SerCx.sys  6.3.9600.16384  Kernel Driver  Stopped
SerCx2  Serial UART Support Library  SerCx2.sys  6.3.9600.16384  Kernel Driver  Running
Serenum  Serenum Filter Driver  serenum.sys  6.3.9600.16384  Kernel Driver  Stopped
Serial  Serial port driver  serial.sys  6.3.9600.16384  Kernel Driver  Stopped
sermouse  Serial Mouse Driver  sermouse.sys  6.3.9600.16384  Kernel Driver  Stopped
sfloppy  High-Capacity Floppy Disk Drive  sfloppy.sys  6.3.9600.16384  Kernel Driver  Stopped
sisagp  SIS AGP Bus Filter  sisagp.sys  6.3.9600.16384  Kernel Driver  Stopped
SiSRaid2  SiSRaid2  SiSRaid2.sys  5.1.1039.2600  Kernel Driver  Stopped
SiSRaid4  SiSRaid4  sisraid4.sys  5.1.1039.3600  Kernel Driver  Stopped
spaceport  Storage Spaces Driver  spaceport.sys  6.3.9600.16384  Kernel Driver  Running
SpbCx  Simple Peripheral Bus Support Library  SpbCx.sys  6.3.9600.16384  Kernel Driver  Running
srv  Server SMB 1.xxx Driver  srv.sys  6.3.9600.16384  File System Driver  Running
srv2  Server SMB 2.xxx Driver  srv2.sys  6.3.9600.16384  File System Driver  Running
srvnet  srvnet  srvnet.sys  6.3.9600.16384  File System Driver  Running
stexstor  stexstor  stexstor.sys  5.1.0.10  Kernel Driver  Stopped
storahci  Microsoft Standard SATA AHCI Driver  storahci.sys  6.3.9600.16384  Kernel Driver  Stopped
storflt  Hyper-V Storage Accelerator  vmstorfl.sys  6.3.9600.16384  Kernel Driver  Stopped
stornvme  Microsoft Standard NVM Express Driver  stornvme.sys  6.3.9600.16384  Kernel Driver  Stopped
storvsc  storvsc  storvsc.sys  6.3.9600.16384  Kernel Driver  Stopped
swenum  Software Bus Driver  swenum.sys  6.3.9600.16384  Kernel Driver  Running
Tcpip  TCP/IP Protocol Driver  tcpip.sys  6.3.9600.16384  Kernel Driver  Running
TCPIP6  Microsoft IPv6 Protocol Driver  tcpip.sys  6.3.9600.16384  Kernel Driver  Stopped
tcpipreg  TCP/IP Registry Compatibility  tcpipreg.sys  6.3.9600.16384  Kernel Driver  Running
tdx  NetIO Legacy TDI Support Driver  tdx.sys  6.3.9600.16384  Kernel Driver  Running
terminpt  Microsoft Remote Desktop Input Driver  terminpt.sys  6.3.9600.16384  Kernel Driver  Stopped
TPM  TPM  tpm.sys  6.3.9600.16384  Kernel Driver  Running
TsUsbFlt  TsUsbFlt  tsusbflt.sys  6.3.9600.16384  Kernel Driver  Stopped
TsUsbGD  Remote Desktop Generic USB Device  TsUsbGD.sys  6.3.9600.16384  Kernel Driver  Stopped
tunnel  Microsoft Tunnel Miniport Adapter Driver  tunnel.sys  6.3.9600.16384  Kernel Driver  Running
TXEI  Intel(R) Trusted Execution Engine Interface   TXEI.sys  1.0.0.1054  Kernel Driver  Running
uagp35  Microsoft AGPv3.5 Filter  uagp35.sys  6.3.9600.16384  Kernel Driver  Stopped
UASPStor  USB Attached SCSI (UAS) Driver  uaspstor.sys  6.3.9600.16384  Kernel Driver  Stopped
UCX01000  USB Controller Extension  ucx01000.sys  6.3.9600.16384  Kernel Driver  Running
udfs  udfs  udfs.sys  6.3.9600.16384  File System Driver  Stopped
UEFI  Microsoft UEFI Driver  UEFI.sys  6.3.9600.16384  Kernel Driver  Running
uliagpkx  Uli AGP Bus Filter  uliagpkx.sys  6.3.9600.16384  Kernel Driver  Stopped
umbus  UMBus Enumerator Driver  umbus.sys  6.3.9600.16384  Kernel Driver  Running
UmPass  Microsoft UMPass Driver  umpass.sys  6.3.9600.16384  Kernel Driver  Stopped
usbccgp  Microsoft USB Generic Parent Driver  usbccgp.sys  6.3.9600.16384  Kernel Driver  Running
usbcir  eHome Infrared Receiver (USBCIR)  usbcir.sys  6.3.9600.16384  Kernel Driver  Stopped
usbehci  Microsoft USB 2.0 Enhanced Host Controller Miniport Driver  usbehci.sys  6.3.9600.16384  Kernel Driver  Stopped
usbhub  Microsoft USB Standard Hub Driver  usbhub.sys  6.3.9600.16384  Kernel Driver  Stopped
USBHUB3  SuperSpeed Hub  UsbHub3.sys  6.3.9600.16384  Kernel Driver  Running
usbohci  Microsoft USB Open Host Controller Miniport Driver  usbohci.sys  6.3.9600.16384  Kernel Driver  Stopped
usbprint  Microsoft USB PRINTER Class  usbprint.sys  6.3.9600.16384  Kernel Driver  Stopped
USBSTOR  USB Mass Storage Driver  USBSTOR.SYS  6.3.9600.16384  Kernel Driver  Stopped
usbuhci  Microsoft USB Universal Host Controller Miniport Driver  usbuhci.sys  6.3.9600.16384  Kernel Driver  Stopped
usbvideo  USB Video Device (WDM)  usbvideo.sys  6.3.9600.16384  Kernel Driver  Stopped
USBXHCI  USB xHCI Compliant Host Controller  USBXHCI.SYS  6.3.9600.16384  Kernel Driver  Running
vdrvroot  Microsoft Virtual Drive Enumerator  vdrvroot.sys  6.3.9600.16384  Kernel Driver  Running
VerifierExt  VerifierExt  VerifierExt.sys  6.3.9600.16384  Kernel Driver  Stopped
vhdmp  vhdmp  vhdmp.sys  6.3.9600.16384  Kernel Driver  Stopped
viaagp  VIA AGP Bus Filter  viaagp.sys  6.3.9600.16384  Kernel Driver  Stopped
ViaC7  VIA C7 Processor Driver  viac7.sys  6.3.9600.16384  Kernel Driver  Stopped
viaide  viaide  viaide.sys  6.0.6000.170  Kernel Driver  Stopped
vmbus  Virtual Machine Bus  vmbus.sys  6.3.9600.16384  Kernel Driver  Stopped
VMBusHID  VMBusHID  VMBusHID.sys  6.3.9600.16384  Kernel Driver  Stopped
volmgr  Volume Manager Driver  volmgr.sys  6.3.9600.16384  Kernel Driver  Running
volmgrx  Dynamic Volume Manager  volmgrx.sys  6.3.9600.16384  Kernel Driver  Running
volsnap  Storage volumes  volsnap.sys  6.3.9600.16384  Kernel Driver  Running
vsmraid  vsmraid  vsmraid.sys  7.0.9200.6320  Kernel Driver  Stopped
VSTXRAID  VIA StorX Storage RAID Controller Windows Driver  vstxraid.sys  8.0.9200.8110  Kernel Driver  Stopped
vwifibus  Virtual WiFi Bus Driver  vwifibus.sys  6.3.9600.16384  Kernel Driver  Running
vwififlt  Virtual WiFi Filter Driver  vwififlt.sys  6.3.9600.16384  Kernel Driver  Running
vwifimp  Virtual WiFi Miniport Service  vwifimp.sys  6.3.9600.16384  Kernel Driver  Running
WacomPen  Wacom Serial Pen HID Driver  wacompen.sys  6.3.9600.16384  Kernel Driver  Stopped
WdBoot  Windows Defender Boot Driver  WdBoot.sys  4.3.9600.16384  Kernel Driver  Stopped
Wdf01000  Kernel Mode Driver Frameworks service  Wdf01000.sys  1.13.9600.16384  Kernel Driver  Running
WdFilter  Windows Defender Mini-Filter Driver  WdFilter.sys  4.3.9600.16384  File System Driver  Running
WdNisDrv  Windows Defender Network Inspection System Driver  WdNisDrv.sys  4.3.9600.16384  Kernel Driver  Running
WFPLWFS  Microsoft Windows Filtering Platform  wfplwfs.sys  6.3.9600.16384  Kernel Driver  Running
WIMMount  WIMMount  wimmount.sys  6.3.9600.16384  File System Driver  Stopped
WinUsb  WinUSB Driver  WinUSB.sys  6.3.9600.16384  Kernel Driver  Stopped
WmiAcpi  Microsoft Windows Management Interface for ACPI  wmiacpi.sys  6.3.9600.16384  Kernel Driver  Running
wpcfltr  Family Safety Filter Driver  wpcfltr.sys  6.3.9600.16384  Kernel Driver  Stopped
WpdUpFltr  WPD Upper Class Filter Driver  WpdUpFltr.sys  6.3.9600.16384  Kernel Driver  Stopped
ws2ifsl  Winsock IFS Driver  ws2ifsl.sys  6.3.9600.16384  Kernel Driver  Stopped
WudfPf  User Mode Driver Frameworks Platform Driver  WudfPf.sys  6.3.9600.16384  Kernel Driver  Running
WUDFRd  Windows Driver Foundation - User-mode Driver Framework Reflector  WUDFRd.sys  6.3.9600.16384  Kernel Driver  Running
WUDFSensorLP  UMDF Reflector service for LocationProvider  WUDFRd.sys  6.3.9600.16384  Kernel Driver  Running


Services

 
Service Name  Service Description  File Name  Version  Type  State  Account
AeLookupSvc  Application Experience  svchost.exe  6.3.9600.16384  Share Process  Running  localSystem
ALG  Application Layer Gateway Service  alg.exe  6.3.9600.16384  Own Process  Stopped  NT AUTHORITY\LocalService
AppIDSvc  Application Identity  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT Authority\LocalService
Appinfo  Application Information  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
AppReadiness  App Readiness  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
AppXSvc  AppX Deployment Service (AppXSVC)  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
AsHidService  ASUS HID Access Service  AsHidSrv.exe  1.0.77.2  Own Process  Running  LocalSystem
ASLDRService  ASLDR Service  ASLDRSrv.exe  1.0.75.1  Own Process  Running  LocalSystem
Asus WebStorage Windows Service  Asus WebStorage Windows Service  AsusWSWinService.exe  1.0.0.0  Own Process  Running  LocalSystem
ATKGFNEXSrv  ATKGFNEX Service  GFNEXSrv.exe  1.0.11.1  Own Process  Running  LocalSystem
AudioEndpointBuilder  Windows Audio Endpoint Builder  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
Audiosrv  Windows Audio  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\LocalService
AxInstSV  ActiveX Installer (AxInstSV)  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
BcmBtRSupport  Bluetooth Driver Management Service  BtwRSupportService.exe  12.0.0.7600  Own Process  Stopped  LocalSystem
BDESVC  BitLocker Drive Encryption Service  svchost.exe  6.3.9600.16384  Share Process  Running  localSystem
BFE  Base Filtering Engine  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\LocalService
BITS  Background Intelligent Transfer Service  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
BrokerInfrastructure  Background Tasks Infrastructure Service  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
Browser  Computer Browser  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
bthserv  Bluetooth Support Service  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\LocalService
CertPropSvc  Certificate Propagation  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
COMSysApp  COM+ System Application  dllhost.exe  6.3.9600.16384  Own Process  Stopped  LocalSystem
cphs  Intel(R) Content Protection HECI Service  IntelCpHeciSvc.exe  9.0.20.9000  Own Process  Stopped  LocalSystem
CryptSvc  Cryptographic Services  svchost.exe  6.3.9600.16384  Share Process  Running  NT Authority\NetworkService
DcomLaunch  DCOM Server Process Launcher  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
defragsvc  Optimize drives  svchost.exe  6.3.9600.16384  Own Process  Stopped  localSystem
DeviceAssociationService  Device Association Service  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
DeviceInstall  Device Install Service  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
Dhcp  DHCP Client  svchost.exe  6.3.9600.16384  Share Process  Running  NT Authority\LocalService
Dnscache  DNS Client  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\NetworkService
dot3svc  Wired AutoConfig  svchost.exe  6.3.9600.16384  Share Process  Stopped  localSystem
DPS  Diagnostic Policy Service  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\LocalService
DptfParticipantProcessorService  Intel(R) Dynamic Platform & Thermal Framework Processor Participant Service Application  DptfParticipantProcessorService.exe  7.0.0.1  Own Process  Running  LocalSystem
DptfPolicyCriticalService  Intel(R) Dynamic Platform & Thermal Framework Critical Service Application  DptfPolicyCriticalService.exe  7.0.0.119  Own Process  Running  LocalSystem
DptfPolicyLpmService  Intel(R) Dynamic Platform & Thermal Framework Low Power Mode Service Application  DptfPolicyLpmService.exe  7.0.0.1  Own Process  Running  LocalSystem
DsmSvc  Device Setup Manager  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
EapHost  Extensible Authentication Protocol  svchost.exe  6.3.9600.16384  Share Process  Stopped  localSystem
EFS  Encrypting File System (EFS)  lsass.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
EventLog  Windows Event Log  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\LocalService
EventSystem  COM+ Event System  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\LocalService
Fax  Fax  fxssvc.exe  6.3.9600.16384  Own Process  Stopped  NT AUTHORITY\NetworkService
fdPHost  Function Discovery Provider Host  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
FDResPub  Function Discovery Resource Publication  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
fhsvc  File History Service  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
FontCache  Windows Font Cache Service  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\LocalService
FontCache3.0.0.0  Windows Presentation Foundation Font Cache 3.0.0.0  PresentationFontCache.exe  3.0.6920.7903  Own Process  Stopped  NT Authority\LocalService
gpsvc  Group Policy Client  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
hidserv  Human Interface Device Service  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
hkmsvc  Health Key and Certificate Management  svchost.exe  6.3.9600.16384  Share Process  Stopped  localSystem
HomeGroupListener  HomeGroup Listener  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
HomeGroupProvider  HomeGroup Provider  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
ICCS  Intel(R) Integrated Clock Controller Service - Intel(R) ICCS  ICCProxy.exe  1.0.0.1  Own Process  Stopped  LocalSystem
IEEtwCollectorService  Internet Explorer ETW Collector Service  IEEtwCollector.exe  11.0.9600.16384  Own Process  Stopped  LocalSystem
IKEEXT  IKE and AuthIP IPsec Keying Modules  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
iphlpsvc  IP Helper  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
KeyIso  CNG Key Isolation  lsass.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
KtmRm  KtmRm for Distributed Transaction Coordinator  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\NetworkService
LanmanServer  Server  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
LanmanWorkstation  Workstation  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\NetworkService
lfsvc  Windows Location Framework Service  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
lltdsvc  Link-Layer Topology Discovery Mapper  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
lmhosts  TCP/IP NetBIOS Helper  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\LocalService
LSM  Local Session Manager  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
MMCSS  Multimedia Class Scheduler  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
MpsSvc  Windows Firewall  svchost.exe  6.3.9600.16384  Share Process  Running  NT Authority\LocalService
MSDTC  Distributed Transaction Coordinator  msdtc.exe  2001.12.10530.16384  Own Process  Stopped  NT AUTHORITY\NetworkService
MSiSCSI  Microsoft iSCSI Initiator Service  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
msiserver  Windows Installer  msiexec.exe  5.0.9600.16384  Own Process  Stopped  LocalSystem
napagent  Network Access Protection Agent  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\NetworkService
NcaSvc  Network Connectivity Assistant  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
NcbService  Network Connection Broker  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
NcdAutoSetup  Network Connected Devices Auto-Setup  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
Netlogon  Netlogon  lsass.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
Netman  Network Connections  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
netprofm  Network List Service  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\LocalService
NetTcpPortSharing  Net.Tcp Port Sharing Service  SMSvcHost.exe  4.0.30319.33440  Share Process  Stopped  NT AUTHORITY\LocalService
NlaSvc  Network Location Awareness  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\NetworkService
nsi  Network Store Interface Service  svchost.exe  6.3.9600.16384  Share Process  Running  NT Authority\LocalService
p2pimsvc  Peer Networking Identity Manager  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
p2psvc  Peer Networking Grouping  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
PcaSvc  Program Compatibility Assistant Service  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
pla  Performance Logs & Alerts  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
PlugPlay  Plug and Play  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
PNRPAutoReg  PNRP Machine Name Publication Service  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
PNRPsvc  Peer Name Resolution Protocol  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
PolicyAgent  IPsec Policy Agent  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT Authority\NetworkService
Power  Power  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
PrintNotify  Printer Extensions and Notifications  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
ProfSvc  User Profile Service  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
QWAVE  Quality Windows Audio Video Experience  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
RasAuto  Remote Access Auto Connection Manager  svchost.exe  6.3.9600.16384  Share Process  Stopped  localSystem
RasMan  Remote Access Connection Manager  svchost.exe  6.3.9600.16384  Share Process  Stopped  localSystem
RemoteAccess  Routing and Remote Access  svchost.exe  6.3.9600.16384  Share Process  Stopped  localSystem
RemoteRegistry  Remote Registry  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
RpcEptMapper  RPC Endpoint Mapper  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\NetworkService
RpcLocator  Remote Procedure Call (RPC) Locator  locator.exe  6.3.9600.16384  Own Process  Stopped  NT AUTHORITY\NetworkService
RpcSs  Remote Procedure Call (RPC)  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\NetworkService
SamSs  Security Accounts Manager  lsass.exe  6.3.9600.16384  Share Process  Running  LocalSystem
SCardSvr  Smart Card  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
ScDeviceEnum  Smart Card Device Enumeration Service  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
Schedule  Task Scheduler  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
SCPolicySvc  Smart Card Removal Policy  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
seclogon  Secondary Logon  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
SENS  System Event Notification Service  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
SensrSvc  Sensor Monitoring Service  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\LocalService
SessionEnv  Remote Desktop Configuration  svchost.exe  6.3.9600.16384  Share Process  Stopped  localSystem
SharedAccess  Internet Connection Sharing (ICS)  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
ShellHWDetection  Shell Hardware Detection  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
smphost  Microsoft Storage Spaces SMP  svchost.exe  6.3.9600.16384  Own Process  Stopped  NT AUTHORITY\NetworkService
SNMPTRAP  SNMP Trap  snmptrap.exe  6.3.9600.16384  Own Process  Stopped  NT AUTHORITY\LocalService
Spooler  Print Spooler  spoolsv.exe  6.3.9600.16384  Own Process  Running  LocalSystem
sppsvc  Software Protection  sppsvc.exe  6.3.9600.16384  Own Process  Running  NT AUTHORITY\NetworkService
SSDPSRV  SSDP Discovery  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\LocalService
SstpSvc  Secure Socket Tunneling Protocol Service  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT Authority\LocalService
StiSvc  Windows Image Acquisition (WIA)  svchost.exe  6.3.9600.16384  Own Process  Stopped  NT Authority\LocalService
StorSvc  Storage Service  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
svsvc  Spot Verifier  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
swprv  Microsoft Software Shadow Copy Provider  svchost.exe  6.3.9600.16384  Own Process  Stopped  LocalSystem
SysMain  Superfetch  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
SystemEventsBroker  System Events Broker  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
TabletInputService  Touch Keyboard and Handwriting Panel Service  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
TapiSrv  Telephony  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\NetworkService
TermService  Remote Desktop Services  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT Authority\NetworkService
Themes  Themes  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
THREADORDER  Thread Ordering Server  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
TimeBroker  Time Broker  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\LocalService
TrkWks  Distributed Link Tracking Client  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
TrustedInstaller  Windows Modules Installer  TrustedInstaller.exe  6.3.9600.16384  Own Process  Stopped  localSystem
UI0Detect  Interactive Services Detection  UI0Detect.exe  6.3.9600.16384  Own Process  Stopped  LocalSystem
UmRdpService  Remote Desktop Services UserMode Port Redirector  svchost.exe  6.3.9600.16384  Share Process  Stopped  localSystem
upnphost  UPnP Device Host  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
VaultSvc  Credential Manager  lsass.exe  6.3.9600.16384  Share Process  Running  LocalSystem
vds  Virtual Disk  vds.exe  6.3.9600.16384  Own Process  Stopped  LocalSystem
vmicguestinterface  Hyper-V Guest Service Interface  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
vmicheartbeat  Hyper-V Heartbeat Service  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
vmickvpexchange  Hyper-V Data Exchange Service  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
vmicrdv  Hyper-V Remote Desktop Virtualization Service  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
vmictimesync  Hyper-V Time Synchronization Service  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
vmicvss  Hyper-V Volume Shadow Copy Requestor  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
vmicshutdown  Hyper-V Guest Shutdown Service  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
VSS  Volume Shadow Copy  vssvc.exe  6.3.9600.16384  Own Process  Stopped  LocalSystem
W32Time  Windows Time  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
wbengine  Block Level Backup Engine Service  wbengine.exe  6.3.9600.16384  Own Process  Stopped  localSystem
WbioSrvc  Windows Biometric Service  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
Wcmsvc  Windows Connection Manager  svchost.exe  6.3.9600.16384  Share Process  Running  NT Authority\LocalService
wcncsvc  Windows Connect Now - Config Registrar  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\LocalService
WcsPlugInService  Windows Color System  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
WdiServiceHost  Diagnostic Service Host  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\LocalService
WdiSystemHost  Diagnostic System Host  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
WdNisSvc  Windows Defender Network Inspection Service  NisSrv.exe  4.3.9600.16384  Own Process  Running  NT AUTHORITY\LocalService
WebClient  WebClient  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
Wecsvc  Windows Event Collector  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\NetworkService
WEPHOSTSVC  Windows Encryption Provider Host Service  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
wercplsupport  Problem Reports and Solutions Control Panel Support  svchost.exe  6.3.9600.16384  Share Process  Stopped  localSystem
WerSvc  Windows Error Reporting Service  svchost.exe  6.3.9600.16384  Own Process  Stopped  localSystem
WiaRpc  Still Image Acquisition Events  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
WinDefend  Windows Defender Service  MsMpEng.exe  4.3.9600.16384  Own Process  Running  LocalSystem
WinHttpAutoProxySvc  WinHTTP Web Proxy Auto-Discovery Service  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\LocalService
winmgmt  Windows Management Instrumentation  svchost.exe  6.3.9600.16384  Share Process  Running  localSystem
WinRM  Windows Remote Management (WS-Management)  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\NetworkService
WlanSvc  WLAN AutoConfig  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
wlidsvc  Microsoft Account Sign-in Assistant  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
wmiApSrv  WMI Performance Adapter  WmiApSrv.exe  6.3.9600.16384  Own Process  Stopped  localSystem
WMPNetworkSvc  Windows Media Player Network Sharing Service  wmpnetwk.exe  12.0.9600.16384  Own Process  Stopped  NT AUTHORITY\NetworkService
workfolderssvc  Work Folders  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT AUTHORITY\LocalService
WPCSvc  Family Safety  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT Authority\LocalService
WPDBusEnum  Portable Device Enumerator Service  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
wscsvc  Security Center  svchost.exe  6.3.9600.16384  Share Process  Running  NT AUTHORITY\LocalService
WSearch  Windows Search  SearchIndexer.exe  7.0.9600.16384  Own Process  Running  LocalSystem
WSService  Windows Store Service (WSService)  svchost.exe  6.3.9600.16384  Share Process  Stopped  LocalSystem
wuauserv  Windows Update  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
wudfsvc  Windows Driver Foundation - User-mode Driver Framework  svchost.exe  6.3.9600.16384  Share Process  Running  LocalSystem
WwanSvc  WWAN AutoConfig  svchost.exe  6.3.9600.16384  Share Process  Stopped  NT Authority\LocalService


AX Files

 
AX File  Version  Description
bdaplgin.ax  6.3.9600.16384  Microsoft BDA Device Control Plug-in for MPEG2 based networks.
g711codc.ax  6.3.9600.16384  Intel G711 CODEC
iac25_32.ax  2.0.5.53  Indeo® audio software
ir41_32.ax  6.3.9600.16384  IR41_32 WRAPPER DLL
ivfsrc.ax  5.10.2.51  Intel Indeo® video IVF Source Filter 5.10
ksproxy.ax  6.3.9600.16384  WDM Streaming ActiveMovie Proxy
kstvtune.ax  6.3.9600.16384  WDM Streaming TvTuner
kswdmcap.ax  6.3.9600.16384  WDM Streaming Video Capture
ksxbar.ax  6.3.9600.16384  WDM Streaming Crossbar
mpeg2data.ax  6.6.9600.16384  Microsoft MPEG-2 Section and Table Acquisition Module
mpg2splt.ax  6.6.9600.16384  DirectShow MPEG-2 Splitter.
msdvbnp.ax  6.6.9600.16384  Microsoft Network Provider for MPEG2 based networks.
msnp.ax  6.6.9600.16384  Microsoft Network Provider for MPEG2 based networks.
psisrndr.ax  6.6.9600.16384  Microsoft Transport Information Filter for MPEG2 based networks.
vbicodec.ax  6.6.9600.16384  Microsoft VBI Codec
vbisurf.ax  6.3.9600.16384  VBI Surface Allocator Filter
vidcap.ax  6.3.9600.16384  Video Capture Interface Server
wstpager.ax  6.6.9600.16384  Microsoft Teletext Server


DLL Files

 
DLL File  Version  Description
accessibilitycpl.dll  6.3.9600.16384  Ease of access control panel
acctres.dll  6.3.9600.16384  Microsoft Internet Account Manager Resources
acledit.dll  6.3.9600.16384  Access Control List Editor
aclui.dll  6.3.9600.16384  Security Descriptor Editor
acppage.dll  6.3.9600.16384  Compatibility Tab Shell Extension Library
acproxy.dll  6.3.9600.16384  Autochk Proxy DLL
actioncenter.dll  6.3.9600.16384  Action Center
actioncentercpl.dll  6.3.9600.16384  Action Center Control Panel
actionqueue.dll  6.3.9600.16384  Unattend Action Queue Generator / Executor
activeds.dll  6.3.9600.16384  ADs Router Layer DLL
actxprxy.dll  6.3.9600.16384  ActiveX Interface Marshaling Library
adhapi.dll  6.3.9600.16384  AD harvest sites and subnets API
adhsvc.dll  6.3.9600.16384  AD Harvest Sites and Subnets Service
adprovider.dll  6.3.9600.16384  adprovider DLL
adsldp.dll  6.3.9600.16384  ADs LDAP Provider DLL
adsldpc.dll  6.3.9600.16384  ADs LDAP Provider C DLL
adsmsext.dll  6.3.9600.16384  ADs LDAP Provider DLL
adsnt.dll  6.3.9600.16384  ADs Windows NT Provider DLL
adtschema.dll  6.3.9600.16384  Security Audit Schema DLL
advapi32.dll  6.3.9600.16384  Advanced Windows 32 Base API
advapi32res.dll  6.3.9600.16384  Advanced Windows 32 Base API
advpack.dll  11.0.9600.16384  ADVPACK
aecache.dll  6.3.9600.16384  AECache Sysprep Plugin
aeevts.dll  6.3.9600.16384  Application Experience Event Resources
aeinv.dll  6.3.9600.16384  Application Experience Program Inventory Component
aelupsvc.dll  6.3.9600.16384  Application Experience Service
aepdu.dll  6.3.9600.16384  Program Compatibility Data Updater
aepic.dll  6.3.9600.16384  Application Experience Program Cache
aeproam.dll  6.3.9600.16384  Association Endpoint(AEP) Roaming Monitor and Handler
alttab.dll  6.3.9600.16384  Windows Shell Alt Tab
amstream.dll  6.6.9600.16384  DirectShow Runtime.
apds.dll  6.3.9600.16384  Microsoft® Help Data Services Module
api-ms-win-appmodel-identity-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-appmodel-runtime-internal-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-appmodel-runtime-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-appmodel-runtime-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-appmodel-state-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-appmodel-state-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-base-bootconfig-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-base-util-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-apiquery-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-appcompat-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-appcompat-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-appinit-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-atoms-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-bem-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-bicltapi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-bicltapi-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-biplmapi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-biplmapi-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-biptcltapi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-biptcltapi-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-calendar-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-com-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-com-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-comm-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-com-private-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-console-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-console-l2-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-crt-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-crt-l2-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-datetime-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-datetime-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-debug-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-debug-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-delayload-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-delayload-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-errorhandling-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-errorhandling-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-fibers-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-fibers-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-fibers-l2-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-fibers-l2-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-file-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-file-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-file-l1-2-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-file-l2-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-file-l2-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-firmware-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-handle-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-heap-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-heap-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-heap-obsolete-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-interlocked-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-interlocked-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-io-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-io-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-job-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-job-l2-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-kernel32-legacy-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-kernel32-legacy-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-kernel32-private-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-libraryloader-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-libraryloader-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-libraryloader-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-libraryloader-private-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-localization-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-localization-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-localization-l1-2-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-localization-l2-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-localization-obsolete-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-localization-obsolete-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-localization-private-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-localregistry-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-memory-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-memory-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-memory-l1-1-2.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-multipleproviderrouter-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-namedpipe-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-namedpipe-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-namespace-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-normalization-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-path-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-privateprofile-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-processenvironment-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-processenvironment-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-processsecurity-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-processthreads-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-processthreads-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-processthreads-l1-1-2.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-processtopology-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-processtopology-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-processtopology-obsolete-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-processtopology-private-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-profile-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-psapi-ansi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-psapi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-psapi-obsolete-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-psm-app-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-psm-appnotify-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-psm-info-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-psm-key-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-psm-plm-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-psm-plm-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-quirks-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-realtime-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-registry-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-registry-l2-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-registry-private-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-registryuserspecific-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-rtlsupport-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-rtlsupport-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-shlwapi-legacy-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-shutdown-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-sidebyside-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-stringansi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-string-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-string-l2-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-stringloader-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-stringloader-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-string-obsolete-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-synch-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-synch-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-sysinfo-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-sysinfo-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-sysinfo-l1-2-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-systemtopology-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-threadpool-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-threadpool-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-threadpool-legacy-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-threadpool-private-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-timezone-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-timezone-private-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-toolhelp-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-url-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-util-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-versionansi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-version-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-version-private-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-windowserrorreporting-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-winrt-error-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-winrt-error-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-winrt-errorprivate-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-winrt-errorprivate-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-winrt-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-winrt-propertysetprivate-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-winrt-registration-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-winrt-robuffer-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-winrt-roparameterizediid-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-winrt-string-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-wow64-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-xstate-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-xstate-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-core-xstate-l2-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-devices-config-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-devices-config-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-devices-query-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-devices-query-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-devices-swdevice-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-devices-swdevice-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-advapi32-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-advapi32-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-advapi32-l2-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-advapi32-l2-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-advapi32-l3-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-advapi32-l4-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-kernel32-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-kernel32-l2-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-normaliz-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-ole32-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-ole32-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-shell32-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-shlwapi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-shlwapi-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-shlwapi-l2-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-shlwapi-l2-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-user32-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-user32-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-downlevel-version-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-dx-d3dkmt-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-eventing-classicprovider-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-eventing-consumer-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-eventing-controller-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-eventing-legacy-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-eventing-obsolete-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-eventing-provider-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-eventlog-legacy-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-eventlog-private-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-gdi-dpiinfo-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-http-time-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-input-ie-interactioncontext-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-mm-joystick-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-mm-mci-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-mm-misc-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-mm-misc-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-mm-misc-l2-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-mm-mme-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-mm-playsound-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-mm-time-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-net-isolation-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-net-isolation-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-ntuser-ie-message-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-ntuser-ie-window-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-ntuser-ie-wmpointer-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-oobe-notification-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-perf-legacy-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-power-base-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-power-setting-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-ro-typeresolution-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-rtcore-navigation-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-rtcore-ntuser-clipboard-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-rtcore-ntuser-private-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-rtcore-ntuser-synch-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-rtcore-ntuser-window-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-rtcore-ntuser-windowstation-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-rtcore-ntuser-winevent-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-rtcore-ntuser-wmpointer-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-rtcore-ole32-clipboard-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-rtcore-session-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-activedirectoryclient-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-appcontainer-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-audit-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-audit-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-base-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-base-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-base-private-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-base-private-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-credentials-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-credentials-l2-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-cryptoapi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-grouppolicy-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-logon-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-lsalookup-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-lsalookup-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-lsalookup-l2-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-lsalookup-l2-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-lsapolicy-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-provider-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-sddl-ansi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-sddl-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-sddlparsecond-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-systemfunctions-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-trustee-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-security-trustee-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-service-core-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-service-core-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-service-management-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-service-management-l2-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-service-private-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-service-winsvc-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-service-winsvc-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-shcore-comhelpers-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-shcore-obsolete-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-shcore-registry-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-shcore-scaling-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-shcore-scaling-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-shcore-stream-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-shcore-stream-winrt-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-shcore-sysinfo-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-shcore-thread-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-shcore-unicodeansi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-shell-shellcom-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
api-ms-win-shell-shellfolders-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
apisetschema.dll  6.3.9600.16384  ApiSet Schema DLL
apphelp.dll  6.3.9600.16384  Application Compatibility Client Library
apphlpdm.dll  6.3.9600.16384  Application Compatibility Help Module
appidapi.dll  6.3.9600.16384  Application Identity APIs Dll
appidsvc.dll  6.3.9600.16384  Application Identity Service
appinfo.dll  6.3.9600.16384  Application Information Service
appreadiness.dll  6.3.9600.16390  AppReadiness
apprepapi.dll  6.3.9600.16384  Application Reputation APIs Dll
apprepsync.dll  6.3.9600.16384  AppRepSync Task
appsruprov.dll  6.3.9600.16384  Application System Resource Usage Monitor (SRUM) provider
appxalluserstore.dll  6.3.9600.16390  AppX All User Store DLL
appxapplicabilityengine.dll  6.3.9600.16384  AppX Applicability Engine
appxdeploymentclient.dll  6.3.9600.16384  AppX Deployment Client DLL
appxdeploymentextensions.dll  6.3.9600.16384  AppX Deployment Extensions DLL
appxdeploymentserver.dll  6.3.9600.16390  AppX Deployment Server DLL
appxpackaging.dll  6.3.9600.16384  Native Code Appx Packaging Library
appxsip.dll  6.3.9600.16384  Appx Subject Interface Package
appxstreamingdatasourceps.dll  6.3.9600.16384  APPX Streaming Data Source COM Proxy/Stub DLL
appxsysprep.dll  6.3.9600.16384  AppX Sysprep Provider
asferror.dll  12.0.9600.16384  ASF Error Definitions
aspnet_counters.dll  4.0.30319.33440  Microsoft ASP.NET Performance Counter Shim DLL
asycfilt.dll  6.3.9600.16384  
atl.dll  3.5.2284.0  ATL Module for Windows XP (Unicode)
atmfd.dll  5.1.2.238  Windows NT OpenType/Type 1 Font Driver
atmlib.dll  5.1.2.238  Windows NT OpenType/Type 1 API Library.
audiodev.dll  6.3.9600.16384  Portable Media Devices Shell Extension
audioendpointbuilder.dll  6.3.9600.16384  Windows Audio Endpoint Builder
audioeng.dll  6.3.9600.16384  Audio Engine
audiokse.dll  6.3.9600.16384  Audio Ks Endpoint
audioses.dll  6.3.9600.16384  Audio Session
audiosrv.dll  6.3.9600.16384  Windows Audio Service
auditcse.dll  6.3.9600.16384  Windows Audit Settings CSE
authbroker.dll  6.3.9600.16384  Web Authentication WinRT API
authext.dll  6.3.9600.16384  Authentication Extensions
authfwcfg.dll  6.3.9600.16384  Windows Firewall with Advanced Security Configuration Helper
authfwgp.dll  6.3.9600.16384  Windows Firewall with Advanced Security Group Policy Editor Extension
authfwsnapin.dll  6.3.9600.16384  Microsoft.WindowsFirewall.SnapIn
authfwwizfwk.dll  6.3.9600.16384  Wizard Framework
authhostproxy.dll  6.3.9600.16384  Web Authentication Host Proxy
authui.dll  6.3.9600.16384  Windows Authentication UI
authz.dll  6.3.9600.16384  Authorization Framework
autoplay.dll  6.3.9600.16384  AutoPlay Control Panel
autoworkplacen.dll  6.3.9600.16384  AutoWorkplace Native Library
avicap.dll  1.15.0.1  AVI Capture DLL
avicap32.dll  6.3.9600.16384  AVI Capture window class
avifil32.dll  6.3.9600.16384  Microsoft AVI File support library
avifile.dll  4.90.0.3000  Microsoft AVI File support library
avrt.dll  6.3.9600.16384  Multimedia Realtime Runtime
axinstsv.dll  6.3.9600.16384  ActiveX Installer Service
azroles.dll  6.3.9600.16384  azroles Module
azroleui.dll  6.3.9600.16384  Authorization Manager
azsqlext.dll  6.3.9600.16384  AzMan Sql Audit Extended Stored Procedures Dll
basecsp.dll  6.3.9600.16384  Microsoft Base Smart Card Crypto Provider
basesrv.dll  6.3.9600.16384  Windows NT BASE API Server DLL
batmeter.dll  6.3.9600.16384  Battery Meter Helper DLL
bcd.dll  6.3.9600.16384  BCD DLL
bcdprov.dll  6.3.9600.16384  Boot Configuration Data WMI Provider
bcdsrv.dll  6.3.9600.16384  Boot Configuration Data COM Server
bcmihvsrv.dll  5.93.97.187  Broadcom Native 802.11 WLAN IHV Service
bcmihvui.dll  5.93.97.187  Broadcom Native 802.11 WLAN IHV Service Extension UI
bcp47langs.dll  6.3.9600.16384  BCP47 Language Classes
bcrypt.dll  6.3.9600.16384  Windows Cryptographic Primitives Library
bcryptprimitives.dll  6.3.9600.16384  Windows Cryptographic Primitives Library
bdehdcfglib.dll  6.3.9600.16384  Windows BitLocker Drive Preparation Tool
bderepair.dll  6.3.9600.16384  BitLocker Drive Encryption: Drive Repair Tool
bdesvc.dll  6.3.9600.16384  BDE Service
bdeui.dll  6.3.9600.16384  Windows BitLocker Drive Encryption User Interface
bfe.dll  6.3.9600.16384  Base Filtering Engine
bi.dll  6.3.9600.16384  Background Broker Infrastructure Client Library
bidispl.dll  6.3.9600.16384  Bidispl DLL
biocredprov.dll  6.3.9600.16384  WinBio Credential Provider
bisrv.dll  6.3.9600.16384  Background Tasks Infrastructure Service
bitsigd.dll  7.7.9600.16384  Background Intelligent Transfer Service IGD Support
bitsperf.dll  7.7.9600.16384  Perfmon Counter Access
bitsprx2.dll  7.7.9600.16384  Background Intelligent Transfer Service Proxy
bitsprx3.dll  7.7.9600.16384  Background Intelligent Transfer Service 2.0 Proxy
bitsprx4.dll  7.7.9600.16384  Background Intelligent Transfer Service 2.5 Proxy
bitsprx5.dll  7.7.9600.16384  Background Intelligent Transfer Service 3.0 Proxy
bitsprx6.dll  7.7.9600.16384  Background Intelligent Transfer Service 4.0 Proxy
bitsprx7.dll  7.7.9600.16384  Background Intelligent Transfer Service 5.0 Proxy
biwinrt.dll  6.3.9600.16384  Windows Background Broker Infrastructure
blackbox.dll  11.0.9600.16384  BlackBox DLL
blb_ps.dll  6.3.9600.16384  Microsoft® Block Level Backup proxy/stub
blbevents.dll  6.3.9600.16384  Blb Publisher
blbres.dll  6.3.9600.16384  Microsoft® Block Level Backup Engine Service Resources
bluetoothapis.dll  6.3.9600.16384  Bluetooth Usermode Api host
bootmenuux.dll  6.3.9600.16384  BootMenuUX
bootstr.dll  6.3.9600.16384  Boot String Resource Library
bootux.dll  6.3.9600.16384  bootux
bootvid.dll  6.3.9600.16384  VGA Boot Driver
brdgcfg.dll  6.3.9600.16384  NWLink IPX Notify Object
bridgeres.dll  6.3.9600.16384  Bridge Resources
brokerlib.dll  6.3.9600.16384  Broker Base Library
browcli.dll  6.3.9600.16384  Browser Service Client DLL
browser.dll  6.3.9600.16384  Computer Browser Service DLL
browseui.dll  6.3.9600.16384  Shell Browser UI Library
bthci.dll  6.3.9600.16384  Bluetooth Class Installer
bthhfsrv.dll  6.3.9600.16384  Bluetooth Handsfree Service
bthmtpcontexthandler.dll  6.3.9600.16384  Bluetooth MTP Context Menu Handler
bthpanapi.dll  6.3.9600.16384  bthpanapi
bthpancontexthandler.dll  1.0.0.1  Bthpan Context Handler
bthradiomedia.dll  6.3.9600.16384  Bluetooth Radio Media Provider
bthserv.dll  6.3.9600.16384  Bluetooth Support Service
bthsqm.dll  6.3.9600.16384  Bluetooth SQM Agent
btpanui.dll  6.3.9600.16384  Bluetooth PAN User Interface
btwdi.dll  12.0.0.7030  Broadcom Bluetooth BT Device Co-Installer
bwcontexthandler.dll  1.0.0.1  ContextH Application
c_g18030.dll  6.3.9600.16384  GB18030 DBCS-Unicode Conversion DLL
c_is2022.dll  6.3.9600.16384  ISO-2022 Code Page Translation DLL
c_iscii.dll  6.3.9600.16384  ISCII Code Page Translation DLL
cabinet.dll  6.3.9600.16384  Microsoft® Cabinet File API
cabview.dll  6.3.9600.16384  Cabinet File Viewer Shell Extension
callbuttons.dll  6.3.9600.16384  Windows Runtime CallButtonsServer DLL
callbuttons.proxystub.dll  6.3.9600.16384  Windows Runtime CallButtonsServer ProxyStub DLL
capiprovider.dll  6.3.9600.16384  capiprovider DLL
capisp.dll  6.3.9600.16384  Sysprep cleanup dll for CAPI
catsrv.dll  2001.12.10530.16384  COM+ Configuration Catalog Server
catsrvps.dll  2001.12.10530.16384  COM+ Configuration Catalog Server Proxy/Stub
catsrvut.dll  2001.12.10530.16384  COM+ Configuration Catalog Server Utilities
cca.dll  6.6.9600.16384  CCA DirectShow Filter.
cdd.dll  6.3.9600.16384  Canonical Display Driver
cdosys.dll  6.6.9600.16384  Microsoft CDO for Windows Library
certca.dll  6.3.9600.16384  Microsoft® Active Directory Certificate Services CA
certcli.dll  6.3.9600.16384  Microsoft® Active Directory Certificate Services Client
certcredprovider.dll  6.3.9600.16384  Cert Credential Provider
certenc.dll  6.3.9600.16384  Active Directory Certificate Services Encoding
certenroll.dll  6.3.9600.16384  Microsoft® Active Directory Certificate Services Enrollment Client
certenrollui.dll  6.3.9600.16384  X509 Certificate Enrollment UI
certmgr.dll  6.3.9600.16384  Certificates snap-in
certpoleng.dll  6.3.9600.16384  Certificate Policy Engine
certprop.dll  6.3.9600.16384  Microsoft Smartcard Certificate Propagation Service
cewmdm.dll  12.0.9600.16384  Windows CE WMDM Service Provider
cfgbkend.dll  6.3.9600.16384  Configuration Backend Interface
cfgmgr32.dll  6.3.9600.16384  Configuration Manager DLL
cfmifs.dll  6.3.9600.16384  FmIfs Engine
cfmifsproxy.dll  6.3.9600.16384  Microsoft® FmIfs Proxy Library
chartv.dll  6.3.9600.16384  Chart View
chkwudrv.dll  6.3.9600.16384  Search Windows Update for Drivers
chxreadingstringime.dll  6.3.9600.16384  CHxReadingStringIME
ci.dll  6.3.9600.16384  Code Integrity Module (Test)
cic.dll  6.3.9600.16384  CIC - MMC controls for Taskpad
circoinst.dll  6.3.9600.16384  USB Consumer IR Driver coinstaller for eHome
clb.dll  6.3.9600.16384  Column List Box
clbcatq.dll  2001.12.10530.16384  COM+ Configuration Catalog
clfsw32.dll  6.3.9600.16384  Common Log Marshalling Win32 DLL
cliconfg.dll  6.3.9600.16384  SQL Client Configuration Utility DLL
clrhost.dll  6.3.9600.16384  In Proc server for managed servers in the Windows Runtime
clusapi.dll  6.3.9600.16384  Cluster API Library
cmcfg32.dll  7.2.9600.16384  Microsoft Connection Manager Configuration Dll
cmdext.dll  6.3.9600.16384  cmd.exe Extension DLL
cmdial32.dll  7.2.9600.16384  Microsoft Connection Manager
cmifw.dll  6.3.9600.16384  Windows Firewall rule configuration plug-in
cmipnpinstall.dll  6.3.9600.16384  PNP plugin installer for CMI
cmlua.dll  7.2.9600.16384  Connection Manager Admin API Helper
cmpbk32.dll  7.2.9600.16384  Microsoft Connection Manager Phonebook
cmstplua.dll  7.2.9600.16384  Connection Manager Admin API Helper for Setup
cmutil.dll  7.2.9600.16384  Microsoft Connection Manager Utility Lib
cngcredui.dll  6.3.9600.16384  Microsoft CNG CredUI Provider
cngprovider.dll  6.3.9600.16384  cngprovider DLL
cnvfat.dll  6.3.9600.16384  FAT File System Conversion Utility DLL
cofiredm.dll  6.3.9600.16384  Corrupted File Recovery Diagnostic Module
colbact.dll  2001.12.10530.16384  COM+
colorcnv.dll  6.3.9600.16384  Windows Media Color Conversion
colorui.dll  6.3.9600.16384  Microsoft Color Control Panel
combase.dll  6.3.9600.16384  Microsoft COM for Windows
comcat.dll  6.3.9600.16384  Microsoft Component Category Manager Library
comctl32.dll  5.82.9600.16384  User Experience Controls Library
comdlg32.dll  6.3.9600.16384  Common Dialogs DLL
commdlg.dll  3.10.0.103  Windows Win16 Application Launcher
compobj.dll  3.10.0.103  Windows Win16 Application Launcher
comppkgsup.dll  12.0.9600.16384  Component Package Support DLL
compstui.dll  6.3.9600.16384  Common Property Sheet User Interface DLL
comrepl.dll  2001.12.10530.16384  COM+
comres.dll  2001.12.10530.16384  COM+ Resources
comsnap.dll  2001.12.10530.16384  COM+ Explorer MMC Snapin
comsvcs.dll  2001.12.10530.16384  COM+ Services
comuid.dll  2001.12.10530.16384  COM+ Explorer UI
configureexpandedstorage.dll  6.3.9600.16384  ConfigureExpandedStorage
connect.dll  6.3.9600.16384  Get Connected Wizards
connectedaccountstate.dll  6.3.9600.16384  ConnectedAccountState.dll
consentux.dll  6.3.9600.16384  Device Broker Consent Prompt
console.dll  6.3.9600.16384  Control Panel Console Applet
coremmres.dll  6.3.9600.16384  General Core Multimedia Resources
correngine.dll  6.3.9600.16384  Correlation Engine
cpfilters.dll  6.6.9600.16384   PTFilter & Encypter/Decrypter Tagger Filters.
credentialmigrationhandler.dll  6.3.9600.16384  Credential Migration Handler
credssp.dll  6.3.9600.16384  Credential Delegation Security Package
credui.dll  6.3.9600.16384  Credential Manager User Interface
crtdll.dll  4.0.1183.1  Microsoft C Runtime Library
crypt32.dll  6.3.9600.16384  Crypto API32
cryptbase.dll  6.3.9600.16384  Base cryptographic API DLL
cryptcatsvc.dll  6.3.9600.16384  Cryptographic Catalog Services
cryptdlg.dll  6.3.9600.16384  Microsoft Common Certificate Dialogs
cryptdll.dll  6.3.9600.16384  Cryptography Manager
cryptext.dll  6.3.9600.16384  Crypto Shell Extensions
cryptnet.dll  6.3.9600.16384  Crypto Network Related API
cryptowinrt.dll  6.3.9600.16384  Crypto WinRT Library
cryptsp.dll  6.3.9600.16384  Cryptographic Service Provider API
cryptsvc.dll  6.3.9600.16384  Cryptographic Services
crypttpmeksvc.dll  6.3.9600.16384  Cryptographic TPM Endorsement Key Services
cryptui.dll  6.3.9600.16384  Microsoft Trust UI Provider
cryptuiwizard.dll  6.3.9600.16384  Microsoft Trust UI Provider
cryptxml.dll  6.3.9600.16384  XML DigSig API
ctl3d32.dll  2.31.0.0  Ctl3D 3D Windows Controls
ctl3dv2.dll  3.10.0.103  Windows Win16 Application Launcher
cscapi.dll  6.3.9600.16384  Offline Files Win32 API
cscdll.dll  6.3.9600.16384  Offline Files Temporary Shim
csrsrv.dll  6.3.9600.16384  Client Server Runtime Process
csystemeventsbrokerclient.dll  6.3.9600.16384  Classic System Events Broker Client Library
d2d1.dll  6.3.9600.16384  Microsoft D2D Library
d3d10.dll  6.3.9600.16384  Direct3D 10 Runtime
d3d10_1.dll  6.3.9600.16384  Direct3D 10.1 Runtime
d3d10_1core.dll  6.3.9600.16384  Direct3D 10.1 Runtime
d3d10core.dll  6.3.9600.16384  Direct3D 10 Runtime
d3d10level9.dll  6.3.9600.16384  Direct3D 10 to Direct3D9 Translation Runtime
d3d10warp.dll  6.3.9600.16384  Direct3D 10 Rasterizer
d3d11.dll  6.3.9600.16384  Direct3D 11 Runtime
d3d8.dll  6.3.9600.16384  Microsoft Direct3D
d3d8thk.dll  6.3.9600.16384  Microsoft Direct3D OS Thunk Layer
d3d9.dll  6.3.9600.16384  Direct3D 9 Runtime
d3dcompiler_47.dll  6.3.9600.16384  Direct3D HLSL Compiler
d3dim.dll  6.3.9600.16384  Microsoft Direct3D
d3dim700.dll  6.3.9600.16384  Microsoft Direct3D
d3dramp.dll  6.3.9600.16384  Microsoft Direct3D
d3dxof.dll  6.3.9600.16384  DirectX Files DLL
dab.dll  6.3.9600.16384  Desktop Activity Broker DLL
dabapi.dll  6.3.9600.16384  Desktop Activity Broker API
daconn.dll  6.3.9600.16384  Direct Access Connection Flows
dafbth.dll  6.3.9600.16384  Bluetooth Device Association Framework Provider
dafprintprovider.dll  6.3.9600.16384  DAF Print Provider DLL
dafupnp.dll  6.3.9600.16384  DAF UPnP Provider
dafwcn.dll  6.3.9600.16384  Windows Connect Now DAF Plugin
dafwfdprovider.dll  6.3.9600.16384  Windows Wi-Fi Direct DAF Plugin
dafwsd.dll  6.3.9600.16384  DAF WSD Provider
damm.dll  6.3.9600.16384  DirectAccess Media Manager
daotpcredentialprovider.dll  6.3.9600.16384  DirectAccess One-Time Password Credential Provider
das.dll  6.3.9600.16384  Device Association Service
dataclen.dll  6.3.9600.16384  Disk Space Cleaner for Windows
datusage.dll  6.3.9600.16384  Network Data Usage Helper
davclnt.dll  6.3.9600.16384  Web DAV Client DLL
davhlpr.dll  6.3.9600.16384  DAV Helper DLL
dbgeng.dll  6.3.9600.16384  Windows Symbolic Debugger Engine
dbghelp.dll  6.3.9600.16384  Windows Image Helper
dbnetlib.dll  6.3.9600.16384  Winsock Oriented Net DLL for SQL Clients
dbnmpntw.dll  6.3.9600.16384  Named Pipes Net DLL for SQL Clients
dciman32.dll  6.3.9600.16384  DCI Manager
dcomp.dll  6.3.9600.16384  Microsoft DirectComposition Library
ddaclsys.dll  6.3.9600.16384  SysPrep module for Resetting Data Drive ACL
ddeml.dll  3.10.0.103  Windows Win16 Application Launcher
ddoiproxy.dll  6.3.9600.16384  DDOI Interface Proxy
ddores.dll  6.3.9600.16384  Device Category information and resources
ddraw.dll  6.3.9600.16384  Microsoft DirectDraw
ddrawex.dll  6.3.9600.16384  Direct Draw Ex
defaultdevicemanager.dll  6.3.9600.16384  Default Device Manager
defaultprinterprovider.dll  6.3.9600.16384  Microsoft Windows Default Printer Provider
defragproxy.dll  6.3.9600.16384  Microsoft® Drive Optimizer Proxy Library
defragres.dll  6.3.9600.16384  Microsoft\Drive Optimizer Resources
defragsvc.dll  6.3.9600.16384  Microsoft\Drive Optimizer
delegatorprovider.dll  6.3.9600.16384  WMI PassThru Provider for Storage Management
deskadp.dll  6.3.9600.16384  Advanced display adapter properties
deskmon.dll  6.3.9600.16384  Advanced display monitor properties
devdispitemprovider.dll  6.3.9600.16384  DeviceItem inproc devquery subsystem
devenum.dll  6.6.9600.16384  Device enumeration.
deviceaccess.dll  6.3.9600.16384  Device Broker And Policy COM Server
deviceassociation.dll  6.3.9600.16384  Device Association Client DLL
devicecenter.dll  6.3.9600.16384  Device Center
devicedisplaystatusmanager.dll  6.3.9600.16384  Device Display Status Manager
devicedriverretrievalclient.dll  6.3.9600.16384  Device Driver Retrieval Client
deviceelementsource.dll  6.3.9600.16384  DeviceElementSource
devicemetadataretrievalclient.dll  6.3.9600.16384  Windows MRC
devicepairing.dll  6.3.9600.16384  Shell extensions for Device Pairing
devicepairingfolder.dll  6.3.9600.16384  Device Pairing Folder
devicepairingproxy.dll  6.3.9600.16384  Device Pairing Proxy Dll
deviceregistration.dll  6.3.9600.16384  Device Registration DLL
devicesetupmanager.dll  6.3.9600.16384  Device Setup Manager
devicesetupmanagerapi.dll  6.3.9600.16384  Device Setup Manager Client API
devicesetupstatusprovider.dll  6.3.9600.16384  Device Setup Status Provider Dll
deviceuxres.dll  6.3.9600.16384  Windows Device User Experience Resource File
devinv.dll  6.3.9600.16384  Device Inventory Library
devmgr.dll  6.3.9600.16384  Device Manager MMC Snapin
devobj.dll  6.3.9600.16384  Device Information Set DLL
devpropmgr.dll  6.3.9600.16384  Microsoft Windows Device Property Manager
devrtl.dll  6.3.9600.16384  Device Management Run Time Library
dfdts.dll  6.3.9600.16384  Windows Disk Failure Diagnostic Module
dfscli.dll  6.3.9600.16384  Windows NT Distributed File System Client DLL
dfshim.dll  6.3.9600.16384  ClickOnce Application Deployment Support Library
dfsshlex.dll  6.3.9600.16384  Distributed File System shell extension
dhcpcmonitor.dll  6.3.9600.16384  DHCP Client Monitor Dll
dhcpcore.dll  6.3.9600.16384  DHCP Client Service
dhcpcore6.dll  6.3.9600.16384  DHCPv6 Client
dhcpcsvc.dll  6.3.9600.16384  DHCP Client Service
dhcpcsvc6.dll  6.3.9600.16384  DHCPv6 Client
dhcpqec.dll  6.3.9600.16384  Microsoft DHCP NAP Enforcement Client
dhcpsapi.dll  6.3.9600.16384  DHCP Server API Stub DLL
diagcpl.dll  6.3.9600.16384  Troubleshooting Control Panel
diagperf.dll  6.3.9600.16384  Microsoft Performance Diagnostics
difxapi.dll  2.1.0.0  Driver Install Frameworks for API library module
dimsjob.dll  6.3.9600.16384  DIMS Job DLL
dimsroam.dll  6.3.9600.16384  Key Roaming DIMS Provider DLL
dinput.dll  6.3.9600.16384  Microsoft DirectInput
dinput8.dll  6.3.9600.16384  Microsoft DirectInput
directdb.dll  6.3.9600.16384  Microsoft Direct Database API
discan.dll  6.3.9600.16384  Data Integrity Scan Task
diskcopy.dll  6.3.9600.16384  Windows DiskCopy
dismapi.dll  6.3.9600.16384  DISM API Framework
dispci.dll  6.3.9600.16384  Microsoft Display Class Installer
dispex.dll  5.8.9600.16384  Microsoft ® DispEx
display.dll  6.3.9600.16384  Display Control Panel
dlnashext.dll  12.0.9600.16384  DLNA Namespace DLL
dmband.dll  6.3.9600.16384  Microsoft DirectMusic Band
dmcompos.dll  6.3.9600.16384  Microsoft DirectMusic Composer
dmdlgs.dll  6.3.9600.16384  Disk Management Snap-in Dialogs
dmdskmgr.dll  6.3.9600.16384  Disk Management Snap-in Support Library
dmdskres.dll  6.3.9600.16384  Disk Management Snap-in Resources
dmdskres2.dll  6.3.9600.16384  Disk Management Snap-in Resources
dmime.dll  6.3.9600.16384  Microsoft DirectMusic Interactive Engine
dmintf.dll  6.3.9600.16384  Disk Management DCOM Interface Stub
dmloader.dll  6.3.9600.16384  Microsoft DirectMusic Loader
dmocx.dll  6.3.9600.16384  TreeView OCX
dmscript.dll  6.3.9600.16384  Microsoft DirectMusic Scripting
dmstyle.dll  6.3.9600.16384  Microsoft DirectMusic Style Engline
dmsynth.dll  6.3.9600.16384  Microsoft DirectMusic Software Synthesizer
dmusic.dll  6.3.9600.16384  Microsoft DirectMusic Core Services
dmutil.dll  6.3.9600.16384  Logical Disk Manager Utility Library
dmvdsitf.dll  6.3.9600.16384  Disk Management Snap-in Support Library
dmvscres.dll  6.3.9600.16384  Virtual Machine Dynamic Memory Resource DLL
dnsapi.dll  6.3.9600.16384  DNS Client API DLL
dnscmmc.dll  6.3.9600.16384  DNS Client MMC Snap-in DLL
dnsext.dll  6.3.9600.16384  DNS extension DLL
dnshc.dll  6.3.9600.16384  DNS Helper Class
dnsrslvr.dll  6.3.9600.16384  DNS Caching Resolver Service
docprop.dll  6.3.9600.16384  OLE DocFile Property Page
documentperformanceevents.dll  6.3.9600.16384  Documents and Printing Performance Events
dot3api.dll  6.3.9600.16384  802.3 Autoconfiguration API
dot3cfg.dll  6.3.9600.16384  802.3 Netsh Helper
dot3conn.dll  6.3.9600.16384  Wired Network Connection Flows
dot3dlg.dll  6.3.9600.16384  802.3 UI Helper
dot3gpclnt.dll  6.3.9600.16384  802.3 Group Policy Client
dot3gpui.dll  6.3.9600.16384  802.3 Network Policy Management Snap-in
dot3hc.dll  6.3.9600.16384  Dot3 Helper Class
dot3mm.dll  6.3.9600.16384  Wired Network Media Manager
dot3msm.dll  6.3.9600.16384  802.3 Media Specific Module
dot3svc.dll  6.3.9600.16384  Wired AutoConfig Service
dot3ui.dll  6.3.9600.16384  802.3 Advanced UI
dpapi.dll  6.3.9600.16384  Data Protection API
dpapiprovider.dll  6.3.9600.16384  dpapiprovider DLL
dpapisrv.dll  6.3.9600.16384  DPAPI Server
dplayx.dll  6.3.9600.16384  DirectPlay Stub
dpmodemx.dll  6.3.9600.16384  DirectPlay Stub
dpnaddr.dll  6.3.9600.16384  DirectPlay Stub
dpnathlp.dll  6.3.9600.16384  DirectPlay Stub
dpnet.dll  6.3.9600.16384  DirectPlay Stub
dpnhpast.dll  6.3.9600.16384  DirectPlay Stub
dpnhupnp.dll  6.3.9600.16384  DirectPlay Stub
dpnlobby.dll  6.3.9600.16384  DirectPlay Stub
dps.dll  6.3.9600.16384  WDI Diagnostic Policy Service
dptfpolicylpmdll.dll  7.0.0.1  Intel Dynamic Platform & Thermal Framework Generic Participant Driver
dpwsockx.dll  6.3.9600.16384  DirectPlay Stub
dpx.dll  6.3.9600.16384  Microsoft(R) Delta Package Expander
drmmgrtn.dll  11.0.9600.16384  DRM Migration DLL
drmv2clt.dll  11.0.9600.16384  DRMv2 Client DLL
drprov.dll  6.3.9600.16384  Microsoft Remote Desktop Session Host Server Network Provider
drt.dll  6.3.9600.16384  Distributed Routing Table
drtprov.dll  6.3.9600.16384  Distributed Routing Table Providers
drttransport.dll  6.3.9600.16384  Distributed Routing Table Transport Provider
drvstore.dll  6.3.9600.16384  Driver Store API
ds16gt.dll  3.510.3711.0  Microsoft ODBC Driver Setup Generic Thunk
ds32gt.dll  6.3.9600.16384  ODBC Driver Setup Generic Thunk
dsauth.dll  6.3.9600.16384  DS Authorization for Services
dsccore.dll  6.3.9600.16384  DSC
dsccoreconfprov.dll  6.3.9600.16384  DSC
dsdmo.dll  6.3.9600.16384  DirectSound Effects
dskquota.dll  6.3.9600.16384  Windows Shell Disk Quota Support DLL
dskquoui.dll  6.3.9600.16384  Windows Shell Disk Quota UI DLL
dsound.dll  6.3.9600.16384  DirectSound
dsparse.dll  6.3.9600.16384  Active Directory Domain Services API
dsprop.dll  6.3.9600.16384  Windows Active Directory Property Pages
dsquery.dll  6.3.9600.16384  Directory Service Find
dsrole.dll  6.3.9600.16384  DS Setup Client DLL
dssec.dll  6.3.9600.16384  Directory Service Security UI
dssenh.dll  6.3.9600.16384  Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider
dsui.dll  6.3.9600.16384  Device Setup UI Pages
dsuiext.dll  6.3.9600.16384  Directory Service Common UI
dswave.dll  6.3.9600.16384  Microsoft DirectMusic Wave
dtsh.dll  6.3.9600.16384  Detection and Sharing Status API
dui70.dll  6.3.9600.16384  Windows DirectUI Engine
duser.dll  6.3.9600.16384  Windows DirectUser Engine
dwmapi.dll  6.3.9600.16384  Microsoft Desktop Window Manager API
dwmcore.dll  6.3.9600.16384  Microsoft DWM Core Library
dwmredir.dll  6.3.9600.16384  Microsoft Desktop Window Manager Redirection Component
dwrite.dll  6.3.9600.16384  Microsoft DirectX Typography Services
dxdiagn.dll  6.3.9600.16384  Microsoft DirectX Diagnostic Tool
dxgi.dll  6.3.9600.16384  DirectX Graphics Infrastructure
dxgwdi.dll  6.3.9600.16384  Microsoft DirectX Graphics WDI Handler
dxmasf.dll  12.0.9600.16384  Microsoft Windows Media Component Removal File.
dxp.dll  6.3.9600.16384  Device Stage Shell Extension
dxpps.dll  6.3.9600.16384  Device Experience Platform Proxy\Stub DLL
dxptasksync.dll  6.3.9600.16384  Microsoft Windows DXP Sync.
dxtmsft.dll  11.0.9600.16384  DirectX Media -- Image DirectX Transforms
dxtrans.dll  11.0.9600.16384  DirectX Media -- DirectX Transform Core
dxva2.dll  6.3.9600.16384  DirectX Video Acceleration 2.0 DLL
eapp3hst.dll  6.3.9600.16384  Microsoft ThirdPartyEapDispatcher
eappcfg.dll  6.3.9600.16384  Eap Peer Config
eappgnui.dll  6.3.9600.16384  EAP Generic UI
eapphost.dll  6.3.9600.16384  Microsoft EAPHost Peer service
eappprxy.dll  6.3.9600.16384  Microsoft EAPHost Peer Client DLL
eapprovp.dll  6.3.9600.16384  EAP extension DLL
eapqec.dll  6.3.9600.16384  Microsoft EAP NAP Enforcement Client
eapsvc.dll  6.3.9600.16384  Microsoft EAPHost service
easconsent.dll  6.3.9600.16384  EASConsent
easinvoker.proxystub.dll  6.3.9600.16384  Exchange ActiveSync Invoker Proxy Stub
easwrt.dll  6.3.9600.16384  Exchange ActiveSync Windows Runtime DLL
efsadu.dll  6.3.9600.16384  File Encryption Utility
efscore.dll  6.3.9600.16384  EFS Core Library
efslsaext.dll  6.3.9600.16384  LSA extension for EFS
efssvc.dll  6.3.9600.16384  EFS Service
efsutil.dll  6.3.9600.16384  EFS Utility Library
efswrt.dll  6.3.9600.16384  Storage Protection Windows Runtime DLL
ehstorapi.dll  6.3.9600.16384  Windows Enhanced Storage API
ehstorpwdmgr.dll  6.3.9600.16384  Microsoft Enhanced Storage Password Manager
ehstorshell.dll  6.3.9600.16384  Windows Enhanced Storage Shell Extension DLL
els.dll  6.3.9600.16384  Event Viewer Snapin
elscore.dll  6.3.9600.16384  Els Core Platform DLL
elshyph.dll  6.3.9600.16384  ELS Hyphenation Service
elslad.dll  6.3.9600.16384  ELS Language Detection
elstrans.dll  6.3.9600.16384  ELS Transliteration Service
encapi.dll  6.3.9600.16384  Encoder API
encdec.dll  6.6.9600.16384   XDSCodec & Encypter/Decrypter Tagger Filters.
encdump.dll  5.0.1.1  Media Foundation Crash Dump Encryption DLL
energy.dll  6.3.9600.16384  Power Efficiency Diagnostics
energyprov.dll  6.3.9600.16384  Energy System Resource Usage Monitor (SRUM) provider
energytask.dll  6.3.9600.16384  Power Efficiency Diagnostics Task
eqossnap.dll  6.3.9600.16384  EQoS Snapin extension
es.dll  2001.12.10530.16384  COM+
esent.dll  6.3.9600.16384  Extensible Storage Engine for Microsoft(R) Windows(R)
esentprf.dll  6.3.9600.16384  Extensible Storage Engine Performance Monitoring Library for Microsoft(R) Windows(R)
etweseproviderresources.dll  6.3.9600.16384  Microsoft ESE ETW
eventaggregation.dll  6.3.9600.16384  Event Aggregation Library
eventcls.dll  6.3.9600.16384  Microsoft® Volume Shadow Copy Service event class
evr.dll  6.3.9600.16384  Enhanced Video Renderer DLL
explorerframe.dll  6.3.9600.16384  ExplorerFrame
expsrv.dll  6.0.72.9589  Visual Basic for Applications Runtime - Expression Service
ext-ms-win-advapi32-auth-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-advapi32-encryptedfile-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-advapi32-eventingcontroller-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-advapi32-eventlog-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-advapi32-idletask-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-advapi32-lsa-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-advapi32-msi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-advapi32-ntmarta-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-advapi32-psm-app-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-advapi32-registry-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-advapi32-safer-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-advapi32-shutdown-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-appmodel-deployment-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-appxdeploymentclient-appxdeploy-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-audiocore-pal-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-authz-claimpolicies-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-authz-context-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-authz-remote-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-biometrics-winbio-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-bluetooth-deviceassociation-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-branding-winbrand-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-cluster-clusapi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-cluster-clusapi-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-cluster-resutils-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-cmd-util-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-cng-rng-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-com-clbcatq-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-com-ole32-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-com-ole32-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-com-psmregister-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-core-bi-service-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-core-psm-service-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-domainjoin-netjoin-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-firewallapi-webproxy-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-font-fontgroups-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-fs-clfs-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-fsutilext-ifsutil-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-fsutilext-ulib-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-fveapi-query-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-gdi-dc-create-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-gdi-dc-create-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-gdi-dc-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-gdi-draw-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-gdi-draw-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-gdi-font-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-gdi-font-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-gdi-metafile-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-gdi-metafile-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-gdi-path-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-gdi-private-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-gdi-render-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-gdi-wcs-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-globalization-collation-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-globalization-input-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-gpapi-grouppolicy-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-gpsvc-grouppolicy-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-gui-uxinit-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-imm-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-kernel32-appcompat-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-kernel32-datetime-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-kernel32-elevation-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-kernel32-errorhandling-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-kernel32-file-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-kernel32-localization-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-kernel32-package-current-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-kernel32-package-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-kernel32-package-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-kernel32-quirks-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-kernel32-registry-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-kernel32-sidebyside-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-kernel32-transacted-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-kernel32-windowserrorreporting-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-kernelbase-processthread-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-mm-msacm-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-mm-pehelper-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-mm-wmdrmsdk-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-mpr-multipleproviderrouter-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-mrmcorer-environment-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-mrmcorer-resmanager-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-msa-ui-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-msa-user-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-msiltcfg-msi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-net-isoext-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-networking-wcmapi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-networking-winipsec-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-networking-wlanapi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-newdev-config-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntdsa-activedirectoryserver-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntdsapi-activedirectoryclient-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntos-kcminitcfg-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntos-ksecurity-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntos-ksecurity-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntos-ksigningpolicy-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntos-ksr-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntos-pico-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntos-tm-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntos-werkernel-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-caret-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-chartranslation-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-dialogbox-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-dialogbox-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-draw-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-draw-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-gui-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-gui-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-keyboard-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-keyboard-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-menu-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-menu-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-message-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-message-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-misc-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-misc-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-mouse-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-powermanagement-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-private-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-private-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-rectangle-ext-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-rotationmanager-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-string-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-synch-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-touch-hittest-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-windowclass-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-windowclass-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-window-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-window-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-windowstation-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ntuser-windowstation-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ole32-bindctx-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ole32-ie-ext-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ole32-oleautomation-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-oleacc-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-printer-winspool-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-printer-winspool-l1-1-1.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-profile-profsvc-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-profile-userenv-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ras-rasapi32-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ras-rasdlg-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ras-rasman-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-ras-tapi32-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-reinfo-query-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-rometadata-dispenser-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-rtcore-gdi-devcaps-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-rtcore-gdi-object-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-rtcore-gdi-rgn-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-rtcore-ntuser-dc-access-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-rtcore-ntuser-dpi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-rtcore-ntuser-sysparams-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-samsrv-accountstore-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-scesrv-server-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-secur32-translatename-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-security-credui-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-security-cryptui-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-security-kerberos-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-security-vaultcli-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-session-userinit-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-session-usertoken-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-session-wininit-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-session-winlogon-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-session-winsta-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-session-wtsapi32-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-setupapi-cfgmgr32remote-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-setupapi-classinstallers-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-setupapi-inf-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-setupapi-logging-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-shell32-shellcom-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-shell32-shellfolders-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-shell-propsys-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-shell-settingsync-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-shell-shell32-l1-2-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-shell-shlwapi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-smbshare-browser-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-smbshare-sscore-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-spinf-inf-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-storage-iscsidsc-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-sxs-oleautomation-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-uiacore-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-umpoext-umpo-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-usp10-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-uxtheme-themes-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-webio-pal-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-wer-reporting-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-wevtapi-eventlog-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-winbici-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-winhttp-pal-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-wininet-pal-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-winlogon-mincreds-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-winrt-storage-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-wlan-grouppolicy-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-wlan-onexui-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-wlan-scard-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-wsclient-devlicense-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-wwan-wwapi-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-xaml-controls-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
ext-ms-win-xaml-pal-l1-1-0.dll  6.3.9600.16384  ApiSet Stub DLL
f3ahvoas.dll  6.3.9600.16384  JP Japanese Keyboard Layout for Fujitsu FMV oyayubi-shift keyboard
faultrep.dll  6.3.9600.16384  Windows User Mode Crash Reporting DLL
fdbth.dll  6.3.9600.16384  Function Discovery Bluetooth Provider Dll
fdbthproxy.dll  6.3.9600.16384  Bluetooth Provider Proxy Dll
fddevquery.dll  6.3.9600.16384  Microsoft Windows Device Query Helper
fde.dll  6.3.9600.16384  Folder Redirection Snapin Extension
fdeploy.dll  6.3.9600.16384  Folder Redirection Group Policy Extension
fdphost.dll  6.3.9600.16384  Function Discovery Provider host service
fdpnp.dll  6.3.9600.16384  Pnp Provider Dll
fdprint.dll  6.3.9600.16384  Function Discovery Print Provider Dll
fdproxy.dll  6.3.9600.16384  Function Discovery Proxy Dll
fdrespub.dll  6.3.9600.16384  Function Discovery Resource Publication Service
fdssdp.dll  6.3.9600.16384  Function Discovery SSDP Provider Dll
fdwcn.dll  6.3.9600.16384  Windows Connect Now - Config Function Discovery Provider DLL
fdwnet.dll  6.3.9600.16384  Function Discovery WNet Provider Dll
fdwsd.dll  6.3.9600.16384  Function Discovery WS Discovery Provider Dll
feclient.dll  6.3.9600.16384  Windows NT File Encryption Client Interfaces
fhautoplay.dll  6.3.9600.16384  Microsoft® File History AutoPlay Integration Library
fhcat.dll  6.3.9600.16384  File History Catalog Library
fhcfg.dll  6.3.9600.16384  File History Configuration Manager
fhcleanup.dll  6.3.9600.16384  File History Disk Cleanup Handler
fhcpl.dll  6.3.9600.16384  File History Control Panel
fhengine.dll  6.3.9600.16384  File History Engine
fhevents.dll  6.3.9600.16384  File History Event Listener Library
fhlisten.dll  6.3.9600.16384  File History HomeGroup Listener
fhshl.dll  6.3.9600.16384  File History Custom Shell Library
fhsrchapi.dll  6.3.9600.16384  File History Search API
fhsrchph.dll  6.3.9600.16384  File History Search Protocol Handler
fhsvc.dll  6.3.9600.16384  File History Service
fhsvcctl.dll  6.3.9600.16384  File History Service Control Library
fhtask.dll  6.3.9600.16384  File History Task Handler
fhuxadapter.dll  6.3.9600.16384  File History Data Adapter
fhuxapi.dll  6.3.9600.16384  File History API
fhuxcommon.dll  6.3.9600.16384  File History Common Library
fhuxgraphics.dll  6.3.9600.16384  File History Graphics
fhuxpresentation.dll  6.3.9600.16384  File History Presentation
fileappxstreamingdatasource.dll  6.3.9600.16384  File AppX Streaming Data Source Library
filemgmt.dll  6.3.9600.16384  Services and Shared Folders
findnetprinters.dll  6.3.9600.16384  Find Network Printers COM Component
firewallapi.dll  6.3.9600.16384  Windows Firewall API
firewallcontrolpanel.dll  6.3.9600.16384  Windows Firewall Control Panel
fltlib.dll  6.3.9600.16384  Filter Library
fmapi.dll  6.3.9600.16384  File Management API
fmifs.dll  6.3.9600.16384  FM IFS Utility DLL
fms.dll  6.3.9600.16384  Font Management Services
fntcache.dll  6.3.9600.16384  Windows Font Cache Service
fontext.dll  6.3.9600.16384  Windows Font Folder
fontsub.dll  6.3.9600.16384  Font Subsetting DLL
fphc.dll  6.3.9600.16384  Filtering Platform Helper Class
framedyn.dll  6.3.9600.16384  WMI SDK Provider Framework
framedynos.dll  6.3.9600.16384  WMI SDK Provider Framework
frprov.dll  6.3.9600.16384  Folder Redirection WMI Provider
fsutilext.dll  6.3.9600.16384  FS Utility Extension DLL
fthsvc.dll  6.3.9600.16384  Microsoft Windows Fault Tolerant Heap Diagnostic Module
fundisc.dll  6.3.9600.16384  Function Discovery Dll
fveapi.dll  6.3.9600.16384  Windows BitLocker Drive Encryption API
fveapibase.dll  6.3.9600.16384  Windows BitLocker Drive Encryption Base API
fvecerts.dll  6.3.9600.16384  BitLocker Certificates Library
fvecpl.dll  6.3.9600.16384  BitLocker Drive Encryption control panel
fveskybackup.dll  6.3.9600.16384  Windows BitLocker Drive Encryption SkyDrive Backup
fveui.dll  6.3.9600.16384  BitLocker Drive Encryption UI
fvewiz.dll  6.3.9600.16384  BitLocker Drive Encryption Wizard
fwcfg.dll  6.3.9600.16384  Windows Firewall Configuration Helper
fwpuclnt.dll  6.3.9600.16384  FWP/IPsec User-Mode API
fwremotesvr.dll  6.3.9600.16384  Windows Firewall Remote APIs Server
fxsapi.dll  6.3.9600.16384  Microsoft Fax API Support DLL
fxscom.dll  6.3.9600.16384  Microsoft Fax Server COM Client Interface
fxscomex.dll  6.3.9600.16384  Microsoft Fax Server Extended COM Client Interface
fxscompose.dll  6.3.9600.16384  Compose Form
fxscomposeres.dll  6.3.9600.16384  Fax Compose
fxsevent.dll  6.3.9600.16384  Microsoft Fax EventLog Support DLL
fxsext32.dll  6.3.9600.16384  Microsoft Fax Exchange Command Extension
fxsmon.dll  6.3.9600.16384  Microsoft Fax Print Monitor
fxsresm.dll  6.3.9600.16384  Microsoft Fax Resource DLL
fxsroute.dll  6.3.9600.16384  Microsoft Fax Routing DLL
fxsst.dll  6.3.9600.16384  Fax Service
fxst30.dll  6.3.9600.16384  Microsoft Fax T30 Protocol Service Provider
fxstiff.dll  6.3.9600.16384  Microsoft Fax TIFF library
fxsutility.dll  6.3.9600.16384  Fax Utility DLL
fxsxp32.dll  6.3.9600.16384  Microsoft Fax Transport Provider
gacinstall.dll  6.3.9600.16384  Installers for CLR and other managed code
gameux.dll  6.3.9600.16384  Games Explorer
gameuxlegacygdfs.dll  1.0.0.1  Legacy GDF resource DLL
gcdef.dll  6.3.9600.16384  Game Controllers Default Sheets
gdi32.dll  6.3.9600.16384  GDI Client DLL
gdiplus.dll  6.3.9600.16384  Microsoft GDI+
geofencemonitorservice.dll  6.3.9600.16384  Windows Location Framework Service
getuname.dll  6.3.9600.16384  Unicode name Dll for UCE
gfxres.dll  1.0.0.0  GfxRes
gfxsrvc.dll  8.15.10.3286  
glcndfilter.dll  6.3.9600.16384  Windows Reader
glmf32.dll  6.3.9600.16384  OpenGL Metafiling DLL
globcollationhost.dll  6.3.9600.16384  GlobCollationHost
globinputhost.dll  6.3.9600.16384  Windows Globalization Extension API for Input
glu32.dll  6.3.9600.16384  OpenGL Utility Library DLL
gpapi.dll  6.3.9600.16384  Group Policy Client API
gpedit.dll  6.3.9600.16384  GPEdit
gpprnext.dll  6.3.9600.16384  Group Policy Printer Extension
gpsvc.dll  6.3.9600.16384  Group Policy Client
gptext.dll  6.3.9600.16384  GPTExt
groupinghc.dll  6.3.9600.16384  Grouping Helper Class
hal.dll  6.3.9600.16384  Hardware Abstraction Layer DLL
halextintclpiodma.dll  6.3.9600.16384  HAL Extension for Intel(R) Low Power Subsystem DMA Controller
halextintcuartdma.dll  6.3.9600.16384  HAL Extension for Intel(R) UART DMA Controller
halmacpi.dll  6.3.9600.16384  Hardware Abstraction Layer DLL
hbaapi.dll  6.3.9600.16384  HBA API data interface dll for HBA_API_Rev_2-18_2002MAR1.doc
hccutils.dll  8.15.10.3286  hccutils Module
hcproviders.dll  6.3.9600.16384  Action Center Providers
helppaneproxy.dll  6.3.9600.16384  Microsoft® Help Proxy
hgcpl.dll  6.3.9600.16384  HomeGroup Control Panel
hgprint.dll  6.3.9600.16384  HomeGroup Printing Support
hhsetup.dll  6.3.9600.16384  Microsoft® HTML Help
hid.dll  6.3.9600.16384  Hid User Library
hidserv.dll  6.3.9600.16384  Human Interface Device Service
hlink.dll  6.3.9600.16384  Microsoft Office 2000 component
hnetcfg.dll  6.3.9600.16384  Home Networking Configuration Manager
hnetmon.dll  6.3.9600.16384  Home Networking Monitor DLL
hotplug.dll  6.3.9600.16384  Safely Remove Hardware applet
hotspotauth.dll  6.3.9600.16384  Microsoft Windows Hotspot Authentication
httpapi.dll  6.3.9600.16384  HTTP Protocol Stack API
httpprxm.dll  6.3.9600.16384  Proxy Manager
httpprxp.dll  6.3.9600.16384  Proxy Manager Provider RPC interface
htui.dll  6.3.9600.16384  Common halftone Color Adjustment Dialogs
ias.dll  6.3.9600.16384  Network Policy Server
iasacct.dll  6.3.9600.16384  NPS Accounting Provider
iasads.dll  6.3.9600.16384  NPS Active Directory Data Store
iasdatastore.dll  6.3.9600.16384  NPS Datastore server
iashlpr.dll  6.3.9600.16384  NPS Surrogate Component
iasmigplugin.dll  6.3.9600.16384  NPS Migration DLL
iasnap.dll  6.3.9600.16384  NPS NAP Provider
iaspolcy.dll  6.3.9600.16384  NPS Pipeline
iasrad.dll  6.3.9600.16384  NPS RADIUS Protocol Component
iasrecst.dll  6.3.9600.16384  NPS XML Datastore Access
iassam.dll  6.3.9600.16384  NPS NT SAM Provider
iassdo.dll  6.3.9600.16384  NPS SDO Component
iassvcs.dll  6.3.9600.16384  NPS Services Component
icclibdll.dll    
iccvid.dll  1.10.0.12  Cinepak® Codec
icfupgd.dll  6.3.9600.16384  Windows Firewal ICF Settings Upgrade
icm32.dll  6.3.9600.16384  Microsoft Color Management Module (CMM)
icmp.dll  6.3.9600.16384  ICMP DLL
icmui.dll  6.3.9600.16384  Microsoft Color Matching System User Interface DLL
iconcodecservice.dll  6.3.9600.16384  Converts a PNG part of the icon to a legacy bmp icon
icsigd.dll  6.3.9600.16384  Internet Gateway Device properties
icsvc.dll  6.3.9600.16384  Virtual Machine Integration Component Service
idctrls.dll  6.3.9600.16384  Identity Controls
idlisten.dll  6.3.9600.16384  Identity Listener
idndl.dll  6.3.9600.16384  Downlevel DLL
idstore.dll  6.3.9600.16384  Identity Store
ieadvpack.dll  11.0.9600.16384  ADVPACK
ieapfltr.dll  11.0.9600.16384  Microsoft SmartScreen Filter
iedkcs32.dll  18.0.9600.16384  IEAK branding
ieetwcollectorres.dll  11.0.9600.16384  IE ETW Collector Service Resources
ieetwproxystub.dll  11.0.9600.16384  IE ETW Collector Proxy Stub Resources
ieframe.dll  11.0.9600.16384  Internet Browser
iepeers.dll  11.0.9600.16384  Internet Explorer Peer Objects
iernonce.dll  11.0.9600.16384  Extended RunOnce processing with UI
iertutil.dll  11.0.9600.16384  Run time utility for Internet Explorer
iesetup.dll  11.0.9600.16384  IOD Version Map
iesysprep.dll  11.0.9600.16384  IE Sysprep Provider
ieui.dll  11.0.9600.16384  Internet Explorer UI Engine
ifmon.dll  6.3.9600.16384  IF Monitor DLL
ifsutil.dll  6.3.9600.16384  IFS Utility DLL
ifsutilx.dll  6.3.9600.16384  IFS Utility Extension DLL
ig7icd32.dll  10.18.10.3286  OpenGL(R) Driver for Intel(R) Graphics Accelerator
igd10iumd32.dll  10.18.10.3286  User Mode Driver for Intel(R) Graphics Technology
igdail32.dll    
igdbcl32.dll  6.14.10.9141  OpenCL User Mode Driver for Intel(R) Graphics Technology
igdde32.dll    
igddiag.dll  6.3.9600.16384  IGD Helper Class
igdfcl32.dll  8.1.0.2998  OpenCL Driver for Intel(R) Graphics Technology
igdmd32.dll    
igdrcl32.dll  10.18.10.3286  OpenCL User Mode Driver for Intel(R) Graphics Technology
igdumdim32.dll  10.18.10.3286  User Mode Driver for Intel(R) Graphics Technology
igdusc32.dll  8.15.10.9141  Unified Shader Compiler for Intel(R) Graphics Accelerator
igfx11cmrt32.dll  3.0.0.1015  MDF(CM) Runtime DX11 Dynamic Link Library
igfxcmjit32.dll  3.0.0.1015  MDF(CM) JIT Dynamic Link Library
igfxcmrt32.dll  3.0.0.1015  MDF(CM) Runtime Dynamic Link Library
igfxcoin_v3286.dll  1.2.30.0  Intel(R) Graphics Media Accelerator Driver Coinstaller
igfxdev.dll  8.15.10.3286  igfxdev Module
igfxdevlib.dll  1.0.0.0  
igfxdo.dll  8.15.10.3286  igfxdo Module
igfxexps.dll  8.15.10.3286  igfxext Module
igfxpph.dll  8.15.10.3286  igfxpph Module
igfxress.dll  8.15.10.3286  igfxress Module
igfxsrvc.dll  8.15.10.3286  igfxsrvc Module
igfxtmm.dll  8.15.10.3286  igfxTMM Module
iglhcp32.dll  9.0.20.9000  iglhcp32 Dynamic Link Library
iglhsip32.dll  9.0.20.9000  iglhsip32 Dynamic Link Library
ikeext.dll  6.3.9600.16384  IKE extension
imagehlp.dll  6.3.9600.16384  Windows NT Image Helper
imageres.dll  6.3.9600.16384  Windows Image Resource
imagesp1.dll  6.3.9600.16384  Windows SP1 Image Resource
imapi.dll  6.3.9600.16384  Image Mastering API
imapi2.dll  6.3.9600.16384  Image Mastering API v2
imapi2fs.dll  6.3.9600.16384  Image Mastering File System Imaging API v2
imgutil.dll  11.0.9600.16384  IE plugin image decoder support DLL
imm32.dll  6.3.9600.16384  Multi-User Windows IMM32 API Client DLL
inetcomm.dll  6.3.9600.16384  Microsoft Internet Messaging API Resources
inetmib1.dll  6.3.9600.16384  Microsoft MIB-II subagent
inetpp.dll  6.3.9600.16384  Internet Print Provider DLL
inetppui.dll  6.3.9600.16384  Internet Print Client DLL
inetres.dll  6.3.9600.16384  Microsoft Internet Messaging API Resources
inked.dll  6.3.9600.16384  Microsoft Tablet PC InkEdit Control
input.dll  6.3.9600.16384  InputSetting DLL
inputswitch.dll  6.3.9600.16384  Microsoft Windows Input Switcher
inseng.dll  11.0.9600.16384  Install engine
intel_opencl_icd32.dll  1.2.11.0  OpenCL Client DLL
intelcameraplugin.dll  1.0.0.1  Intel(R) Camera MFT
intelopencl32.dll  1.1.0.1005  Intel(R) OpenCL(TM) Runtime
intelsocyuvcopy.dll  1.0.0.1  Intel(R) SoC YUV Copy Filter
intelwidiaac32.dll  4.5.27.0  Intel AAC
intelwidiaudiofilter32.dll  4.5.27.0  Audio Source Filter.
intelwididdeagent32.dll  4.5.27.0  IntelWiDiDDEAgent.dll COM object.
intelwidilogserver32.dll  4.5.27.0  Logging Server
intelwidimcumd32.dll  4.5.27.0  IntelWiDiMCUMD.dll
intelwidimux32.dll  4.5.27.0  Intel(R) TS Mux / Network Renderer
intelwidisecuresourcefilter32.dll  4.5.27.0  Secure Video Source Filter.
intelwidisilencefilter32.dll  4.5.27.0  Silence Audio Filter.
intelwidiutils32.dll  4.5.27.0  Platform Detection Library
intelwidiwinnextagent32.dll  4.5.27.0  IntelWiDiWinNextAgent.dll COM object.
iologmsg.dll  6.3.9600.16384  IO Logging DLL
iphlpapi.dll  6.3.9600.16384  IP Helper API
iphlpsvc.dll  6.3.9600.16384  Service that offers IPv6 connectivity over an IPv4 network.
ipnathlp.dll  6.3.9600.16384  Microsoft NAT Helper Components
iprop.dll  6.3.9600.16384  OLE PropertySet Implementation
iprtprio.dll  6.3.9600.16384  IP Routing Protocol Priority DLL
iprtrmgr.dll  6.3.9600.16384  IP Router Manager
ipsecsnp.dll  6.3.9600.16384  IP Security Policy Management Snap-in
ipsecsvc.dll  6.3.9600.16384  Windows IPsec SPD Server DLL
ipsmsnap.dll  6.3.9600.16384  IP Security Monitor Snap-in
ir32_32.dll  6.3.9600.16384  IR32_32 WRAPPER DLL
ir32_32original.dll  3.24.15.3  Intel Indeo(R) Video R3.2 32-bit Driver
ir41_32original.dll  4.51.16.3  Intel Indeo® Video 4.5
ir41_qc.dll  6.3.9600.16384  IR41_QC WRAPPER DLL
ir41_qcoriginal.dll  4.30.62.2  Intel Indeo® Video Interactive Quick Compressor
ir41_qcx.dll  6.3.9600.16384  IR41_QCX WRAPPER DLL
ir41_qcxoriginal.dll  4.30.64.1  Intel Indeo® Video Interactive Quick Compressor
ir50_32.dll  6.3.9600.16384  IR50_32 WRAPPER DLL
ir50_32original.dll  5.2562.15.55  Intel Indeo® video 5.10
ir50_qc.dll  6.3.9600.16384  IR50_QC WRAPPER DLL
ir50_qcoriginal.dll  5.0.63.48  Intel Indeo® video 5.10 Quick Compressor
ir50_qcx.dll  6.3.9600.16384  IR50_QCX WRAPPER DLL
ir50_qcxoriginal.dll  5.0.64.48  Intel Indeo® video 5.10 Quick Compressor
irclass.dll  6.3.9600.16384  Infrared Class Coinstaller
irmon.dll  6.3.9600.16384  Infrared Monitor
iscsicpl.dll  5.2.3790.1830  iSCSI Initiator Control Panel Applet
iscsidsc.dll  6.3.9600.16384  iSCSI Discovery api
iscsied.dll  6.3.9600.16384  iSCSI Extension DLL
iscsiexe.dll  6.3.9600.16384  iSCSI Discovery service
iscsilog.dll  6.3.9600.16384  iSCSI Event Log DLL
iscsium.dll  6.3.9600.16384  iSCSI Discovery api
iscsiwmi.dll  6.3.9600.16384  MS iSCSI Initiator WMI Provider
iscsiwmiv2.dll  6.3.9600.16384  WMI Provider for iSCSI
itircl.dll  6.3.9600.16384  Microsoft® InfoTech IR Local DLL
itss.dll  6.3.9600.16384  Microsoft® InfoTech Storage System Library
iuilp.dll  6.3.9600.16384  iuilp
iyuv_32.dll  6.3.9600.16384  Intel Indeo(R) Video YUV Codec
javascriptcollectionagent.dll  11.0.9600.16384  JavaScript Performance Collection Agent
jnwmon.dll  0.3.9600.16384  Windows Journal Port Monitor DLL
jscript.dll  5.8.9600.16384  Microsoft ® JScript
jscript9.dll  11.0.9600.16384  Microsoft ® JScript
jscript9diag.dll  11.0.9600.16384  Microsoft ® JScript Diagnostics
jsproxy.dll  11.0.9600.16384  JScript Proxy Auto-Configuration
kbd101.dll  6.3.9600.16384  JP Japanese Keyboard Layout for 101
kbd101a.dll  6.3.9600.16384  KO Hangeul Keyboard Layout for 101 (Type A)
kbd101b.dll  6.3.9600.16384  KO Hangeul Keyboard Layout for 101(Type B)
kbd101c.dll  6.3.9600.16384  KO Hangeul Keyboard Layout for 101(Type C)
kbd103.dll  6.3.9600.16384  KO Hangeul Keyboard Layout for 103
kbd106.dll  6.3.9600.16384  JP Japanese Keyboard Layout for 106
kbd106n.dll  6.3.9600.16384  JP Japanese Keyboard Layout for 106
kbda1.dll  6.3.9600.16384  Arabic_English_101 Keyboard Layout
kbda2.dll  6.3.9600.16384  Arabic_2 Keyboard Layout
kbda3.dll  6.3.9600.16384  Arabic_French_102 Keyboard Layout
kbdal.dll  6.3.9600.16384  Albania Keyboard Layout
kbdarme.dll  6.3.9600.16384  Eastern Armenian Keyboard Layout
kbdarmph.dll  6.3.9600.16384  Armenian Phonetic Keyboard Layout
kbdarmty.dll  6.3.9600.16384  Armenian Typewriter Keyboard Layout
kbdarmw.dll  6.3.9600.16384  Western Armenian Keyboard Layout
kbdax2.dll  6.3.9600.16384  JP Japanese Keyboard Layout for AX2
kbdaze.dll  6.3.9600.16384  Azerbaijan_Cyrillic Keyboard Layout
kbdazel.dll  6.3.9600.16384  Azeri-Latin Keyboard Layout
kbdazst.dll  6.3.9600.16384  Azerbaijani (Standard) Keyboard Layout
kbdbash.dll  6.3.9600.16384  Bashkir Keyboard Layout
kbdbe.dll  6.3.9600.16384  Belgian Keyboard Layout
kbdbene.dll  6.3.9600.16384  Belgian Dutch Keyboard Layout
kbdbgph.dll  6.3.9600.16384  Bulgarian Phonetic Keyboard Layout
kbdbgph1.dll  6.3.9600.16384  Bulgarian (Phonetic Traditional) Keyboard Layout
kbdbhc.dll  6.3.9600.16384  Bosnian (Cyrillic) Keyboard Layout
kbdblr.dll  6.3.9600.16384  Belarusian Keyboard Layout
kbdbr.dll  6.3.9600.16384  Brazilian Keyboard Layout
kbdbu.dll  6.3.9600.16384  Bulgarian (Typewriter) Keyboard Layout
kbdbug.dll  6.3.9600.16384  Buginese Keyboard Layout
kbdbulg.dll  6.3.9600.16384  Bulgarian Keyboard Layout
kbdca.dll  6.3.9600.16384  Canadian Multilingual Keyboard Layout
kbdcan.dll  6.3.9600.16384  Canadian Multilingual Standard Keyboard Layout
kbdcher.dll  6.3.9600.16384  Cherokee Nation Keyboard Layout
kbdcherp.dll  6.3.9600.16384  Cherokee Phonetic Keyboard Layout
kbdcr.dll  6.3.9600.16384  Croatian/Slovenian Keyboard Layout
kbdcz.dll  6.3.9600.16384  Czech Keyboard Layout
kbdcz1.dll  6.3.9600.16384  Czech_101 Keyboard Layout
kbdcz2.dll  6.3.9600.16384  Czech_Programmer's Keyboard Layout
kbdda.dll  6.3.9600.16384  Danish Keyboard Layout
kbddiv1.dll  6.3.9600.16384  Divehi Phonetic Keyboard Layout
kbddiv2.dll  6.3.9600.16384  Divehi Typewriter Keyboard Layout
kbddv.dll  6.3.9600.16384  Dvorak US English Keyboard Layout
kbdes.dll  6.3.9600.16384  Spanish Alernate Keyboard Layout
kbdest.dll  6.3.9600.16384  Estonia Keyboard Layout
kbdfa.dll  6.3.9600.16384  Persian Keyboard Layout
kbdfar.dll  6.3.9600.16384  Persian Standard Keyboard Layout
kbdfc.dll  6.3.9600.16384  Canadian French Keyboard Layout
kbdfi.dll  6.3.9600.16384  Finnish Keyboard Layout
kbdfi1.dll  6.3.9600.16384  Finnish-Swedish with Sami Keyboard Layout
kbdfo.dll  6.3.9600.16384  Faroese Keyboard Layout
kbdfr.dll  6.3.9600.16384  French Keyboard Layout
kbdfthrk.dll  6.3.9600.16384  Futhark Keyboard Layout
kbdgae.dll  6.3.9600.16384  Scottish Gaelic (United Kingdom) Keyboard Layout
kbdgeo.dll  6.3.9600.16384  Georgian Keyboard Layout
kbdgeoer.dll  6.3.9600.16384  Georgian (Ergonomic) Keyboard Layout
kbdgeome.dll  6.3.9600.16384  Georgian (MES) Keyboard Layout
kbdgeooa.dll  6.3.9600.16384  Georgian (Old Alphabets) Keyboard Layout
kbdgeoqw.dll  6.3.9600.16384  Georgian (QWERTY) Keyboard Layout
kbdgkl.dll  6.3.9600.16384  Greek_Latin Keyboard Layout
kbdgn.dll  6.3.9600.16384  Guarani Keyboard Layout
kbdgr.dll  6.3.9600.16384  German Keyboard Layout
kbdgr1.dll  6.3.9600.16384  German_IBM Keyboard Layout
kbdgrlnd.dll  6.3.9600.16384  Greenlandic Keyboard Layout
kbdgthc.dll  6.3.9600.16384  Gothic Keyboard Layout
kbdhau.dll  6.3.9600.16384  Hausa Keyboard Layout
kbdhaw.dll  6.3.9600.16384  Hawaiian Keyboard Layout
kbdhe.dll  6.3.9600.16384  Greek Keyboard Layout
kbdhe220.dll  6.3.9600.16384  Greek IBM 220 Keyboard Layout
kbdhe319.dll  6.3.9600.16384  Greek IBM 319 Keyboard Layout
kbdheb.dll  6.3.9600.16384  KBDHEB Keyboard Layout
kbdhebl3.dll  6.3.9600.16384  Hebrew Standard Keyboard Layout
kbdhela2.dll  6.3.9600.16384  Greek IBM 220 Latin Keyboard Layout
kbdhela3.dll  6.3.9600.16384  Greek IBM 319 Latin Keyboard Layout
kbdhept.dll  6.3.9600.16384  Greek_Polytonic Keyboard Layout
kbdhu.dll  6.3.9600.16384  Hungarian Keyboard Layout
kbdhu1.dll  6.3.9600.16384  Hungarian 101-key Keyboard Layout
kbdibm02.dll  6.3.9600.16384  JP Japanese Keyboard Layout for IBM 5576-002/003
kbdibo.dll  6.3.9600.16384  Igbo Keyboard Layout
kbdic.dll  6.3.9600.16384  Icelandic Keyboard Layout
kbdinasa.dll  6.3.9600.16384  Assamese (Inscript) Keyboard Layout
kbdinbe1.dll  6.3.9600.16384  Bengali - Inscript (Legacy) Keyboard Layout
kbdinbe2.dll  6.3.9600.16384  Bengali (Inscript) Keyboard Layout
kbdinben.dll  6.3.9600.16384  Bengali Keyboard Layout
kbdindev.dll  6.3.9600.16384  Devanagari Keyboard Layout
kbdinen.dll  6.3.9600.16384  English - India Keyboard Layout
kbdinguj.dll  6.3.9600.16384  Gujarati Keyboard Layout
kbdinhin.dll  6.3.9600.16384  Hindi Keyboard Layout
kbdinkan.dll  6.3.9600.16384  Kannada Keyboard Layout
kbdinmal.dll  6.3.9600.16384  Malayalam Keyboard Layout Keyboard Layout
kbdinmar.dll  6.3.9600.16384  Marathi Keyboard Layout
kbdinori.dll  6.3.9600.16384  Odia Keyboard Layout
kbdinpun.dll  6.3.9600.16384  Punjabi/Gurmukhi Keyboard Layout
kbdintam.dll  6.3.9600.16384  Tamil Keyboard Layout
kbdintel.dll  6.3.9600.16384  Telugu Keyboard Layout
kbdinuk2.dll  6.3.9600.16384  Inuktitut Naqittaut Keyboard Layout
kbdir.dll  6.3.9600.16384  Irish Keyboard Layout
kbdit.dll  6.3.9600.16384  Italian Keyboard Layout
kbdit142.dll  6.3.9600.16384  Italian 142 Keyboard Layout
kbdiulat.dll  6.3.9600.16384  Inuktitut Latin Keyboard Layout
kbdjav.dll  6.3.9600.16384  Javanese Keyboard Layout
kbdjpn.dll  6.3.9600.16384  JP Japanese Keyboard Layout Stub driver
kbdkaz.dll  6.3.9600.16384  Kazak_Cyrillic Keyboard Layout
kbdkhmr.dll  6.3.9600.16384  Cambodian Standard Keyboard Layout
kbdkni.dll  6.3.9600.16384  Khmer (NIDA) Keyboard Layout
kbdkor.dll  6.3.9600.16384  KO Hangeul Keyboard Layout Stub driver
kbdkurd.dll  6.3.9600.16384  Central Kurdish Keyboard Layout
kbdkyr.dll  6.3.9600.16384  Kyrgyz Keyboard Layout
kbdla.dll  6.3.9600.16384  Latin-American Spanish Keyboard Layout
kbdlao.dll  6.3.9600.16384  Lao Standard Keyboard Layout
kbdlisub.dll  6.3.9600.16384  Lisu Basic Keyboard Layout
kbdlisus.dll  6.3.9600.16384  Lisu Standard Keyboard Layout
kbdlk41a.dll  6.3.9600.16384  DEC LK411-AJ Keyboard Layout
kbdlt.dll  6.3.9600.16384  Lithuania Keyboard Layout
kbdlt1.dll  6.3.9600.16384  Lithuanian Keyboard Layout
kbdlt2.dll  6.3.9600.16384  Lithuanian Standard Keyboard Layout
kbdlv.dll  6.3.9600.16384  Latvia Keyboard Layout
kbdlv1.dll  6.3.9600.16384  Latvia-QWERTY Keyboard Layout
kbdlvst.dll  6.3.9600.16384  Latvian (Standard) Keyboard Layout
kbdmac.dll  6.3.9600.16384  Macedonian (FYROM) Keyboard Layout
kbdmacst.dll  6.3.9600.16384  Macedonian (FYROM) - Standard Keyboard Layout
kbdmaori.dll  6.3.9600.16384  Maori Keyboard Layout
kbdmlt47.dll  6.3.9600.16384  Maltese 47-key Keyboard Layout
kbdmlt48.dll  6.3.9600.16384  Maltese 48-key Keyboard Layout
kbdmon.dll  6.3.9600.16384  Mongolian Keyboard Layout
kbdmonmo.dll  6.3.9600.16384  Mongolian (Mongolian Script) Keyboard Layout
kbdmonst.dll  6.3.9600.16384  Traditional Mongolian (Standard) Keyboard Layout
kbdmyan.dll  6.3.9600.16384  Myanmar Keyboard Layout
kbdne.dll  6.3.9600.16384  Dutch Keyboard Layout
kbdnec.dll  6.3.9600.16384  JP Japanese Keyboard Layout for (NEC PC-9800)
kbdnec95.dll  6.3.9600.16384  JP Japanese Keyboard Layout for (NEC PC-9800 Windows 95)
kbdnecat.dll  6.3.9600.16384  JP Japanese Keyboard Layout for (NEC PC-9800 on PC98-NX)
kbdnecnt.dll  6.3.9600.16384  JP Japanese NEC PC-9800 Keyboard Layout
kbdnepr.dll  6.3.9600.16384  Nepali Keyboard Layout
kbdnko.dll  6.3.9600.16384  N'Ko Keyboard Layout
kbdno.dll  6.3.9600.16384  Norwegian Keyboard Layout
kbdno1.dll  6.3.9600.16384  Norwegian with Sami Keyboard Layout
kbdnso.dll  6.3.9600.16384  Sesotho sa Leboa Keyboard Layout
kbdntl.dll  6.3.9600.16384  New Tai Leu Keyboard Layout
kbdogham.dll  6.3.9600.16384  Ogham Keyboard Layout
kbdolch.dll  6.3.9600.16384  Ol Chiki Keyboard Layout
kbdoldit.dll  6.3.9600.16384  Old Italic Keyboard Layout
kbdosm.dll  6.3.9600.16384  Osmanya Keyboard Layout
kbdpash.dll  6.3.9600.16384  Pashto (Afghanistan) Keyboard Layout
kbdphags.dll  6.3.9600.16384  Phags-pa Keyboard Layout
kbdpl.dll  6.3.9600.16384  Polish Keyboard Layout
kbdpl1.dll  6.3.9600.16384  Polish Programmer's Keyboard Layout
kbdpo.dll  6.3.9600.16384  Portuguese Keyboard Layout
kbdro.dll  6.3.9600.16384  Romanian (Legacy) Keyboard Layout
kbdropr.dll  6.3.9600.16384  Romanian (Programmers) Keyboard Layout
kbdrost.dll  6.3.9600.16384  Romanian (Standard) Keyboard Layout
kbdru.dll  6.3.9600.16384  Russian Keyboard Layout
kbdru1.dll  6.3.9600.16384  Russia(Typewriter) Keyboard Layout
kbdrum.dll  6.3.9600.16384  Russian - Mnemonic Keyboard Layout
kbdsf.dll  6.3.9600.16384  Swiss French Keyboard Layout
kbdsg.dll  6.3.9600.16384  Swiss German Keyboard Layout
kbdsl.dll  6.3.9600.16384  Slovak Keyboard Layout
kbdsl1.dll  6.3.9600.16384  Slovak(QWERTY) Keyboard Layout
kbdsmsfi.dll  6.3.9600.16384  Sami Extended Finland-Sweden Keyboard Layout
kbdsmsno.dll  6.3.9600.16384  Sami Extended Norway Keyboard Layout
kbdsn1.dll  6.3.9600.16384  Sinhala Keyboard Layout
kbdsora.dll  6.3.9600.16384  Sora Keyboard Layout
kbdsorex.dll  6.3.9600.16384  Sorbian Extended Keyboard Layout
kbdsors1.dll  6.3.9600.16384  Sorbian Standard Keyboard Layout
kbdsorst.dll  6.3.9600.16384  Sorbian Standard (Legacy) Keyboard Layout
kbdsp.dll  6.3.9600.16384  Spanish Keyboard Layout
kbdsw.dll  6.3.9600.16384  Swedish Keyboard Layout
kbdsw09.dll  6.3.9600.16384  Sinhala - Wij 9 Keyboard Layout
kbdsyr1.dll  6.3.9600.16384  Syriac Standard Keyboard Layout
kbdsyr2.dll  6.3.9600.16384  Syriac Phoenetic Keyboard Layout
kbdtaile.dll  6.3.9600.16384  Tai Le Keyboard Layout
kbdtajik.dll  6.3.9600.16384  Tajik Keyboard Layout
kbdtat.dll  6.3.9600.16384  Tatar (Legacy) Keyboard Layout
kbdth0.dll  6.3.9600.16384  Thai Kedmanee Keyboard Layout
kbdth1.dll  6.3.9600.16384  Thai Pattachote Keyboard Layout
kbdth2.dll  6.3.9600.16384  Thai Kedmanee (non-ShiftLock) Keyboard Layout
kbdth3.dll  6.3.9600.16384  Thai Pattachote (non-ShiftLock) Keyboard Layout
kbdtifi.dll  6.3.9600.16384  Tifinagh (Basic) Keyboard Layout
kbdtifi2.dll  6.3.9600.16384  Tifinagh (Extended) Keyboard Layout
kbdtiprc.dll  6.3.9600.16384  Tibetan (PRC) Keyboard Layout
kbdtiprd.dll  6.3.9600.16384  Tibetan (PRC) - Updated Keyboard Layout
kbdtt102.dll  6.3.9600.16384  Tatar Keyboard Layout
kbdtuf.dll  6.3.9600.16384  Turkish F Keyboard Layout
kbdtuq.dll  6.3.9600.16384  Turkish Q Keyboard Layout
kbdturme.dll  6.3.9600.16384  Turkmen Keyboard Layout
kbdtzm.dll  6.3.9600.16384  Central Atlas Tamazight Keyboard Layout
kbdughr.dll  6.3.9600.16384  Uyghur (Legacy) Keyboard Layout
kbdughr1.dll  6.3.9600.16384  Uyghur Keyboard Layout
kbduk.dll  6.3.9600.16384  United Kingdom Keyboard Layout
kbdukx.dll  6.3.9600.16384  United Kingdom Extended Keyboard Layout
kbdur.dll  6.3.9600.16384  Ukrainian Keyboard Layout
kbdur1.dll  6.3.9600.16384  Ukrainian (Enhanced) Keyboard Layout
kbdurdu.dll  6.3.9600.16384  Urdu Keyboard Layout
kbdus.dll  6.3.9600.16384  United States Keyboard Layout
kbdusa.dll  6.3.9600.16384  US IBM Arabic 238_L Keyboard Layout
kbdusl.dll  6.3.9600.16384  Dvorak Left-Hand US English Keyboard Layout
kbdusr.dll  6.3.9600.16384  Dvorak Right-Hand US English Keyboard Layout
kbdusx.dll  6.3.9600.16384  US Multinational Keyboard Layout
kbduzb.dll  6.3.9600.16384  Uzbek_Cyrillic Keyboard Layout
kbdvntc.dll  6.3.9600.16384  Vietnamese Keyboard Layout
kbdwol.dll  6.3.9600.16384  Wolof Keyboard Layout
kbdyak.dll  6.3.9600.16384  Sakha - Russia Keyboard Layout
kbdyba.dll  6.3.9600.16384  Yoruba Keyboard Layout
kbdycc.dll  6.3.9600.16384  Serbian (Cyrillic) Keyboard Layout
kbdycl.dll  6.3.9600.16384  Serbian (Latin) Keyboard Layout
kd.dll  6.3.9600.16384  Local Kernel Debugger
kd_02_10df.dll  6.3.9600.16384  Emulex Network Kernel Debug Extensibility Module
kd_02_10ec.dll  6.3.9600.16384  Realtek Network Kernel Debug Extensibility Module
kd_02_14e4.dll  6.3.9600.16384  Broadcom Network Kernel Debug Extensibility Module
kd_02_1969.dll  6.3.9600.16384  Qualcomm Atheros Network Kernel Debug Extensibility Module
kd_02_19a2.dll  6.3.9600.16384  Emulex Network Kernel Debug Extensibility Module
kd_02_8086.dll  6.3.9600.16384  Intel Network Kernel Debug Extensibility Module
kd1394.dll  6.3.9600.16384  1394 Kernel Debugger
kdcom.dll  6.3.9600.16384  Serial Kernel Debugger
kdhv1394.dll  6.3.9600.16384  Enlightened Kernel Debugger 1394 Extension DLL
kdnet.dll  6.3.9600.16384  Network Kernel Debugger
kdscli.dll  6.3.9600.16384  Microsoft Key Distribution Service Provider
kdstub.dll  6.3.9600.16384  Network Kernel Debug Extensibility Stubs
kdusb.dll  6.3.9600.16384  USB 2.0 Kernel Debugger
keepaliveprovider.dll  6.3.9600.16384  Keep alive provider API
kerberos.dll  6.3.9600.16384  Kerberos Security Package
kernel.appcore.dll  6.3.9600.16384  AppModel API Host
kernel32.dll  6.3.9600.16384  Windows NT BASE API Client DLL
kernelbase.dll  6.3.9600.16384  Windows NT BASE API Client DLL
kernelceip.dll  6.3.9600.16384  Kernel Ceip Task
keyiso.dll  6.3.9600.16384  CNG Key Isolation Service
keymgr.dll  6.3.9600.16384  Stored User Names and Passwords
kmsvc.dll  6.3.9600.16384  Key Management Service
korwbrkr.dll  6.3.9600.16384  Korean Word Breaker
ksuser.dll  6.3.9600.16384  User CSA Library
ktmw32.dll  6.3.9600.16384  Windows KTM Win32 Client DLL
l2gpstore.dll  6.3.9600.16384  Policy Storage dll
l2nacp.dll  6.3.9600.16384  Windows Onex Credential Provider
l2sechc.dll  6.3.9600.16384  Layer 2 Security Diagnostics Helper Classes
langcleanupsysprepaction.dll  6.3.9600.16384  Language cleanup Sysprep action
laprxy.dll  12.0.9600.16384  Windows Media Logagent Proxy
libjpegencoder.dll  1.1.0.6  Intel JPEG Encoder
licmgr10.dll  11.0.9600.16384  Microsoft® License Manager DLL
linkinfo.dll  6.3.9600.16384  Windows Volume Tracking
listsvc.dll  6.3.9600.16384  Windows HomeGroup
livessp.dll  6.3.9600.16384  Live Security Package
lldpnotify.dll  6.3.9600.16384  MSLLDP Configuration Support
lltdapi.dll  6.3.9600.16384  Link-Layer Topology Mapper API
lltdres.dll  6.3.9600.16384  Link-Layer Topology Discovery Resources
lltdsvc.dll  6.3.9600.16384  Link-Layer Topology Mapper Service
lmhsvc.dll  6.3.9600.16384  TCPIP NetBios Transport Services DLL
loadperf.dll  6.3.9600.16384  Load & Unload Performance Counters
localsec.dll  6.3.9600.16384  Local Users and Groups MMC Snapin
localspl.dll  6.3.9600.16384  Local Spooler DLL
localui.dll  6.3.9600.16384  Local Monitor UI DLL
locationapi.dll  6.3.9600.16384  Microsoft Windows Location API
lockscreencontent.dll  6.3.9600.16384  Windows Lock Screen Content
lockscreencontenthost.dll  6.3.9600.16384  LockScreenContent Host
loghours.dll  6.3.9600.16384  Schedule Dialog
logoncli.dll  6.3.9600.16384  Net Logon Client DLL
lpk.dll  6.3.9600.16384  Language Pack
lpksetupproxyserv.dll  6.3.9600.16384  COM proxy server for lpksetup.exe
lsasrv.dll  6.3.9600.16384  LSA Server DLL
lsm.dll  6.3.9600.16384  Local Session Manager Service
lsmproxy.dll  6.3.9600.16384  LSM interfaces proxy Dll
luainstall.dll  6.3.9600.16384  Lua manifest install
lz32.dll  6.3.9600.16384  LZ Expand/Compress API DLL
lzexpand.dll  3.10.0.103  Windows Win16 Application Launcher
magnification.dll  6.3.9600.16384  Microsoft Magnification API
maintenanceui.dll  6.3.9600.16384  Maintenance Settings Control Panel
mapi32.dll  1.0.2536.0  Extended MAPI 1.0 for Windows NT
mapistub.dll  1.0.2536.0  Extended MAPI 1.0 for Windows NT
mbaeapi.dll  6.3.9600.16384  Mobile Broadband Account Experience API
mbaeapipublic.dll  6.3.9600.16384  Mobile Broadband Account API
mbaexmlparser.dll  6.3.9600.16384  Mobile Broadband Account Experience Parser
mbsmsapi.dll  6.3.9600.16384  Microsoft Windows Mobile Broadband SMS API
mbussdapi.dll  6.3.9600.16384  Microsoft Windows Mobile Broadband USSD API
mcewmdrmndbootstrap.dll  1.3.2310.10  Windows® Media Center WMDRM-ND Receiver Bridge Bootstrap DLL
mciavi32.dll  6.3.9600.16384  Video For Windows MCI driver
mcicda.dll  6.3.9600.16384  MCI driver for cdaudio devices
mciqtz32.dll  6.6.9600.16384  DirectShow MCI Driver
mciseq.dll  6.3.9600.16384  MCI driver for MIDI sequencer
mciwave.dll  6.3.9600.16384  MCI driver for waveform audio
mcupdate_authenticamd.dll  6.3.9600.16384  AMD Microcode Update Library
mcupdate_genuineintel.dll  6.3.9600.16384  Intel Microcode Update Library
mcxdriv.dll  6.3.9600.16384  Media Center Extender Resources
mdminst.dll  6.3.9600.16384  Modem Class Installer
mdmregistration.dll  6.3.9600.16384  MDM Registration DLL
memorydiagnostic.dll  6.3.9600.16384  Microsoft Windows Memory Diagnostic Task Handler
metrointelgenericuiframework.dll  1.0.0.0  MetroIntelGenericUIFramework
mf.dll  12.0.9600.16384  Media Foundation DLL
mf3216.dll  6.3.9600.16384  32-bit to 16-bit Metafile Conversion DLL
mfaacenc.dll  6.3.9600.16384  Media Foundation AAC Encoder
mfasfsrcsnk.dll  12.0.9600.16384  Media Foundation ASF Source and Sink DLL
mfc40.dll  4.1.0.6140  MFCDLL Shared Library - Retail Version
mfc40u.dll  4.1.0.6140  MFCDLL Shared Library - Retail Version
mfc42.dll  6.6.8063.0  MFCDLL Shared Library - Retail Version
mfc42u.dll  6.6.8063.0  MFCDLL Shared Library - Retail Version
mfcaptureengine.dll  12.0.9600.16384  Media Foundation CaptureEngine DLL
mfcore.dll  12.0.9600.16384  Media Foundation Core DLL
mfcsubs.dll  2001.12.10530.16384  COM+
mfds.dll  12.0.9600.16384  Media Foundation Direct Show wrapper DLL
mfdvdec.dll  6.3.9600.16384  Media Foundation DV Decoder
mferror.dll  12.0.9600.16384  Media Foundation Error DLL
mfh264enc.dll  6.3.9600.16384  Media Foundation H264 Encoder
mfmediaengine.dll  6.3.9600.16384  Media Foundation Media Engine DLL
mfmjpegdec.dll  6.3.9600.16384  Media Foundation MJPEG Decoder
mfmp4srcsnk.dll  12.0.9600.16384  Media Foundation MPEG4 Source and Sink DLL
mfmpeg2srcsnk.dll  12.0.9600.16384  Media Foundation MPEG2 Source and Sink DLL
mfnetcore.dll  12.0.9600.16384  Media Foundation Net Core DLL
mfnetsrc.dll  12.0.9600.16384  Media Foundation Net Source DLL
mfplat.dll  12.0.9600.16442  Media Foundation Platform DLL
mfplay.dll  12.0.9600.16384  Media Foundation Playback API DLL
mfps.dll  12.0.9600.16384  Media Foundation Proxy DLL
mfreadwrite.dll  12.0.9600.16384  Media Foundation ReadWrite DLL
mfsrcsnk.dll  12.0.9600.16384  Media Foundation Source and Sink DLL
mfsvr.dll  6.3.9600.16384  Media Foundation Simple Video Renderer DLL
mftranscode.dll  12.0.9600.16384  Media Foundation Transcode DLL
mfvdsp.dll  6.3.9600.16384  Windows Media Foundation Video DSP Components
mfwmaaec.dll  6.3.9600.16384  Windows Media Audio AEC for Media Foundation
mgmtapi.dll  6.3.9600.16384  Microsoft SNMP Manager API (uses WinSNMP)
mi.dll  6.3.9600.16384  Management Infrastructure
mibincodec.dll  6.3.9600.16384  Management Infrastructure binary codec component
microsoft.management.infrastructure.native.unmanaged.dll  6.3.9600.16384  Microsoft.Management.Infrastructure.Native.Unmanaged.dll
microsoftaccounttokenprovider.dll  6.3.9600.16384  Microsoft® Account Token Provider
microsoft-windows-battery-events.dll  6.3.9600.16384  Microsoft-Windows-Battery-Events Resources
microsoft-windows-hal-events.dll  6.3.9600.16384  Microsoft-Windows-HAL-Events Resources
microsoft-windows-kernel-pnp-events.dll  6.3.9600.16384  Microsoft-Windows-Kernel-Pnp-Events Resources
microsoft-windows-kernel-power-events.dll  6.3.9600.16384  Microsoft-Windows-Kernel-Power-Events Resources
microsoft-windows-kernel-processor-power-events.dll  6.3.9600.16384  Microsoft-Windows-Kernel-Processor-Power-Events Resources
microsoft-windows-pdc.dll  6.3.9600.16384  Microsoft-Windows-Pdc Resources
microsoft-windows-processor-aggregator-events.dll  6.3.9600.16384  Microsoft-Windows-Processor-Aggregator-Events Resources
microsoft-windows-sleepstudy-events.dll  6.3.9600.16384  Microsoft-Windows-SleepStudy-Events Resources
microsoft-windows-storage-tiering-events.dll  6.3.9600.16384  Microsoft-Windows-Storage-Tiering-Events Resources
microsoft-windows-system-events.dll  6.3.9600.16384  Microsoft-Windows-System-Events Resources
midimap.dll  6.3.9600.16384  Microsoft MIDI Mapper
migflt.dll  6.3.9600.16384  PBR Wim Capture Utility - Filter DLL
migisol.dll  6.3.9600.16384  Migration System Isolation Layer
miguiresource.dll  6.3.9600.16384  MIG wini32 resources
mimefilt.dll  2008.0.9600.16384  MIME Filter
mimofcodec.dll  6.3.9600.16384  Management Infrastructure mof codec component
mirrordrvcompat.dll  6.3.9600.16384  Mirror Driver Compatibility Helper
mispace.dll  6.3.9600.16384  Storage Management Provider for Spaces
miutils.dll  6.3.9600.16384  Management Infrastructure
mlang.dll  6.3.9600.16384  Multi Language Support DLL
mmcbase.dll  6.3.9600.16384  MMC Base DLL
mmci.dll  6.3.9600.16384  Media class installer
mmcico.dll  6.3.9600.16384  Media class co-installer
mmcndmgr.dll  6.3.9600.16384  MMC Node Manager DLL
mmcshext.dll  6.3.9600.16384  MMC Shell Extension DLL
mmcss.dll  6.3.9600.16384  Multimedia Class Scheduler Service
mmdevapi.dll  6.3.9600.16384  MMDevice API
mmres.dll  6.3.9600.16384  General Audio Resources
mmsystem.dll  3.10.0.103  Windows Win16 Application Launcher
modemui.dll  6.3.9600.16384  Windows Modem Properties
montr_ci.dll  6.3.9600.16384  Microsoft Monitor Class Installer
moricons.dll  6.3.9600.16384  Windows NT Setup Icon Resources Library
mp3dmod.dll  6.3.9600.16384  Microsoft MP3 Decoder DMO
mp43decd.dll  6.3.9600.16384  Windows Media MPEG-4 Video Decoder
mp4sdecd.dll  6.3.9600.16384  Windows Media MPEG-4 S Video Decoder
mpg4decd.dll  6.3.9600.16384  Windows Media MPEG-4 Video Decoder
mpr.dll  6.3.9600.16384  Multiple Provider Router DLL
mprapi.dll  6.3.9600.16384  Windows NT MP Router Administration DLL
mprddm.dll  6.3.9600.16384  Demand Dial Manager Supervisor
mprdim.dll  6.3.9600.16384  Dynamic Interface Manager
mprext.dll  6.3.9600.16384  Multiple Provider Router Extension DLL
mprmsg.dll  6.3.9600.16384  Multi-Protocol Router Service Messages DLL
mpssvc.dll  6.3.9600.16384  Microsoft Protection Service
mrmcorer.dll  6.3.9600.16384  Microsoft Windows MRM
mrmindexer.dll  6.3.9600.16384  Microsoft Windows MRM
msaatext.dll  2.0.10413.0  Active Accessibility text support
msac3enc.dll  6.3.9600.16384  Microsoft AC-3 Encoder
msacm.dll  3.50.0.9  Microsoft Audio Compression Manager
msacm32.dll  6.3.9600.16384  Microsoft ACM Audio Filter
msadce.dll  6.3.9600.16384  OLE DB Cursor Engine
msadcer.dll  6.3.9600.16384  OLE DB Cursor Engine Resources
msadco.dll  6.3.9600.16384  Remote Data Services Data Control
msadcor.dll  6.3.9600.16384  Remote Data Services Data Control Resources
msadds.dll  6.3.9600.16384  OLE DB Data Shape Provider
msaddsr.dll  6.3.9600.16384   OLE DB Data Shape Provider Resources
msader15.dll  6.3.9600.16384  ActiveX Data Objects Resources
msado15.dll  6.3.9600.16384  ActiveX Data Objects
msadomd.dll  6.3.9600.16384  ActiveX Data Objects (Multi-Dimensional)
msador15.dll  6.3.9600.16384  Microsoft ActiveX Data Objects Recordset
msadox.dll  6.3.9600.16384  ActiveX Data Objects Extensions
msadrh15.dll  6.3.9600.16384  ActiveX Data Objects Rowset Helper
msafd.dll  6.3.9600.16384  Microsoft Windows Sockets 2.0 Service Provider
msasn1.dll  6.3.9600.16384  ASN.1 Runtime APIs
msauddecmft.dll  6.3.9600.16384  Media Foundation Audio Decoders
msaudite.dll  6.3.9600.16384  Security Audit Events DLL
msauserext.dll  6.3.9600.16384  MSA USER Extension DLL
mscandui.dll  6.3.9600.16384  MSCANDUI Server DLL
mscat32.dll  6.3.9600.16384  MSCAT32 Forwarder DLL
msched.dll  6.3.9600.16384  Maintenance Scheduler
msclmd.dll  6.3.9600.16384  Microsoft Class Mini-driver
mscms.dll  6.3.9600.16384  Microsoft Color Matching System DLL
mscoree.dll  6.3.9600.16384  Microsoft .NET Runtime Execution Engine
mscorier.dll  6.3.9600.16384  Microsoft .NET Runtime IE resources
mscories.dll  2.0.50727.7905  Microsoft .NET IE SECURITY REGISTRATION
mscpx32r.dll  6.3.9600.16384  ODBC Code Page Translator Resources
mscpxl32.dll  6.3.9600.16384  ODBC Code Page Translator
msctf.dll  6.3.9600.16384  MSCTF Server DLL
msctfmonitor.dll  6.3.9600.16384  MsCtfMonitor DLL
msctfp.dll  6.3.9600.16384  MSCTFP Server DLL
msctfui.dll  6.3.9600.16384  MSCTFUI Server DLL
msctfuimanager.dll  6.3.9600.16384  Microsoft UIManager DLL
msdadc.dll  6.3.9600.16384  OLE DB Data Conversion Stub
msdadiag.dll  6.3.9600.16384  Built-In Diagnostics
msdaenum.dll  6.3.9600.16384  OLE DB Root Enumerator Stub
msdaer.dll  6.3.9600.16384  OLE DB Error Collection Stub
msdaora.dll  6.3.9600.16384  OLE DB Provider for Oracle
msdaorar.dll  6.3.9600.16384  OLE DB Provider for Oracle Resources
msdaosp.dll  6.3.9600.16384  OLE DB Simple Provider
msdaprsr.dll  6.3.9600.16384  OLE DB Persistence Services Resources
msdaprst.dll  6.3.9600.16384  OLE DB Persistence Services
msdaps.dll  6.3.9600.16384  OLE DB Interface Proxies/Stubs
msdarem.dll  6.3.9600.16384  OLE DB Remote Provider
msdaremr.dll  6.3.9600.16384  OLE DB Remote Provider Resources
msdart.dll  6.3.9600.16384  OLE DB Runtime Routines
msdasc.dll  6.3.9600.16384  OLE DB Service Components Stub
msdasql.dll  6.3.9600.16384  OLE DB Provider for ODBC Drivers
msdasqlr.dll  6.3.9600.16384  OLE DB Provider for ODBC Drivers Resources
msdatl3.dll  6.3.9600.16384  OLE DB Implementation Support Routines
msdatt.dll  6.3.9600.16384  OLE DB Temporary Table Services
msdaurl.dll  6.3.9600.16384  OLE DB RootBinder Stub
msdelta.dll  6.3.9600.16384  Microsoft Patch Engine
msdfmap.dll  6.3.9600.16384  Data Factory Handler
msdmo.dll  6.6.9600.16384  DMO Runtime
msdri.dll  6.3.9600.16384  Microsoft Digital Receiver Interface Class Driver
msdrm.dll  6.3.9600.16384  Windows Rights Management client
msdtckrm.dll  2001.12.10530.16384  Microsoft Distributed Transaction Coordinator OLE Transactions KTM Resource Manager DLL
msdtclog.dll  2001.12.10530.16384  Microsoft Distributed Transaction Coordinator Log Manager DLL
msdtcprx.dll  2001.12.10530.16384  Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL
msdtctm.dll  2001.12.10530.16384  Microsoft Distributed Transaction Coordinator Transaction Manager DLL
msdtcuiu.dll  2001.12.10530.16384  Microsoft Distributed Transaction Coordinator Administrative DLL
msdtcvsp1res.dll  2001.12.10530.16384  Microsoft Distributed Transaction Coordinator Resources for Vista SP1
msexch40.dll  4.0.9756.0  Microsoft Jet Exchange Isam
msexcl40.dll  4.0.9756.0  Microsoft Jet Excel Isam
msfeeds.dll  11.0.9600.16384  Microsoft Feeds Manager
msfeedsbs.dll  11.0.9600.16384  Microsoft Feeds Background Sync
msftedit.dll  6.3.9600.16384  Rich Text Edit Control, v7.5
mshtml.dll  11.0.9600.16384  Microsoft (R) HTML Viewer
mshtmldac.dll  11.0.9600.16384  DAC for Trident DOM
mshtmled.dll  11.0.9600.16384  Microsoft® HTML Editing Component
mshtmler.dll  11.0.9600.16384  Microsoft® HTML Editing Component's Resource DLL
msi.dll  5.0.9600.16384  Windows Installer
msicofire.dll  6.3.9600.16384  Corrupted MSI File Recovery Diagnostic Module
msidcrl40.dll  6.3.9600.16384  Microsoft® Account Dynamic Link Library
msident.dll  6.3.9600.16384  Microsoft Identity Manager
msidle.dll  6.3.9600.16384  User Idle Monitor
msidntld.dll  6.3.9600.16384  Microsoft Identity Manager
msieftp.dll  6.3.9600.16384  Microsoft Internet Explorer FTP Folder Shell Extension
msihnd.dll  5.0.9600.16384  Windows® installer
msiltcfg.dll  5.0.9600.16384  Windows Installer Configuration API Stub
msimg32.dll  6.3.9600.16384  GDIEXT Client DLL
msimsg.dll  5.0.9600.16384  Windows® Installer International Messages
msimtf.dll  6.3.9600.16384  Active IMM Server DLL
msisip.dll  5.0.9600.16384  MSI Signature SIP Provider
msiwer.dll  5.0.9600.16384  MSI Windows Error Reporting
msjet40.dll  4.0.9765.0  Microsoft Jet Engine Library
msjetoledb40.dll  4.0.9756.0  
msjint40.dll  4.0.9765.0  Microsoft Jet Database Engine International DLL
msjro.dll  6.3.9600.16384  Jet and Replication Objects
msjter40.dll  4.0.9756.0  Microsoft Jet Database Engine Error DLL
msjtes40.dll  4.0.9756.0  Microsoft Jet Expression Service
mskeyprotcli.dll  6.3.9600.16384  Windows Client Key Protection Provider
mskeyprotect.dll  6.3.9600.16384  Microsoft Key Protection Provider
msls31.dll  3.10.349.0  Microsoft Line Services library file
msltus40.dll  4.0.9756.0  Microsoft Jet Lotus 1-2-3 Isam
msmpeg2adec.dll  12.0.9477.0  Microsoft DTV-DVD Audio Decoder
msmpeg2enc.dll  12.0.9600.16384  Microsoft MPEG-2 Encoder
msmpeg2vdec.dll  12.0.9477.0  Microsoft DTV-DVD Video Decoder
msnetobj.dll  11.0.9600.16384  DRM ActiveX Network Object
msobjs.dll  6.3.9600.16384  System object audit names
msoeacct.dll  6.3.9600.16384  Microsoft Internet Account Manager
msoert2.dll  6.3.9600.16384  Microsoft Windows Mail RT Lib
msorc32r.dll  6.3.9600.16384  ODBC Driver for Oracle Resources
msorcl32.dll  6.3.9600.16384  ODBC Driver for Oracle
mspatcha.dll  6.3.9600.16384  Microsoft File Patch Application API
mspatchc.dll  6.3.9600.16384  Microsoft Patch Creation Engine
mspbde40.dll  4.0.9756.0  Microsoft Jet Paradox Isam
msports.dll  6.3.9600.16384  Ports Class Installer
msprivs.dll  6.3.9600.16384  Microsoft Privilege Translations
msrahc.dll  6.3.9600.16384  Remote Assistance Diagnostics Provider
msrating.dll  11.0.9600.16384  Internet Ratings and Local User Management DLL
msrd2x40.dll  4.0.9756.0  Microsoft (R) Red ISAM
msrd3x40.dll  4.0.9756.0  Microsoft (R) Red ISAM
msrdc.dll  6.3.9600.16384  Remote Differential Compression COM server
msrdpwebaccess.dll  6.3.9600.16384  Microsoft Remote Desktop Services Web Access Control
msrepl40.dll  4.0.9756.0  Microsoft Replication Library
msrle32.dll  6.3.9600.16384  Microsoft RLE Compressor
msscntrs.dll  7.0.9600.16384  PKM Perfmon Counter DLL
msscp.dll  11.0.9600.16384  Windows Media Secure Content Provider
mssha.dll  6.3.9600.16384  Windows Security Health Agent
msshavmsg.dll  6.3.9600.16384  Windows Security Health Agent Validator Message
msshooks.dll  7.0.9600.16384  Microsoft Search Hooks
mssign32.dll  6.3.9600.16384  Microsoft Trust Signing APIs
mssip32.dll  6.3.9600.16384  MSSIP32 Forwarder DLL
mssitlb.dll  7.0.9600.16384  mssitlb
msspellcheckingfacility.dll  6.3.9600.16384  Microsoft Spell Checking Facility
mssph.dll  7.0.9600.16384  Microsoft Search Protocol Handler
mssphtb.dll  7.0.9600.16384  Outlook MSSearch Connector
mssprxy.dll  7.0.9600.16384  Microsoft Search Proxy
mssrch.dll  7.0.9600.16384  Microsoft Embedded Search
mssvp.dll  7.0.9600.16384  MSSearch Vista Platform
mstask.dll  6.3.9600.16384  Task Scheduler interface DLL
mstext40.dll  4.0.9756.0  Microsoft Jet Text Isam
mstextprediction.dll  6.3.9600.16384  Microsoft TextPrediction DLL
mstscax.dll  6.3.9600.16384  Remote Desktop Services ActiveX Client
msutb.dll  6.3.9600.16384  MSUTB Server DLL
msv1_0.dll  6.3.9600.16384  Microsoft Authentication Package v1.0
msvbvm60.dll  6.0.98.15  Visual Basic Virtual Machine
msvcirt.dll  7.0.9600.16384  Windows NT IOStreams DLL
msvcp100.dll  10.0.40219.1  Microsoft® C Runtime Library
msvcp120_clr0400.dll  12.0.20806.33440  Microsoft® C Runtime Library
msvcp60.dll  7.0.9600.16384  Windows NT C++ Runtime Library DLL
msvcr100.dll  10.0.40219.1  Microsoft® C Runtime Library
msvcr100_clr0400.dll  12.0.20806.33440  Microsoft® .NET Framework
msvcr120_clr0400.dll  12.0.20806.33440  Microsoft® C Runtime Library
msvcrt.dll  7.0.9600.16384  Windows NT CRT DLL
msvcrt20.dll  2.12.0.0  Microsoft® C Runtime Library
msvcrt40.dll  6.3.9600.16384  VC 4.x CRT DLL (Forwarded to msvcrt.dll)
msvfw32.dll  6.3.9600.16384  Microsoft Video for Windows DLL
msvidc32.dll  6.3.9600.16384  Microsoft Video 1 Compressor
msvidctl.dll  6.5.9600.16384  ActiveX control for streaming video
msvideo.dll  1.15.0.1  Microsoft Video for Windows DLL
msvideodsp.dll  6.3.9600.16384  Video Stabilization MFT
msvproc.dll  12.0.9600.16384  Media Foundation Video Processor
mswb7.dll  6.3.9600.16384  MSWB7 DLL
mswb70011.dll  6.3.9600.16384  MSWB7EA DLL
mswb7001e.dll  6.3.9600.16384  MSWB7EA DLL
mswb70404.dll  6.3.9600.16384  MSWB7EA DLL
mswb70804.dll  6.3.9600.16384  MSWB7EA DLL
mswdat10.dll  4.0.9756.0  Microsoft Jet Sort Tables
mswmdm.dll  12.0.9600.16384  Windows Media Device Manager Core
mswsock.dll  6.3.9600.16384  Microsoft Windows Sockets 2.0 Service Provider
mswstr10.dll  4.0.9765.0  Microsoft Jet Sort Library
msxactps.dll  6.3.9600.16384  OLE DB Transaction Proxies/Stubs
msxbde40.dll  4.0.9756.0  Microsoft Jet xBASE Isam
msxml3.dll  8.110.9600.16384  MSXML 3.0
msxml3r.dll  8.110.9600.16384  XML Resources
msxml6.dll  6.30.9600.16384  MSXML 6.0
msxml6r.dll  6.30.9600.16384  XML Resources
msyuv.dll  6.3.9600.16384  Microsoft UYVY Video Decompressor
mtxclu.dll  2001.12.10530.16384  Microsoft Distributed Transaction Coordinator Failover Clustering Support DLL
mtxdm.dll  2001.12.10530.16384  COM+
mtxex.dll  2001.12.10530.16384  COM+
mtxlegih.dll  2001.12.10530.16384  COM+
mtxoci.dll  2001.12.10530.16384  Microsoft Distributed Transaction Coordinator Database Support DLL for Oracle
muifontsetup.dll  6.3.9600.16384  MUI Callback for font registry settings
muilanguagecleanup.dll  6.3.9600.16384  MUI Callback for Language pack cleanup
mycomput.dll  6.3.9600.16384  Computer Management
mydocs.dll  6.3.9600.16384  My Documents Folder UI
napcrypt.dll  6.3.9600.16384  NAP Cryptographic API helper
napdsnap.dll  6.3.9600.16384  NAP GPEdit Extension
naphlpr.dll  6.3.9600.16384  NAP client config API helper
napinsp.dll  6.3.9600.16384  E-mail Naming Shim Provider
napipsec.dll  6.3.9600.16384  NAP IPSec Enforcement Client
napmontr.dll  6.3.9600.16384  NAP Netsh Helper
naturallanguage6.dll  6.3.9600.16384  Natural Language Development Platform 6
ncaapi.dll  6.3.9600.16384  Microsoft Network Connectivity Assistant API
ncasvc.dll  6.3.9600.16384  Microsoft Network Connectivity Assistant Service
ncbservice.dll  6.3.9600.16384  Network Connection Broker
ncdautosetup.dll  6.3.9600.16384  Network Connected Devices Auto-Setup service DLL
ncdprop.dll  6.3.9600.16384  Advanced network device properties
nci.dll  6.3.9600.16384  CoInstaller: NET
ncobjapi.dll  6.3.9600.16384  Microsoft® Windows® Operating System
ncrypt.dll  6.3.9600.16384  Windows NCrypt Router
ncryptprov.dll  6.3.9600.16384  Microsoft KSP
ncryptsslp.dll  6.3.9600.16384  Microsoft SChannel Provider
ncuprov.dll  6.3.9600.16384  Network Connectivity Statistics Provider for System Resource Usage Monitor Service
ncsi.dll  6.3.9600.16384  Network Connectivity Status Indicator
nddeapi.dll  6.3.9600.16384  Network DDE Share Management APIs
ndfapi.dll  6.3.9600.16384  Network Diagnostic Framework Client API
ndfetw.dll  6.3.9600.16384  Network Diagnostic Engine Event Interface
ndfhcdiscovery.dll  6.3.9600.16384  Network Diagnostic Framework HC Discovery API
ndiscapcfg.dll  6.3.9600.16384  NdisCap Notify Object
ndishc.dll  6.3.9600.16384  NDIS Helper Classes
ndisimplatform.dll  6.3.9600.16384  Ndis IM Platform MUX Notify Object
ndproxystub.dll  6.3.9600.16384  Network Diagnostic Engine Proxy/Stub
nduprov.dll  6.3.9600.16384  Network Statistics Provider for System Resource Usage Monitor Service
negoexts.dll  6.3.9600.16384  NegoExtender Security Package
netapi.dll  3.10.0.103  Windows Win16 Application Launcher
netapi32.dll  6.3.9600.16384  Net Win32 API DLL
netbios.dll  6.3.9600.16384  NetBIOS Interface Library
netcenter.dll  6.3.9600.16384  Network Center control panel
netcfgx.dll  6.3.9600.16384  Network Configuration Objects
netcorehc.dll  6.3.9600.16384  Networking Core Diagnostics Helper Classes
netdiagfx.dll  6.3.9600.16384  Network Diagnostic Framework
netevent.dll  6.3.9600.16384  Net Event Handler
netfxperf.dll  6.3.9600.16384  Extensible Performance Counter Shim
neth.dll  6.3.9600.16384  Net Help Messages DLL
netid.dll  6.3.9600.16384  System Control Panel Applet; Network ID Page
netiohlp.dll  6.3.9600.16384  Netio Helper DLL
netjoin.dll  6.3.9600.16384  Domain Join DLL
netlogon.dll  6.3.9600.16384  Net Logon Services DLL
netman.dll  6.3.9600.16384  Network Connections Manager
netmsg.dll  6.3.9600.16384  Net Messages DLL
netplwiz.dll  6.3.9600.16384  Map Network Drives/Network Places Wizard
netprofm.dll  6.3.9600.16384  Network List Manager
netprofmsvc.dll  6.3.9600.16384  Network List Manager
netprovisionsp.dll  6.3.9600.16384  Provisioning Service Provider DLL
netsetupapi.dll  6.3.9600.16384  Network Configuration API
netshell.dll  6.3.9600.16384  Network Connections Shell
nettrace.dll  6.3.9600.16384  Network Trace Helper
netutils.dll  6.3.9600.16384  Net Win32 API Helpers DLL
netvsccoinstall.dll  6.3.9600.16384  NetVsc Protocol Driver Coinstaller
netvscres.dll  6.3.9600.16384  Virtual Machine NDIS Miniport Resource DLL
networkexplorer.dll  6.3.9600.16384  Network Explorer
networkitemfactory.dll  6.3.9600.16384  NetworkItem Factory
networkstatus.dll  6.3.9600.16384  Network Status Interface
newdev.dll  6.0.5054.0  Add Hardware Device Library
ninput.dll  6.3.9600.16384  Microsoft Pen and Touch Input Component
nl7data0011.dll  6.3.9600.16384  Microsoft Japanese Natural Language Data and Code
nl7data001e.dll  6.3.9600.16384  Microsoft Thai Natural Language Data and Code
nl7data0404.dll  6.3.9600.16384  Microsoft Chinese Traditional Natural Language Data and Code
nl7data0804.dll  6.3.9600.16384  Microsoft Chinese Simplified Natural Language Data and Code
nl7lexicons0011.dll  6.3.9600.16384  Microsoft Japanese Natural Language Data
nl7lexicons001e.dll  6.3.9600.16384  Microsoft Thai Natural Language Data
nl7lexicons0404.dll  6.3.9600.16384  Microsoft Chinese Traditional Natural Language Data
nl7lexicons0804.dll  6.3.9600.16384  Microsoft Chinese Simplified Natural Language Data
nl7models0011.dll  6.3.9600.16384  Microsoft Japanese Natural Language Data
nl7models001e.dll  6.3.9600.16384  Microsoft Thai Natural Language Data
nl7models0404.dll  6.3.9600.16384  Microsoft Chinese Traditional Natural Language Data
nl7models0804.dll  6.3.9600.16384  Microsoft Chinese Simplified Natural Language Data
nlaapi.dll  6.3.9600.16384  Network Location Awareness 2
nlahc.dll  6.3.9600.16384  NLA Helper Classes
nlasvc.dll  6.3.9600.16384  Network Location Awareness 2
nlhtml.dll  2008.0.9600.16384  HTML filter
nlmgp.dll  6.3.9600.16384  Network List Manager Snapin
nlmproxy.dll  6.3.9600.16384  Network List Manager Public Proxy
nlmsprep.dll  6.3.9600.16384  Network List Manager Sysprep Module
nlsbres.dll  6.3.9600.16384  NLSBuild resource DLL
nlsdata0000.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0002.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0003.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0007.dll  6.3.9600.16384  Microsoft German Natural Language Server Data and Code
nlsdata0009.dll  6.3.9600.16384  Microsoft English Natural Language Server Data and Code
nlsdata000a.dll  6.3.9600.16384  Microsoft Spanish Natural Language Server Data and Code
nlsdata000c.dll  6.3.9600.16384  Microsoft French Natural Language Server Data and Code
nlsdata000d.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata000f.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0010.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0018.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata001a.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata001b.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata001d.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0020.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0021.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0022.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0024.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0026.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0027.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata002a.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0039.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata003e.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0045.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0046.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0047.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0049.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata004a.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata004b.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata004c.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata004e.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0414.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0416.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0816.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata081a.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdata0c1a.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlsdl.dll  6.3.9600.16384  Nls Downlevel DLL
nlslexicons0002.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0003.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0007.dll  6.3.9600.16384  Microsoft German Natural Language Server Data and Code
nlslexicons0009.dll  6.3.9600.16384  Microsoft English Natural Language Server Data and Code
nlslexicons000a.dll  6.3.9600.16384  Microsoft Spanish Natural Language Server Data and Code
nlslexicons000c.dll  6.3.9600.16384  Microsoft French Natural Language Server Data and Code
nlslexicons000d.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons000f.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0010.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0018.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons001a.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons001b.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons001d.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0020.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0021.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0022.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0024.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0026.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0027.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons002a.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0039.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons003e.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0045.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0046.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0047.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0049.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons004a.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons004b.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons004c.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons004e.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0414.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0416.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0816.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons081a.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
nlslexicons0c1a.dll  6.3.9600.16384  Microsoft Neutral Natural Language Server Data and Code
normaliz.dll  6.3.9600.16384  Unicode Normalization DLL
npmproxy.dll  6.3.9600.16384  Network List Manager Proxy
nrpsrv.dll  6.3.9600.16384  Name Resolution Proxy (NRP) RPC interface
nshhttp.dll  6.3.9600.16384  HTTP netsh DLL
nshipsec.dll  6.3.9600.16384  Net Shell IP Security helper DLL
nshwfp.dll  6.3.9600.16384  Windows Filtering Platform Netsh Helper
nsi.dll  6.3.9600.16384  NSI User-mode interface DLL
nsisvc.dll  6.3.9600.16384  Network Store Interface RPC server
ntasn1.dll  6.3.9600.16384  Microsoft ASN.1 API
ntdll.dll  6.3.9600.16384  NT Layer DLL
ntdsapi.dll  6.3.9600.16384  Active Directory Domain Services API
ntlanman.dll  6.3.9600.16384  Microsoft® Lan Manager
ntlanui2.dll  6.3.9600.16384  Network object shell UI
ntmarta.dll  6.3.9600.16384  Windows NT MARTA provider
ntprint.dll  6.3.9600.16384  Spooler Setup DLL
ntshrui.dll  6.3.9600.16384  Shell extensions for sharing
ntvdmcpl.dll  6.3.9600.16384  Windows 16-Bit Emulation Control Panel
ntvdmd.dll  3.10.0.103  Windows Win16 Application Launcher
objsel.dll  6.3.9600.16384  Object Picker Dialog
occache.dll  11.0.9600.16384  Object Control Viewer
ocsetapi.dll  6.3.9600.16384  Windows Optional Component Setup API
odbc16gt.dll  3.510.3711.0  Microsoft ODBC Driver Generic Thunk
odbc32.dll  6.3.9600.16384  ODBC Driver Manager
odbc32gt.dll  6.3.9600.16384  ODBC Driver Generic Thunk
odbcbcp.dll  6.3.9600.16384  BCP for ODBC
odbcconf.dll  6.3.9600.16384  ODBC Driver Configuration Program
odbccp32.dll  6.3.9600.16384  ODBC Installer
odbccr32.dll  6.3.9600.16384  ODBC Cursor Library
odbccu32.dll  6.3.9600.16384  ODBC Cursor Library
odbcint.dll  6.3.9600.16384  ODBC Resources
odbcji32.dll  6.3.9600.16384  Microsoft ODBC Desktop Driver Pack 3.5
odbcjt32.dll  6.3.9600.16384  Microsoft ODBC Desktop Driver Pack 3.5
odbctrac.dll  6.3.9600.16384  ODBC Driver Manager Trace
oddbse32.dll  6.3.9600.16384  ODBC (3.0) driver for DBase
odexl32.dll  6.3.9600.16384  ODBC (3.0) driver for Excel
odfox32.dll  6.3.9600.16384  ODBC (3.0) driver for FoxPro
odpdx32.dll  6.3.9600.16384  ODBC (3.0) driver for Paradox
odtext32.dll  6.3.9600.16384  ODBC (3.0) driver for text files
oemlicense.dll    
offfilt.dll  2008.0.9600.16384  OFFICE Filter
offreg.dll  6.3.9600.16384  Offline registry DLL
ogldrv.dll  6.3.9600.16384  MSOGL
ole2.dll  3.10.0.103  Windows Win16 Application Launcher
ole2disp.dll  3.10.0.103  Windows Win16 Application Launcher
ole2nls.dll  3.10.0.103  Windows Win16 Application Launcher
ole32.dll  6.3.9600.16384  Microsoft OLE for Windows
oleacc.dll  7.2.9600.16384  Active Accessibility Core Component
oleacchooks.dll  7.2.9600.16384  Active Accessibility Event Hooks Library
oleaccrc.dll  7.2.9600.16384  Active Accessibility Resource DLL
oleaut32.dll  6.3.9600.16384  
olecli.dll  3.10.0.103  Windows Win16 Application Launcher
olecli32.dll  6.3.9600.16384  Object Linking and Embedding Client Library
oledb32.dll  6.3.9600.16384  OLE DB Core Services
oledb32r.dll  6.3.9600.16384  OLE DB Core Services Resources
oledlg.dll  6.3.9600.16384  OLE User Interface Support
oleprn.dll  6.3.9600.16384  Oleprn DLL
olepro32.dll  6.3.9600.16384  
olesvr.dll  3.10.0.103  Windows Win16 Application Launcher
olesvr32.dll  6.3.9600.16384  Object Linking and Embedding Server Library
olethk32.dll  6.3.9600.16384  Microsoft OLE for Windows
ondemandconnroutehelper.dll  6.3.9600.16384  On Demand Connctiond Route Helper
onex.dll  6.3.9600.16384  IEEE 802.1X supplicant library
onexui.dll  6.3.9600.16384  IEEE 802.1X supplicant UI library
oobefldr.dll  6.3.9600.16384  Getting Started
opcservices.dll  6.3.9600.16384  Native Code OPC Services Library
opencl.dll  1.2.11.0  OpenCL Client DLL
opengl32.dll  6.3.9600.16384  OpenGL Client DLL
osbaseln.dll  6.3.9600.16384  Service Reporting API
osksupport.dll  6.3.9600.16384  Microsoft On-Screen Keyboard Support Utilities
osuninst.dll  6.3.9600.16384  Uninstall Interface
p2p.dll  6.3.9600.16384  Peer-to-Peer Grouping
p2pgraph.dll  6.3.9600.16384  Peer-to-Peer Graphing
p2pnetsh.dll  6.3.9600.16384  Peer-to-Peer NetSh Helper
p2psvc.dll  6.3.9600.16384  Peer-to-Peer Services
packager.dll  6.3.9600.16384  Object Packager2
packagestateroaming.dll  6.3.9600.16384  Package State Roaming
panmap.dll  6.3.9600.16384  PANOSE(tm) Font Mapper
pautoenr.dll  6.3.9600.16384  Auto Enrollment DLL
pcacli.dll  6.3.9600.16384  Program Compatibility Assistant Client Module
pcadm.dll  6.3.9600.16384  Program Compatibility Assistant Diagnostic Module
pcaevts.dll  6.3.9600.16384  Program Compatibility Assistant Event Resources
pcasvc.dll  6.3.9600.16384  Program Compatibility Assistant Service
pcaui.dll  6.3.9600.16384  Program Compatibility Assistant User Interface Module
pcpksp.dll  6.3.9600.16384  Microsoft Platform Key Storage Provider for Platform Crypto Provider
pcptpm12.dll  6.3.9600.16384  Microsoft Platform Crypto Provider for Trusted Platform Module 1.2
pcwum.dll  6.3.9600.16384  Performance Counters for Windows Native DLL
pcwutl.dll  6.3.9600.16384  Program Compatibility Troubleshooter Helper
pcsvdevice.dll  6.3.9600.16384  PCSV Proxy Provider for devices
pdh.dll  6.3.9600.16384  Windows Performance Data Helper DLL
pdhui.dll  6.3.9600.16384  PDH UI
perfctrs.dll  6.3.9600.16384  Performance Counters
perfdisk.dll  6.3.9600.16384  Windows Disk Performance Objects DLL
perfnet.dll  6.3.9600.16384  Windows Network Service Performance Objects DLL
perfos.dll  6.3.9600.16384  Windows System Performance Objects DLL
perfproc.dll  6.3.9600.16384  Windows System Process Performance Objects DLL
perftrack.dll  6.3.9600.16384  Microsoft Performance PerfTrack
perfts.dll  6.3.9600.16384  Windows Remote Desktop Services Performance Objects
photometadatahandler.dll  6.3.9600.16384  Photo Metadata Handler
photowiz.dll  6.3.9600.16384  Photo Printing Wizard
pid.dll  6.3.9600.16384  Microsoft PID
pidgenx.dll  6.3.9600.16384  Pid Generation
pifmgr.dll  6.3.9600.16384  Windows NT PIF Manager Icon Resources Library
pku2u.dll  6.3.9600.16384  Pku2u Security Package
pla.dll  6.3.9600.16384  Performance Logs & Alerts
playlistfolder.dll  6.3.9600.16384  Playlist Folder
playsndsrv.dll  6.3.9600.16384  PlaySound Service
playtodevice.dll  12.0.9600.16384  PLAYTODEVICE DLL
playtomanager.dll  6.3.9600.16384  Microsoft Windows PlayTo Manager
playtostatusprovider.dll  6.3.9600.16384  PlayTo Status Provider Dll
ploptin.dll  6.3.9600.16384  Prelaunch OptIn
pmspl.dll  3.10.0.103  Windows Win16 Application Launcher
pngfilt.dll  11.0.9600.16384  IE PNG plugin image decoder
pnidui.dll  6.3.9600.16384  Network System Icon
pnpclean.dll  6.3.9600.16384  Plug and Play Maintenance Task Library
pnppolicy.dll  6.3.9600.16384  pnppolicy Task
pnpts.dll  6.3.9600.16384  PlugPlay Troubleshooter
pnpui.dll  5.2.3668.0  Plug and Play User Interface DLL
pnpxassoc.dll  6.3.9600.16384  PNPX Association Dll
pnpxassocprx.dll  6.3.9600.16384  PNPX Association Dll
pnrpauto.dll  6.3.9600.16384  PNRP Auto Service Dll
pnrphc.dll  6.3.9600.16384  PNRP Helper Class
pnrpnsp.dll  6.3.9600.16384  PNRP Name Space Provider
pnrpsvc.dll  6.3.9600.16384  PNRP Service Dll
polstore.dll  6.3.9600.16384  Policy Storage dll
portabledeviceapi.dll  6.3.9600.16384  Windows Portable Device API Components
portabledeviceclassextension.dll  6.3.9600.16384  Windows Portable Device Class Extension Component
portabledeviceconnectapi.dll  6.3.9600.16384  Portable Device Connection API Components
portabledevicestatus.dll  6.3.9600.16384  Microsoft Windows Portable Device Status Provider
portabledevicesyncprovider.dll  6.3.9600.16384  Microsoft Windows Portable Device Provider.
portabledevicetypes.dll  6.3.9600.16384  Windows Portable Device (Parameter) Types Component
portabledevicewiacompat.dll  6.3.9600.16384  PortableDevice WIA Compatibility Driver
portabledevicewmdrm.dll  6.3.9600.16384  Windows Portable Device WMDRM Component
pots.dll  6.3.9600.16384  Power Troubleshooter
powercpl.dll  6.3.9600.16384  Power Options Control Panel
powerwmiprovider.dll  6.3.9600.16384  Power WMI providers
powrprof.dll  6.3.9600.16384  Power Profile Helper DLL
presentationcffrasterizernative_v0300.dll  3.0.6920.7903  WinFX OpenType/CFF Rasterizer
presentationhostproxy.dll  6.3.9600.16384  Windows Presentation Foundation Host Proxy
presentationnative_v0300.dll  3.0.6920.7903  PresentationNative_v0300.dll
prflbmsg.dll  6.3.9600.16384  Perflib Event Messages
printdialogs.dll  6.3.9600.16384  Microsoft® Windows® Operating System
printfilterpipelineprxy.dll  6.3.9600.16384  Print Filter Pipeline Proxy
printisolationproxy.dll  6.3.9600.16384  Print Sandbox COM Proxy Stub
printui.dll  6.3.9600.16384  Printer Settings User Interface
prm0001.dll  6.3.9600.16384  Microsoft Arabic Natural Language Data and Code
prm0005.dll  6.3.9600.16384  Microsoft Czech Natural Language Data and Code
prm0006.dll  6.3.9600.16384  Microsoft Danish Natural Language Data and Code
prm0007.dll  6.3.9600.16384  Microsoft German Natural Language Data and Code
prm0008.dll  6.3.9600.16384  Microsoft Greek Natural Language Data and Code
prm0009.dll  6.3.9600.16384  Microsoft English Natural Language Data and Code
prm000b.dll  6.3.9600.16384  Microsoft Finnish Natural Language Data and Code
prm000e.dll  6.3.9600.16384  Microsoft Hungarian Natural Language Data and Code
prm0013.dll  6.3.9600.16384  Microsoft Dutch Natural Language Data and Code
prm0015.dll  6.3.9600.16384  Microsoft Polish Natural Language Data and Code
prm0019.dll  6.3.9600.16384  Microsoft Russian Natural Language Data and Code
prm001f.dll  6.3.9600.16384  Microsoft Turkish Natural Language Data and Code
prncache.dll  6.3.9600.16384  Print UI Cache
prnfldr.dll  6.3.9600.16384  prnfldr dll
prnntfy.dll  6.3.9600.16384  prnntfy DLL
prntvpt.dll  6.3.9600.16384  Print Ticket Services Module
procinst.dll  6.3.9600.16384  Processor Class Installer
profapi.dll  6.3.9600.16384  User Profile Basic API
profext.dll  6.3.9600.16384  profext
profprov.dll  6.3.9600.16384  User Profile WMI Provider
profsvc.dll  6.3.9600.16384  ProfSvc
profsvcext.dll  6.3.9600.16384  ProfSvcExt
propsys.dll  7.0.9600.16384  Microsoft Property System
provcore.dll  6.3.9600.16384  Microsoft Wireless Provisioning Core
provsvc.dll  6.3.9600.16384  Windows HomeGroup
provthrd.dll  6.3.9600.16384  WMI Provider Thread & Log Library
proximitycommon.dll  6.3.9600.16384  Proximity Common Implementation
proximitycommonpal.dll  6.3.9600.16384  Proximity Common PAL
proximityrtapipal.dll  6.3.9600.16384  Proximity WinRT API PAL
proximityservice.dll  6.3.9600.16384  Proximity Service Implementation
proximityservicepal.dll  6.3.9600.16384  Proximity Service PAL
prvdmofcomp.dll  6.3.9600.16384  WMI
psapi.dll  6.3.9600.16384  Process Status Helper
pshed.dll  6.3.9600.16384  Platform Specific Hardware Error Driver
psisdecd.dll  6.6.9600.16384  Microsoft SI/PSI parser for MPEG2 based networks.
psmodulediscoveryprovider.dll  6.3.9600.16384  WMI
psmsrv.dll  6.3.9600.16384  Process State Manager (PSM) Service
pstask.dll  6.3.9600.16384  pstask Task
pstorec.dll  6.3.9600.16384  Deprecated Protected Storage COM interfaces
puiapi.dll  6.3.9600.16384  puiapi DLL
puiobj.dll  6.3.9600.16384  PrintUI Objects DLL
purchasewindowslicense.dll  6.3.9600.16384  Purchase Windows License
pwlauncher.dll  6.3.9600.16384  Windows To Go Launcher
pwrshplugin.dll  6.3.9600.16384  pwrshplugin.dll
pwsso.dll  6.3.9600.16384  Windows To Go Shell Service Object
qagent.dll  6.3.9600.16384  Quarantine Agent Proxy
qagentrt.dll  6.3.9600.16384  Quarantine Agent Service Run-Time
qasf.dll  12.0.9600.16384  DirectShow ASF Support
qcap.dll  6.6.9600.16384  DirectShow Runtime.
qcliprov.dll  6.3.9600.16384  Quarantine Client WMI Provider
qdv.dll  6.6.9600.16384  DirectShow Runtime.
qdvd.dll  6.6.9600.16384  DirectShow DVD PlayBack Runtime.
qedit.dll  6.6.9600.16384  DirectShow Editing.
qedwipes.dll  6.6.9600.16384  DirectShow Editing SMPTE Wipes
qmgr.dll  7.7.9600.16384  Background Intelligent Transfer Service
qmgrprxy.dll  7.7.9600.16384  Background Intelligent Transfer Service Proxy
qshvhost.dll  6.3.9600.16384  Quarantine SHV Host
qsvrmgmt.dll  6.3.9600.16384  Quarantine Server Management
quartz.dll  6.6.9600.16384  DirectShow Runtime.
query.dll  6.3.9600.16384  Content Index Utility DLL
qutil.dll  6.3.9600.16384  Quarantine Utilities
qwave.dll  6.3.9600.16384  Windows NT
racengn.dll  6.3.9600.16384  Reliability analysis metrics calculation engine
racpldlg.dll  6.3.9600.16384  Remote Assistance Contact List
radardt.dll  6.3.9600.16384  Microsoft Windows Resource Exhaustion Detector
radarrs.dll  6.3.9600.16384  Microsoft Windows Resource Exhaustion Resolver
radcui.dll  6.3.9600.16384  RemoteApp and Desktop Connection UI Component
rasadhlp.dll  6.3.9600.16384  Remote Access AutoDial Helper
rasapi32.dll  6.3.9600.16384  Remote Access API
rasauto.dll  6.3.9600.16384  Remote Access AutoDial Manager
rascfg.dll  6.3.9600.16384  RAS Configuration Objects
raschap.dll  6.3.9600.16384  Remote Access PPP CHAP
raschapext.dll  6.3.9600.16384  Windows Extension library for raschap
rasctrs.dll  6.3.9600.16384  Windows NT Remote Access Perfmon Counter dll
rascustom.dll  6.3.9600.16384  Custom Protocol Engine
rasdiag.dll  6.3.9600.16384  RAS Diagnostics Helper Classes
rasdlg.dll  6.3.9600.16384  Remote Access Common Dialog API
rasgcw.dll  6.3.9600.16384  RAS Wizard Pages
rasman.dll  6.3.9600.16384  Remote Access Connection Manager
rasmans.dll  6.3.9600.16384  Remote Access Connection Manager
rasmbmgr.dll  6.3.9600.16384  Provides support for the switching of mobility enabled VPN connections if their underlying interface goes down.
rasmm.dll  6.3.9600.16384  RAS Media Manager
rasmontr.dll  6.3.9600.16384  RAS Monitor DLL
rasmxs.dll  6.3.9600.16384  Remote Access Device DLL for modems, PADs and switches
rasplap.dll  6.3.9600.16384  RAS PLAP Credential Provider
rasppp.dll  6.3.9600.16384  Remote Access PPP
rasser.dll  6.3.9600.16384  Remote Access Media DLL for COM ports
rastapi.dll  6.3.9600.16384  Remote Access TAPI Compliance Layer
rastls.dll  6.3.9600.16384  Remote Access PPP EAP-TLS
rastlsext.dll  6.3.9600.16384  Windows Extension library for rastls
rdbui.dll  6.3.9600.16384  ReadyBoost UI
rdpcfgex.dll  6.3.9600.16384  Remote Desktop Session Host Server Connection Configuration Extension for the RDP protocol
rdpcore.dll  6.3.9600.16384  RDP Core DLL
rdpcorets.dll  6.3.9600.16384  TS RDPCore DLL
rdpencom.dll  6.3.9600.16384  RDPSRAPI COM Objects
rdpendp.dll  6.3.9600.16384  RDP Audio Endpoint
rdpsaps.dll  6.3.9600.16384  RDP Session Agent Proxy Stub
rdpudd.dll  6.3.9600.16384  UMRDP Display Driver
rdsappxhelper.dll  6.3.9600.16384  Remote Desktop AppX Scheduler Helper DLL
rdsdwmdr.dll  6.3.9600.16384  Microsoft Remote Desktop Services Desktop Composition Component
rdvidcrl.dll  6.3.9600.16384  Remote Desktop Services Client for Microsoft Online Services
rdvvmtransport.dll  6.3.9600.16384  RdvVmTransport EndPoints
reagent.dll  6.3.9600.16384  Microsoft Windows Recovery Agent DLL
reagenttask.dll  6.3.9600.16384  Microsoft Windows Recovery Agent Task Handler
recovery.dll  6.3.9600.16384  Recovery Control Panel
regapi.dll  6.3.9600.16384  Registry Configuration APIs
regctrl.dll  6.3.9600.16384  RegCtrl
regidle.dll  6.3.9600.16384  RegIdle Backup Task
regsvc.dll  6.3.9600.16384  Remote Registry Service
reinfo.dll  6.3.9600.16384  Microsoft Windows Recovery Info DLL
remotepg.dll  6.3.9600.16384  Remote Sessions CPL Extension
removedevicecontexthandler.dll  6.3.9600.16384  Devices & Printers Remove Device Context Menu Handler
removedeviceelevated.dll  6.3.9600.16384  RemoveDeviceElevated Proxy Dll
resampledmo.dll  6.3.9600.16384  Windows Media Resampler
reseteng.dll  6.3.9600.16384  Microsoft Windows Reset Engine
resutils.dll  6.3.9600.16384  Microsoft Cluster Resource Utility DLL
rfxvmt.dll  6.3.9600.16384  Microsoft RemoteFX VM Transport
rgb9rast.dll  6.3.9600.16384  Microsoft® Windows® Operating System
riched20.dll  5.31.23.1230  Rich Text Edit Control, v3.1
riched32.dll  6.3.9600.16384  Wrapper Dll for Richedit 1.0
rmapi.dll  6.3.9600.16384  Radio Manager API
rnr20.dll  6.3.9600.16384  Windows Socket2 NameSpace DLL
roamingsecurity.dll  6.3.9600.16384  Roaming Security implementation
rometadata.dll  4.0.20806.33440  Microsoft MetaData Library
rotmgr.dll  6.3.9600.16384  Auto-Rotation Manager
rpcepmap.dll  6.3.9600.16384  RPC Endpoint Mapper
rpchttp.dll  6.3.9600.16384  RPC HTTP DLL
rpcns4.dll  6.3.9600.16384  Remote Procedure Call Name Service Client
rpcnsh.dll  6.3.9600.16384  RPC Netshell Helper
rpcrt4.dll  6.3.9600.16384  Remote Procedure Call Runtime
rpcrtremote.dll  6.3.9600.16384  Remote RPC Extension
rpcss.dll  6.3.9600.16384  Distributed COM Services
rsaenh.dll  6.3.9600.16384  Microsoft Enhanced Cryptographic Provider
rshx32.dll  6.3.9600.16384  Security Shell Extension
rstrtmgr.dll  6.3.9600.16384  Restart Manager
rtffilt.dll  2008.0.9600.16384  RTF Filter
rtm.dll  6.3.9600.16384  Routing Table Manager
rtutils.dll  6.3.9600.16384  Routing Utilities
rtworkq.dll  12.0.9600.16384  Realtime WorkQueue DLL
samcli.dll  6.3.9600.16384  Security Accounts Manager Client DLL
samlib.dll  6.3.9600.16384  SAM Library DLL
samsrv.dll  6.3.9600.16384  SAM Server DLL
sas.dll  6.3.9600.16384  WinLogon Software SAS Library
sbe.dll  6.6.9600.16384  DirectShow Stream Buffer Filter.
sbeio.dll  12.0.9600.16384  Stream Buffer IO DLL
sberes.dll  6.6.9600.16384  DirectShow Stream Buffer Filter Resouces.
scansetting.dll  6.3.9600.16384  Microsoft® Windows(TM) ScanSettings Profile and Scanning implementation
scarddlg.dll  6.3.9600.16384  SCardDlg - Smart Card Common Dialog
scardsvr.dll  6.3.9600.16384  Smart Card Resource Management Server
scavengeui.dll  6.3.9600.16384  Update Package Cleanup
sccls.dll  6.3.9600.16384  Class-Installer DLL for Smart Cards
scdeviceenum.dll  6.3.9600.16384  Smart Card Device Enumeration Service
scecli.dll  6.3.9600.16384  Windows Security Configuration Editor Client Engine
scesrv.dll  6.3.9600.16384  Windows Security Configuration Editor Engine
scext.dll  6.3.9600.16384  Service Control Manager Extension DLL for non-minwin
schannel.dll  6.3.9600.16384  TLS / SSL Security Provider
schedcli.dll  6.3.9600.16384  Scheduler Service Client DLL
schedsvc.dll  6.3.9600.16384  Task Scheduler Service
scksp.dll  6.3.9600.16384  Microsoft Smart Card Key Storage Provider
scripto.dll  6.6.9600.16384  Microsoft ScriptO
scrobj.dll  5.8.9600.16384  Windows ® Script Component Runtime
scrrun.dll  5.8.9600.16384  Microsoft ® Script Runtime
sdhcinst.dll  6.3.9600.16384  Secure Digital Host Controller Class Installer
sdiageng.dll  6.3.9600.16384  Scripted Diagnostics Execution Engine
sdiagprv.dll  6.3.9600.16384  Windows Scripted Diagnostic Provider API
sdiagschd.dll  6.3.9600.16384  Scripted Diagnostics Scheduled Task
sdohlp.dll  6.3.9600.16384  NPS SDO Helper Component
searchfolder.dll  6.3.9600.16384  SearchFolder
sechost.dll  6.3.9600.16384  Host for SCM/SDDL/LSA Lookup APIs
seclogon.dll  6.3.9600.16384  Secondary Logon Service DLL
secproc.dll  6.3.9600.16384  Windows Rights Management Desktop Security Processor
secproc_isv.dll  6.3.9600.16384  Windows Rights Management Desktop Security Processor
secproc_ssp.dll  6.3.9600.16384  Windows Rights Management Services Server Security Processor
secproc_ssp_isv.dll  6.3.9600.16384  Windows Rights Management Services Server Security Processor (Pre-production)
secur32.dll  6.3.9600.16384  Security Support Provider Interface
security.dll  6.3.9600.16384  Security Support Provider Interface
sendmail.dll  6.3.9600.16384  Send Mail
sens.dll  6.3.9600.16384  System Event Notification Service (SENS)
sensapi.dll  6.3.9600.16384  SENS Connectivity API DLL
sensorperformanceevents.dll  6.3.9600.16384  Sensors Performance Events
sensorsapi.dll  6.3.9600.16384  Sensor API
sensorsclassextension.dll  6.3.9600.16384  Sensor Driver Class Extension component
sensorscpl.dll  6.3.9600.16384  Open Location and Other Sensors
sensrsvc.dll  6.3.9600.16384  Microsoft Windows Sensor Monitoring Service
serialui.dll  6.3.9600.16384  Serial Port Property Pages
serwvdrv.dll  6.3.9600.16384  Unimodem Serial Wave driver
sessenv.dll  6.3.9600.16384  Remote Desktop Configuration service
setbcdlocale.dll  6.3.9600.16384  MUI Callback for Bcd
setnetworklocation.dll  6.3.9600.16384  Set Network Location Utility
setproxycredential.dll  6.3.9600.16384  Set Proxy Credential Utility
settingmonitor.dll  6.3.9600.16384  Setting Synchronization Change Monitor
settingshandlers.dll  6.3.9600.16384  System Settings Handlers Implementation
settingsync.dll  6.3.9600.16384  Setting Synchronization
settingsynccore.dll  6.3.9600.16384  Setting Synchronization Core
settingsyncpolicy.dll  6.3.9600.16384  SettingSync Policy
setupapi.dll  6.3.9600.16384  Windows Setup API
setupcln.dll  6.3.9600.16384  Setup Files Cleanup
setupetw.dll  6.3.9600.16384  Setup ETW Event Resources
sfc.dll  6.3.9600.16384  Windows File Protection
sfc_os.dll  6.3.9600.16384  Windows File Protection
shacct.dll  6.3.9600.16384  Shell Accounts Classes
sharemediacpl.dll  6.3.9600.16384  Share Media Control Panel
shcore.dll  6.3.9600.16384  SHCORE
shdocvw.dll  6.3.9600.16384  Shell Doc Object and Control Library
shell.dll  3.10.0.103  Windows Win16 Application Launcher
shell32.dll  6.3.9600.16384  Windows Shell Common Dll
shellstyle.dll  6.3.9600.16384  Windows Shell Style Resource Dll
shfolder.dll  6.3.9600.16384  Shell Folder Service
shgina.dll  6.3.9600.16384  Windows Shell User Logon
shimeng.dll  6.3.9600.16384  Shim Engine DLL
shimgvw.dll  6.3.9600.16384  Photo Gallery Viewer
shlwapi.dll  6.3.9600.16384  Shell Light-weight Utility Library
shpafact.dll  6.3.9600.16384  Windows Shell LUA/PA Elevation Factory Dll
shsetup.dll  6.3.9600.16384  Shell setup helper
shsvcs.dll  6.3.9600.16384  Windows Shell Services Dll
shunimpl.dll  6.3.9600.16384  Windows Shell Obsolete APIs
shwebsvc.dll  6.3.9600.16384  Windows Shell Web Services
signdrv.dll  6.3.9600.16384  WMI provider for Signed Drivers
simauth.dll  6.3.9600.16384  EAP SIM run-time dll
simcfg.dll  6.3.9600.16384  EAP SIM config dll
sisbkup.dll  6.3.9600.16384  Single-Instance Store Backup Support Functions
skydriveshell.dll  6.3.9600.16384  Microsoft SkyDrive Shell Extension
skydrivetelemetry.dll  6.3.9600.16384  Telemetry Library for the SkyDrive client
slc.dll  6.3.9600.16384  Software Licensing Client Dll
slcext.dll  6.3.9600.16384  Software Licensing Client Extension Dll
slpts.dll  6.3.9600.16384  Sleep Study Troubleshooter
slr100.dll  4.0.353.3432  System Language Runtime
slwga.dll  6.3.9600.16384  Software Licensing WGA API
smartcardcredentialprovider.dll  6.3.9600.16384  Windows Smartcard Credential Provider
smartcardsimulator.dll  6.3.9600.16384  Microsoft Smart Card Simulator Transport
smbhelperclass.dll  1.0.0.1  SMB (File Sharing) Helper Class for Network Diagnostic Framework
smbwmiv2.dll  6.3.9600.16384  WMIv2 Provider for SMB File Server/Client
smiengine.dll  6.3.9600.16384  WMI Configuration Core
smphost.dll  6.3.9600.16384  Storage Management Provider (SMP) host service
smsdeviceaccessrevocation.dll  6.3.9600.16384  Sms Device Access Revocation Handler
smsrouter.dll  6.3.9600.16384  Mobile Broadband SMS Router
sndvolsso.dll  6.3.9600.16384  SCA Volume
snmpapi.dll  6.3.9600.16384  SNMP Utility Library
sntsearch.dll  6.3.9600.16384  Sticky Notes Search DLL
softkbd.dll  6.3.9600.16384  Soft Keyboard Server and Tip
softpub.dll  6.3.9600.16384  Softpub Forwarder DLL
sortserver2003compat.dll  6.3.9600.16384  Sort Version Server 2003
sortwindows61.dll  6.3.9600.16384  SortWindows61 Dll
sortwindows6compat.dll  6.3.9600.16384  Sort Version Windows 6.0
spacecontrol.dll  6.3.9600.16384  Storage Spaces control panel
spbcd.dll  6.3.9600.16384  BCD Sysprep Plugin
spfileq.dll  6.3.9600.16384  Windows SPFILEQ
spinf.dll  6.3.9600.16384  Windows SPINF
spmpm.dll  6.3.9600.16384  MountPointManager Sysprep Plugin
spnet.dll  6.3.9600.16384  Net Sysprep Plugin
spoolss.dll  6.3.9600.16384  Spooler SubSystem DLL
spopk.dll  6.3.9600.16384  OPK Sysprep Plugin
spp.dll  6.3.9600.16384  Microsoft® Windows Shared Protection Point Library
sppc.dll  6.3.9600.16384  Software Licensing Client Dll
sppcext.dll  6.3.9600.16384  Software Protection Platform Client Extension Dll
sppcomapi.dll  6.3.9600.16384  Software Licensing Library
sppcommdlg.dll  6.3.9600.16384  Software Licensing UI API
sppinst.dll  6.3.9600.16384  SPP CMI Installer Plug-in DLL
sppnp.dll  6.3.9600.16384  PnP module of SysPrep
sppobjs.dll  6.3.9600.16384  Software Protection Platform Plugins
sppwinob.dll  6.3.9600.16384  Software Protection Platform Windows Plugin
sppwmi.dll  6.3.9600.16384  Software Protection Platform WMI provider
spwinsat.dll  6.3.9600.16384  WinSAT Sysprep Plugin
spwizeng.dll  6.3.9600.16384  Setup Wizard Framework
spwizimg.dll  6.3.9600.16384  Setup Wizard Framework Resources
spwizres.dll  6.3.9600.16384  Setup Wizard Framework Resources
spwmp.dll  6.3.9600.16384  Windows Media Player System Preparation DLL
sqlcecompact40.dll  4.0.8275.1  Database Repair Tool (32-bit)
sqlceoledb40.dll  4.0.9600.1  OLEDB Provider (32-bit)
sqlceqp40.dll  4.0.9600.1  Query Processor (32-bit)
sqlcese40.dll  4.0.9600.1  Storage Engine (32-bit)
sqloledb.dll  6.3.9600.16384  OLE DB Provider for SQL Server
sqlsrv32.dll  6.3.9600.16384  SQL Server ODBC Driver
sqlunirl.dll  2000.80.2039.0  String Function .DLL for SQL Enterprise Components
sqlwid.dll  2000.80.2039.0  Unicode Function .DLL for SQL Enterprise Components
sqlwoa.dll  2000.80.2040.0  Unicode/ANSI Function .DLL for SQL Enterprise Components
sqlxmlx.dll  6.3.9600.16384  XML extensions for SQL Server
sqmapi.dll  6.3.9600.16384  SQM Client
srchadmin.dll  7.0.9600.16384  Indexing Options
srclient.dll  6.3.9600.16384  Microsoft® Windows System Restore Client Library
srcore.dll  6.3.9600.16384  Microsoft® Windows System Restore Core Library
srevents.dll  6.3.9600.16384  SrEvents
srh.dll  6.3.9600.16384  Screen Reader Helper DLL
srhelper.dll  6.3.9600.16384  Microsoft® Windows driver and windows update enumeration library
srrstr.dll  6.3.9600.16384  Microsoft® Windows System Protection Configuration Library
srumapi.dll  6.3.9600.16384  System Resource Usage Monitor API
srumsvc.dll  6.3.9600.16384  System Resource Usage Monitor Service
srvcli.dll  6.3.9600.16384  Server Service Client DLL
srvsvc.dll  6.3.9600.16384  Server Service DLL
srwmi.dll  6.3.9600.16384  Microsoft® Windows System Restore WMI Provider
sscore.dll  6.3.9600.16384  Server Service Core DLL
sscoreext.dll  6.3.9600.16384  Server Service Core DLL
ssdpapi.dll  6.3.9600.16384  SSDP Client API DLL
ssdpsrv.dll  6.3.9600.16384  SSDP Service DLL
sspicli.dll  6.3.9600.16384  Security Support Provider Interface
sspisrv.dll  6.3.9600.16384  LSA SSPI RPC interface DLL
ssshim.dll  6.3.9600.16384  Windows Componentization Platform Servicing API
sstpsvc.dll  6.3.9600.16384  Provides the facility of using Secure Socket Tunneling Protocol (SSTP) to connect to remote computers (using VPN).
startupscan.dll  6.3.9600.16384  Startup scan task DLL
stclient.dll  2001.12.10530.16384  COM+ Configuration Catalog Client
sti.dll  6.3.9600.16384  Still Image Devices client DLL
sti_ci.dll  6.3.9600.16384  Still Image Class Installer
stobject.dll  6.3.9600.16384  Systray shell service object
storage.dll  3.10.0.103  Windows Win16 Application Launcher
storagecontexthandler.dll  6.3.9600.16384  Device Center Storage Context Menu Handler
storagewmi.dll  6.3.9600.16384  WMI Provider for Storage Management
storagewmi_passthru.dll  6.3.9600.16384  WMI PassThru Provider for Storage Management
storewuauth.dll  6.3.9600.16384  Authentication Provider
storprop.dll  6.3.9600.16384  Property Pages for Storage Devices
storsvc.dll  6.3.9600.16384  Storage Services
streamci.dll  6.3.9600.16384  Streaming Device Class Installer
structuredquery.dll  7.0.9600.16384  Structured Query
subscriptionmgr.dll  6.3.9600.16384  Subscription Manager DLL
sud.dll  6.3.9600.16384  SUD Control Panel
svsvc.dll  6.3.9600.16384  Microsoft\Spot Verifier
swprv.dll  6.3.9600.16384  Microsoft® Volume Shadow Copy Service software provider
sxproxy.dll  6.3.9600.16384  Microsoft® Windows System Protection Proxy Library
sxs.dll  6.3.9600.16384  Fusion 2.5
sxshared.dll  6.3.9600.16384  Microsoft® Windows SX Shared Library
sxssrv.dll  6.3.9600.16384  Windows SxS Server DLL
sxsstore.dll  6.3.9600.16384  Sxs Store DLL
synccenter.dll  6.3.9600.16384  Microsoft Sync Center
synceng.dll  6.3.9600.16384  Windows Briefcase Engine
syncengine.dll  6.3.9600.16384  Microsoft SkyDrive Sync Engine
synchostps.dll  6.3.9600.16384  Proxystub for sync host
syncinfrastructure.dll  6.3.9600.16384  Microsoft Windows Sync Infrastructure.
syncinfrastructureps.dll  6.3.9600.16384  Microsoft Windows sync infrastructure proxy stub.
syncreg.dll  2007.94.9600.16384  Microsoft Synchronization Framework Registration
syncui.dll  6.3.9600.16384  Windows Briefcase
sysclass.dll  6.3.9600.16384  System Class Installer Library
sysfxui.dll  6.3.9600.16384  Audio System FX Control Panel Extension
sysmain.dll  6.3.9600.16384  Superfetch Service Host
sysntfy.dll  6.3.9600.16384  Windows Notifications Dynamic Link Library
syssetup.dll  6.3.9600.16384  Windows NT System Setup
systemcpl.dll  6.3.9600.16384  My System CPL
systemeventsbrokerclient.dll  6.3.9600.16384  system Events Broker Client Library
systemeventsbrokerserver.dll  6.3.9600.16384  System Events Broker
systemsettings.deviceencryptionhandlers.dll  6.3.9600.16384  Device Encryption Setting Handlers
systemsettings.handlers.dll  6.3.9600.16384  System settings common handler group
systemsettingsadminflowui.dll  6.3.9600.16384  System Settings Admin Flow XAML UI Implementation
systemsettingsdatabase.dll  6.3.9600.16384  System Settings Database Implementation
t2embed.dll  6.3.9600.16384  Microsoft T2Embed Font Embedding
tabbtn.dll  6.3.9600.16384  Microsoft Tablet PC Buttons Component
tabbtnex.dll  6.3.9600.16384  Microsoft Tablet PC Extended Buttons Component
tabsvc.dll  6.3.9600.16384  Microsoft Touch Keyboard and Handwriting Panel Service
tapi.dll  3.10.0.103  Microsoft® Windows(TM) Telephony Server16
tapi3.dll  6.3.9600.16384  Microsoft TAPI3
tapi32.dll  6.3.9600.16384  Microsoft® Windows(TM) Telephony API Client DLL
tapilua.dll  6.3.9600.16384  Microsoft® Windows(TM) Phone And Modem Lua Elevation Dll
tapimigplugin.dll  6.3.9600.16384  Microsoft® Windows(TM) TAPI Migration Plugin Dll
tapiperf.dll  6.3.9600.16384  Microsoft® Windows(TM) Telephony Performance Monitor
tapisrv.dll  6.3.9600.16384  Microsoft® Windows(TM) Telephony Server
tapisysprep.dll  6.3.9600.16384  Microsoft® Windows(TM) Telephony Sysprep Work
tapiui.dll  6.3.9600.16384  Microsoft® Windows(TM) Telephony API UI DLL
taskbarcpl.dll  6.3.9600.16384  Taskbar Control Panel
taskcomp.dll  6.3.9600.16384  Task Scheduler Backward Compatibility Plug-in
taskschd.dll  6.3.9600.16384  Task Scheduler COM API
taskschdps.dll  6.3.9600.16384  Task Scheduler Interfaces Proxy
tbs.dll  6.3.9600.16384  TBS
tcpipcfg.dll  6.3.9600.16384  Network Configuration Objects
tcpipsetup.dll  6.3.9600.16384  TCPIP Network Setup Plugin
tcpmib.dll  6.3.9600.16384  Standard TCP/IP Port Monitor Helper DLL
tcpmon.dll  6.3.9600.16384  Standard TCP/IP Port Monitor DLL
tcpmonui.dll  6.3.9600.16384  Standard TCP/IP Port Monitor UI DLL
tdh.dll  6.3.9600.16384  Event Trace Helper Library
termmgr.dll  6.3.9600.16384  Microsoft TAPI3 Terminal Manager
termsrv.dll  6.3.9600.16384  Remote Desktop Session Host Server Remote Connections Manager
tetheringieprovider.dll  6.3.9600.16384  Microsoft Windows Tethering IE Provider DLL
tetheringmgr.dll  6.3.9600.16384  Microsoft Windows Tethering Manager DLL
tetheringstation.dll  6.3.9600.16384  Microsoft Windows Tethering Station DLL
themecpl.dll  6.3.9600.16384  Personalization CPL
themeservice.dll  6.3.9600.16384  Windows Shell Theme Service Dll
themeui.dll  6.3.9600.16384  Windows Theme API
threadpoolwinrt.dll  6.3.9600.16384  Windows WinRT Threadpool
thumbcache.dll  6.3.9600.16384  Microsoft Thumbnail Cache
timebrokerclient.dll  6.3.9600.16384  Time Broker Client Library
timebrokerserver.dll  6.3.9600.16384  Time Event Broker
timedatemuicallback.dll  6.3.9600.16384  Time Date Control UI Language Change plugin
timesynctask.dll  6.3.9600.16384  Time Synchronization Task
tlscsp.dll  6.3.9600.16384  Microsoft® Remote Desktop Services Cryptographic Utility
toolhelp.dll  3.10.0.103  Windows Win16 Application Launcher
tpmcompc.dll  6.3.9600.16384  Computer Chooser Dialog
tpmtasks.dll  6.3.9600.16384  TPM Maintenance Tasks
tpmvsc.dll  6.3.9600.16384  Microsoft TPM Virtual Smart Card
tquery.dll  7.0.9600.16384  Microsoft Tripoli Query
traffic.dll  6.3.9600.16384  Microsoft Traffic Control 1.0 DLL
trkwks.dll  6.3.9600.16384  Distributed Link Tracking Client
tsbyuv.dll  6.3.9600.16384  Toshiba Video Codec
tschannel.dll  6.3.9600.16384  Task Scheduler Proxy
tsddd.dll  6.3.9600.16384  Framebuffer Display Driver
tsgqec.dll  6.3.9600.16384  RD Gateway QEC
tsmf.dll  6.3.9600.16384  RDP MF Plugin
tspkg.dll  6.3.9600.16384  Web Service Security Package
tsusbgdcoinstaller.dll  6.3.9600.16384  Remote Desktop Generic USB Driver Coinstaller
tsusbredirectiongrouppolicyextension.dll  6.3.9600.16384  Remote Desktop USB Redirection GP Extension
tsworkspace.dll  6.3.9600.16384  RemoteApp and Desktop Connection Component
ttlsauth.dll  6.3.9600.16384  EAP TTLS run-time dll
ttlscfg.dll  6.3.9600.16384  EAP TTLS configuration dll
ttlsext.dll  6.3.9600.16384  Windows Extension library for EAP TTLS
tvratings.dll  6.6.9600.16384  Module for managing TV ratings
twext.dll  6.3.9600.16384  Previous Versions property page
twinapi.appcore.dll  6.3.9600.16384  twinapi.appcore
twinapi.dll  6.3.9600.16384  twinapi
twinui.appcore.dll  6.3.9600.16384  TWINUI.APPCORE
twinui.dll  6.3.9600.16384  TWINUI
txflog.dll  2001.12.10530.16384  COM+
txfw32.dll  6.3.9600.16384  TxF Win32 DLL
tzres.dll  6.3.9600.16384  Time Zones resource DLL
tzsyncres.dll  6.3.9600.16384  TimeZone Sync Resources DLL
typelib.dll  3.10.0.103  Windows Win16 Application Launcher
ubpm.dll  6.3.9600.16384  Unified Background Process Manager DLL
ucmhc.dll  6.3.9600.16384  UCM Helper Class
udhisapi.dll  6.3.9600.16384  UPnP Device Host ISAPI Extension
udwm.dll  6.3.9600.16384  Microsoft Desktop Window Manager
uexfat.dll  6.3.9600.16384  eXfat Utility DLL
ufat.dll  6.3.9600.16384  FAT Utility DLL
uianimation.dll  6.3.9600.16384  Windows Animation Manager
uiautomationcore.dll  7.2.9600.16384  Microsoft UI Automation Core
uiautomationcoreres.dll  7.2.9600.16384  Microsoft UI Automation Core Resource
uicom.dll  6.3.9600.16384  Add/Remove Modems
uireng.dll  6.3.9600.16384  UI Recording Engine Library
uiribbon.dll  6.3.9600.16384  Windows Ribbon Framework
uiribbonres.dll  6.3.9600.16384  Windows Ribbon Framework Resources
ulib.dll  6.3.9600.16384  File Utilities Support DLL
umb.dll  6.3.9600.16384  User Mode Bus Driver Interface Dll
umdmxfrm.dll  6.3.9600.16384  Unimodem Tranform Module
umpnpmgr.dll  6.3.9600.16384  User-mode Plug-and-Play Service
umpo.dll  6.3.9600.16384  User-mode Power Service
umpoext.dll  6.3.9600.16384  User-mode Power Service Extensions
umpowmi.dll  6.3.9600.16384  User-mode Power Service WMI Providers
umrdp.dll  6.3.9600.16384  Remote Desktop Services Device Redirector Service
unattend.dll  6.3.9600.16384  Unattend Library
unimdmat.dll  6.3.9600.16384  Unimodem Service Provider AT Mini Driver
uniplat.dll  6.3.9600.16384  Unimodem AT Mini Driver Platform Driver for Windows NT
untfs.dll  6.3.9600.16384  NTFS Utility DLL
upnp.dll  6.3.9600.16384  UPnP Control Point API
upnphost.dll  6.3.9600.16384  UPnP Device Host
ureg.dll  6.3.9600.16384  Registry Utility DLL
url.dll  11.0.9600.16384  Internet Shortcut Shell Extension DLL
urlmon.dll  11.0.9600.16384  OLE32 Extensions for Win32
usbceip.dll  6.3.9600.16384  USBCEIP Task
usbmon.dll  6.3.9600.16384  Standard Dynamic Printing Port Monitor DLL
usbperf.dll  6.3.9600.16384  USB Performance Objects DLL
usbui.dll  6.3.9600.16384  USB UI Dll
user32.dll  6.3.9600.16384  Multi-User Windows USER API Client DLL
useraccountcontrolsettings.dll  6.3.9600.16384  UserAccountControlSettings
usercpl.dll  6.3.9600.16384  User control panel
userenv.dll  6.3.9600.16384  Userenv
userinitext.dll  6.3.9600.16384  UserInit Utility Extension DLL
userlanguageprofilecallback.dll  6.3.9600.16384  MUI Callback for User Language profile changed
userlanguagescpl.dll  6.3.9600.16384  My Languages Configuration Control Panel
usp10.dll  6.3.9600.16384  Uniscribe Unicode script processor
ustprov.dll  6.3.9600.16384  User State WMI Provider
utildll.dll  6.3.9600.16384  WinStation utility support DLL
uudf.dll  6.3.9600.16384  UDF Utility DLL
uxinit.dll  6.3.9600.16384  Windows User Experience Session Initialization Dll
uxlib.dll  6.3.9600.16384  Setup Wizard Framework
uxlibres.dll  6.3.9600.16384  UXLib Resources
uxtheme.dll  6.3.9600.16384  Microsoft UxTheme Library
van.dll  6.3.9600.16384  View Available Networks
vault.dll  6.3.9600.16384  Windows vault Control Panel
vaultcli.dll  6.3.9600.16384  Credential Vault Client Library
vaultroaming.dll  1.0.0.1  Vault Roaming
vaultsvc.dll  6.3.9600.16384  Credential Manager Service
vbajet32.dll  6.0.1.9431  Visual Basic for Applications Development Environment - Expression Service Loader
vbscript.dll  5.8.9600.16384  Microsoft ® VBScript
vdmdbg.dll  6.3.9600.16384  VDMDBG.DLL
vdmredir.dll  3.10.0.103  Windows Win16 Application Launcher
vds_ps.dll  6.3.9600.16384  Microsoft® Virtual Disk Service proxy/stub
vdsbas.dll  6.3.9600.16384  Virtual Disk Service Basic Provider
vdsdyn.dll  6.3.9600.16384  VDS Dynamic Volume Provider, Version 2.1.0.1
vdsutil.dll  6.3.9600.16384  Virtual Disk Service Utility Library
vdsvd.dll  6.3.9600.16384  VDS Virtual Disk Provider, Version 1.0
ver.dll  3.10.0.103  Windows Win16 Application Launcher
verifier.dll  6.3.9600.16384  Standard application verifier provider dll
version.dll  6.3.9600.16384  Version Checking and File Installation Libraries
vfwwdm32.dll  6.3.9600.16384  VfW MM Driver for WDM Video Capture Devices
vidreszr.dll  6.3.9600.16384  Windows Media Resizer
virtdisk.dll  6.3.9600.16384  Virtual Disk API DLL
vmapplicationhealthmonitorproxy.dll  6.3.9600.16384  VM Application Health Monitor proxy dll
vmbuspipe.dll  6.3.9600.16384  VmBus User Mode Pipe DLL
vmbusres.dll  6.3.9600.16384  Virtual Machine Bus Resource DLL
vmdcoinstall.dll  6.3.9600.16384  Hyper-V Integration Components Coinstaller
vmicres.dll  6.3.9600.16384  Virtual Machine Integration Component Service Resource DLL
vmictimeprovider.dll  6.3.9600.16384  Virtual Machine Integration Component Time Sync Provider Library
vmrdvcore.dll  6.3.9600.16384  VmRdvCore EndPoints
vmstorfltres.dll  6.3.9600.16384  Virtual Machine Storage Filter Resource DLL
vpnike.dll  6.3.9600.16384  VPNIKE Protocol Engine - Test dll
vpnikeapi.dll  6.3.9600.16384  VPN IKE API's
vscmgrps.dll  6.3.9600.16384  Microsoft Virtual Smart Card Manager Proxy/Stub
vss_ps.dll  6.3.9600.16384  Microsoft® Volume Shadow Copy Service proxy/stub
vssapi.dll  6.3.9600.16384  Microsoft® Volume Shadow Copy Requestor/Writer Services API DLL
vsstrace.dll  6.3.9600.16384  Microsoft® Volume Shadow Copy Service Tracing Library
w32time.dll  6.3.9600.16384  Windows Time Service
w32topl.dll  6.3.9600.16384  Windows NT Topology Maintenance Tool
wab32.dll  6.3.9600.16384  Microsoft (R) Contacts DLL
wab32res.dll  6.3.9600.16384  Microsoft (R) Contacts DLL
wabsyncprovider.dll  6.3.9600.16384  Microsoft Windows Contacts Sync Provider
wavdest.dll  6.3.9600.16384  Windows Sound Recorder
wavemsp.dll  6.3.9600.16384  Microsoft Wave MSP
wbemcomn.dll  6.3.9600.16384  WMI
wbiosrvc.dll  6.3.9600.16384  Windows Biometric Service
wcl.dll  6.3.9600.16384  Windows Class Library
wcletw.dll  6.3.9600.16384  Windows Class Library
wclpowrprof.dll  6.3.9600.16384  Windows Class Library
wclsqm.dll  6.3.9600.16384  Windows Class Library
wclunicode.dll  6.3.9600.16384  Windows Class Library
wclwdi.dll  6.3.9600.16384  Windows Class Library
wcmapi.dll  6.3.9600.16384  Windows Connection Manager Client API
wcmcsp.dll  6.3.9600.16384  Windows Connection Service Provider DLL
wcmsvc.dll  6.3.9600.16384  Windows Connection Manager Service DLL
wcnapi.dll  6.3.9600.16384  Windows Connect Now - API Helper DLL
wcncsvc.dll  6.3.9600.16384  Windows Connect Now - Config Registrar Service
wcneapauthproxy.dll  6.3.9600.16384  Windows Connect Now - WCN EAP Authenticator Proxy
wcneappeerproxy.dll  6.3.9600.16384  Windows Connect Now - WCN EAP PEER Proxy
wcnnetsh.dll  6.3.9600.16384  WCN Netsh Helper DLL
wcnwiz.dll  6.3.9600.16384  Windows Connect Now Wizards
wcspluginservice.dll  6.3.9600.16384  WcsPlugInService DLL
wdc.dll  6.3.9600.16384  Performance Monitor
wdfcoinstaller01009.dll  1.9.7600.16385  WDF Coinstaller
wdfres.dll  6.3.9600.16384  Kernel Mode Driver Framework Resource
wdi.dll  6.3.9600.16384  Windows Diagnostic Infrastructure
wdiasqmmodule.dll  6.3.9600.16384  Adaptive SQM WDI Plugin
wdigest.dll  6.3.9600.16384  Microsoft Digest Access
wdscore.dll  6.3.9600.16384  Panther Engine Module
webcamui.dll  6.3.9600.16384  Microsoft® Windows® Operating System
webcheck.dll  11.0.9600.16384  Web Site Monitor
webclnt.dll  6.3.9600.16384  Web DAV Service DLL
webio.dll  6.3.9600.16384  Web Transfer Protocols API
webservices.dll  6.3.9600.16384  Windows Web Services Runtime
websocket.dll  6.3.9600.16384  Web Socket API
wecapi.dll  6.3.9600.16384  Event Collector Configuration API
wecsvc.dll  6.3.9600.16384  Event Collector Service
wephostsvc.dll  6.3.9600.16384  WEP Host Service
wer.dll  6.3.9600.16384  Windows Error Reporting DLL
werconcpl.dll  6.3.9600.16384  PRS CPL
wercplsupport.dll  6.3.9600.16384  Problem Reports and Solutions
werdiagcontroller.dll  6.3.9600.16384  WER Diagnostic Controller
wersvc.dll  6.3.9600.16384  Windows Error Reporting Service
werui.dll  6.3.9600.16384  Windows Error Reporting UI DLL
wevtapi.dll  6.3.9600.16384  Eventing Consumption and Configuration API
wevtfwd.dll  6.3.9600.16384  WS-Management Event Forwarding Plug-in
wevtsvc.dll  6.3.9600.16384  Event Logging Service
wfapigp.dll  6.3.9600.16384  Windows Firewall GPO Helper dll
wfdprov.dll  6.3.9600.16384  Private WPS provisioning API DLL for Wi-Fi Direct
wfhc.dll  6.3.9600.16384  Windows Firewall Helper Class
wfsr.dll  6.3.9600.16384  Windows Fax and Scan Resources
whealogr.dll  6.3.9600.16384  WHEA Troubleshooter
whhelper.dll  6.3.9600.16384  Net shell helper DLL for winHttp
wiaaut.dll  6.3.9600.16384  WIA Automation Layer
wiadefui.dll  6.3.9600.16384  WIA Scanner Default UI
wiadss.dll  6.3.9600.16384  WIA TWAIN compatibility layer
wiarpc.dll  6.3.9600.16384  Windows Image Acquisition RPC client DLL
wiascanprofiles.dll  6.3.9600.16384  Microsoft Windows ScanProfiles
wiaservc.dll  6.3.9600.16384  Still Image Devices Service
wiashext.dll  6.3.9600.16384  Imaging Devices Shell Folder UI
wiatrace.dll  6.3.9600.16384  WIA Tracing
wifeman.dll  3.10.0.103  Windows Win16 Application Launcher
wifidisplay.dll  6.3.9600.16384  Wi-Fi Display DLL
wimgapi.dll  6.3.9600.16384  Windows Imaging Library
win32spl.dll  6.3.9600.16384  Client Side Rendering Print Provider
win87em.dll  3.10.0.103  Windows Win16 Application Launcher
winbici.dll  6.3.9600.16384  Windows Services Instrumentation Module
winbio.dll  6.3.9600.16384  Windows Biometrics Client API
winbrand.dll  6.3.9600.16384  Windows Branding Resources
wincorlib.dll  6.3.9600.16384  Microsoft Windows ® WinRT core library
wincredprovider.dll  6.3.9600.16384  wincredprovider DLL
windows.applicationmodel.background.systemeventsbroker.dll  6.3.9600.16384  Windows Background System Events Broker API Server
windows.applicationmodel.background.timebroker.dll  6.3.9600.16384  Windows Background Time Broker API Server
windows.applicationmodel.dll  6.3.9600.16384  Windows ApplicationModel API Server
windows.applicationmodel.store.dll  6.3.9600.16384  Windows Store Runtime DLL
windows.applicationmodel.store.testingframework.dll  6.3.9600.16384  Windows Store Testing Framework Runtime DLL
windows.data.pdf.dll  6.3.9600.16384  PDF WinRT APIs
windows.devices.background.dll  6.3.9600.16384  Windows.Devices.Background
windows.devices.background.ps.dll  6.3.9600.16384  Windows.Devices.Background Interface Proxy
windows.devices.bluetooth.dll  6.3.9600.16384  Windows.Devices.Bluetooth DLL
windows.devices.custom.dll  6.3.9600.16384  Windows.Devices.Custom
windows.devices.custom.ps.dll  6.3.9600.16384  Windows.Devices.Custom Interface Proxy
windows.devices.enumeration.dll  6.3.9600.16384  Windows.Devices.Enumeration
windows.devices.enumeration.ps.dll  6.3.9600.16384  Windows.Devices.Enumeration Interface Proxy
windows.devices.geolocation.dll  6.3.9600.16384  Geolocation Runtime DLL
windows.devices.humaninterfacedevice.dll  6.3.9600.16384  Windows.Devices.HumanInterfaceDevice DLL
windows.devices.pointofservice.dll  6.3.9600.16384  Windows Runtime PointOfService DLL
windows.devices.portable.dll  6.3.9600.16384  Windows Runtime Portable Devices DLL
windows.devices.printers.extensions.dll  6.3.9600.16384  Windows.Devices.Printers.Extensions
windows.devices.scanners.dll  6.3.9600.16384  Windows Runtime Devices Scanners DLL
windows.devices.sensors.dll  6.3.9600.16419  Windows Runtime Sensors DLL
windows.devices.smartcards.dll  6.3.9600.16384  Windows Runtime Smart Card API DLL
windows.devices.usb.dll  6.3.9600.16384  Windows Runtime Usb DLL
windows.devices.wifidirect.dll  6.3.9600.16384  Windows.Devices.WiFiDirect DLL
windows.globalization.dll  6.3.9600.16384  Windows Globalization
windows.globalization.fontgroups.dll  6.3.9600.16384  Fonts Mapping API
windows.graphics.dll  6.3.9600.16384  WinRT Windows Graphics DLL
windows.graphics.printing.dll  6.3.9600.16384  Microsoft Windows Printing Support
windows.help.runtime.dll  6.3.9600.16384  
windows.immersiveshell.serviceprovider.dll  6.3.9600.16384  Windows.ImmersiveShell.ServiceProvider
windows.management.workplace.workplacesettings.dll  6.3.9600.16384  Windows Runtime WorkplaceSettings DLL
windows.media.devices.dll  6.3.9600.16384  Windows Runtime media device server DLL
windows.media.dll  6.3.9600.16384  Windows Media Runtime DLL
windows.media.mediacontrol.dll  6.3.9600.16384  Windows Runtime MediaControl server DLL
windows.media.renewal.dll  6.3.9600.16384  Windows Media Renewal DLL
windows.media.speechsynthesis.dll  6.3.9600.16384  Windows Speech Runtime DLL
windows.media.streaming.dll  12.0.9600.16384  DLNA DLL
windows.media.streaming.ps.dll  12.0.9600.16384  DLNA Proxy-Stub DLL
windows.networking.backgroundtransfer.contentprefetchtask.dll  6.3.9600.16384  Windows Networking Background Transfer Content Prefetch task DLL
windows.networking.backgroundtransfer.dll  6.3.9600.16384  Windows.Networking.BackgroundTransfer DLL
windows.networking.connectivity.dll  6.3.9600.16384  Windows Networking Connectivity Runtime DLL
windows.networking.dll  6.3.9600.16384  Windows.Networking DLL
windows.networking.hostname.dll  6.3.9600.16384  Windows.Networking.HostName DLL
windows.networking.networkoperators.hotspotauthentication.dll  6.3.9600.16384  Microsoft Windows Hotspot Authentication API
windows.networking.proximity.dll  6.3.9600.16384  Windows Runtime Proximity API DLL
windows.networking.sockets.pushenabledapplication.dll  6.3.9600.16384  Windows.Networking.Sockets.PushEnabledApplication DLL
windows.networking.vpn.dll  6.3.9600.16384  Windows.Networking.Vpn DLL
windows.security.authentication.onlineid.dll  6.3.9600.16384  Windows Runtime OnlineId Authentication DLL
windows.security.credentials.ui.credentialpicker.dll  6.3.9600.16384  WinRT Credential Picker Server
windows.security.credentials.ui.userconsentverifier.dll  6.3.9600.16384  Windows User Consent Verifier API
windows.storage.applicationdata.dll  6.3.9600.16384  Windows Application Data API Server
windows.storage.compression.dll  6.3.9600.16384  WinRT Compression
windows.system.display.dll  6.3.9600.16384  Windows System Display Runtime DLL
windows.system.profile.hardwareid.dll  6.3.9600.16384  Windows System Profile HardwareId DLL
windows.system.profile.systemmanufacturers.dll  6.3.9600.16384  Windows.System.Profile.SystemManufacturers
windows.system.remotedesktop.dll  6.3.9600.16384  Windows System RemoteDesktop Runtime DLL
windows.ui.dll  6.3.9600.16384  Windows Runtime UI Foundation DLL
windows.ui.immersive.dll  6.3.9600.16384  WINDOWS.UI.IMMERSIVE
windows.ui.input.inking.dll  6.3.9600.16384  WinRT Windows Inking DLL
windows.ui.search.dll  6.3.9600.16384  Windows.UI.Search
windows.ui.xaml.dll  6.3.9600.16384  Windows.UI.Xaml dll
windows.web.dll  6.3.9600.16384  Web Client DLL
windows.web.http.dll  6.3.9600.16384  Windows.Web.Http DLL
windowscodecs.dll  6.3.9600.16384  Microsoft Windows Codecs Library
windowscodecsext.dll  6.3.9600.16384  Microsoft Windows Codecs Extended Library
windowslivelogin.dll  6.3.9600.16384  Microsoft® Account Login Helper
winethc.dll  6.3.9600.16384  WinInet Helper Class
winfax.dll  6.3.9600.16384  Microsoft Fax API Support DLL
winhttp.dll  6.3.9600.16384  Windows HTTP Services
wininet.dll  11.0.9600.16384  Internet Extensions for Win32
wininitext.dll  6.3.9600.16384  WinInit Utility Extension DLL
winipsec.dll  6.3.9600.16384  Windows IPsec SPD Client DLL
winlangdb.dll  6.3.9600.16384  Windows Bcp47 Language Database
winlogonext.dll  6.3.9600.16384  WinLogon Utility Extension DLL
winmde.dll  12.0.9600.16384  WinMDE DLL
winmm.dll  6.3.9600.16384  MCI API DLL
winmmbase.dll  6.3.9600.16384  Base Multimedia Extension API DLL
winmsoirmprotector.dll  6.3.9600.16384  Windows Office file format IRM Protector
winnls.dll  3.10.0.103  Windows Win16 Application Launcher
winnsi.dll  6.3.9600.16384  Network Store Information RPC interface
winopcirmprotector.dll  6.3.9600.16384  Windows Office file format IRM Protector
winrnr.dll  6.3.9600.16384  LDAP RnR Provider DLL
winrscmd.dll  6.3.9600.16384  remtsvc
winrsmgr.dll  6.3.9600.16384  WSMan Shell API
winrssrv.dll  6.3.9600.16384  winrssrv
winrttracing.dll  6.3.9600.16384  Windows Diagnostics Tracing
winsatapi.dll  6.3.9600.16384  Windows System Assessment Tool API
winscard.dll  6.3.9600.16384  Microsoft Smart Card API
winsetupui.dll  6.3.9600.16384  Windows Setup UI
winshfhc.dll  6.3.9600.16384  File Risk Estimation
winsku.dll  6.3.9600.16384  Windows SKU Library
winsock.dll  3.10.0.103  Windows Win16 Application Launcher
winsockhc.dll  6.3.9600.16384  Winsock Network Diagnostic Helper Class
winsrpc.dll  6.3.9600.16384  WINS RPC LIBRARY
winsrv.dll  6.3.9600.16384  Multi-User Windows Server DLL
winsta.dll  6.3.9600.16384  Winstation Library
winsync.dll  2007.94.9600.16384  Synchronization Framework
winsyncmetastore.dll  2007.94.9600.16384  Windows Synchronization Metadata Store
winsyncproviders.dll  2007.94.9600.16384  Windows Synchronization Provider Framework
wintrust.dll  6.3.9600.16384  Microsoft Trust Verification APIs
wintypes.dll  6.3.9600.16384  Windows Base Types DLL
winusb.dll  6.3.9600.16384  Windows USB Driver User Library
wisp.dll  6.3.9600.16384  Microsoft Pen and Touch Input Component
witnesswmiv2provider.dll  6.3.9600.16384  Witness Service WMIv2 Provider
wkscli.dll  6.3.9600.16384  Workstation Service Client DLL
wkspbrokerax.dll  6.3.9600.16384  Microsoft Workspace Broker ActiveX Control
wksprtps.dll  6.3.9600.16384  WorkspaceRuntime ProxyStub DLL
wkssvc.dll  6.3.9600.16384  Workstation Service DLL
wlanapi.dll  6.3.9600.16384  Windows WLAN AutoConfig Client Side API DLL
wlancfg.dll  6.3.9600.16384  Wlan Netsh Helper DLL
wlanconn.dll  6.3.9600.16384  Dot11 Connection Flows
wlandlg.dll  6.3.9600.16384  Wireless Lan Dialog Wizards
wlangpui.dll  6.3.9600.16384  Wireless Network Policy Management Snap-in
wlanhc.dll  6.3.9600.16384  Wireless LAN Helper Classes
wlanhlp.dll  6.3.9600.16384  Windows Wireless LAN 802.11 Client Side Helper API
wlaninst.dll  6.3.9600.16384  Windows NET Device Class Co-Installer for Wireless LAN
wlanmm.dll  6.3.9600.16384  Dot11 Media and AdHoc Managers
wlanmsm.dll  6.3.9600.16384  Windows Wireless LAN 802.11 MSM DLL
wlanpref.dll  6.3.9600.16384  Wireless Preferred Networks
wlanradiomanager.dll  6.3.9600.16384  Wlan Radio Manager
wlansec.dll  6.3.9600.16384  Windows Wireless LAN 802.11 MSM Security Module DLL
wlansvc.dll  6.3.9600.16384  Windows WLAN AutoConfig Service DLL
wlansvcpal.dll  6.3.9600.16384  Windows WLAN AutoConfig Service PAL DLL
wlanui.dll  6.3.9600.16384  Wireless Profile UI
wlanutil.dll  6.3.9600.16384  Windows Wireless LAN 802.11 Utility DLL
wldap32.dll  6.3.9600.16384  Win32 LDAP API DLL
wldp.dll  6.3.9600.16384  Windows Lockdown Policy
wlgpclnt.dll  6.3.9600.16384  802.11 Group Policy Client
wlidcli.dll  6.3.9600.16384  Microsoft® Account Dynamic Link Library
wlidcredprov.dll  6.3.9600.16384  Microsoft® Account Credential Provider
wlidfdp.dll  6.3.9600.16384  Microsoft® Account Function Discovery Provider
wlidnsp.dll  6.3.9600.16384  Microsoft® Account Namespace Provider
wlidprov.dll  6.3.9600.16384  Microsoft® Account Provider
wlidres.dll  6.3.9600.16384  Microsoft® Windows Live ID Resource
wlidsvc.dll  6.3.9600.16384  Microsoft® Account Service
wls0wndh.dll  6.3.9600.16384  Session0 Viewer Window Hook DLL
wmadmod.dll  6.3.9600.16384  Windows Media Audio Decoder
wmadmoe.dll  6.3.9600.16384  Windows Media Audio 10 Encoder/Transcoder
wmalfxgfxdsp.dll  6.3.9600.16384  SysFx DSP
wmasf.dll  12.0.9600.16384  Windows Media ASF DLL
wmcodecdspps.dll  6.3.9600.16384  Windows Media CodecDSP Proxy Stub Dll
wmdmlog.dll  12.0.9600.16384  Windows Media Device Manager Logger
wmdmps.dll  12.0.9600.16384  Windows Media Device Manager Proxy Stub
wmdrmdev.dll  12.0.9600.16384  Windows Media DRM for Network Devices Registration DLL
wmdrmnet.dll  12.0.9600.16384  Windows Media DRM for Network Devices DLL
wmdrmsdk.dll  11.0.9600.16384  Windows Media DRM SDK DLL
wmerror.dll  12.0.9600.16384  Windows Media Error Definitions (English)
wmi.dll  6.3.9600.16384  WMI DC and DP functionality
wmiclnt.dll  6.3.9600.16384  WMI Client API
wmicmiplugin.dll  6.3.9600.16384  WMI CMI Plugin
wmidcom.dll  6.3.9600.16384  WMI
wmidx.dll  12.0.9600.16384  Windows Media Indexer DLL
wmiprop.dll  6.3.9600.16384  WDM Provider Dynamic Property Page CoInstaller
wmitomi.dll  6.3.9600.16384  CIM Provider Adapter
wmnetmgr.dll  12.0.9600.16384  Windows Media Network Plugin Manager DLL
wmp.dll  12.0.9600.16384  Windows Media Player
wmpdui.dll  12.0.9600.16384  Windows Media Player UI Engine
wmpdxm.dll  12.0.9600.16384  Windows Media Player Extension
wmpeffects.dll  12.0.9600.16384  Windows Media Player Effects
wmphoto.dll  6.3.9600.16384  Windows Media Photo Codec
wmploc.dll  12.0.9600.16384  Windows Media Player Resources
wmpmde.dll  12.0.9600.16384  WMPMDE DLL
wmpps.dll  12.0.9600.16384  Windows Media Player Proxy Stub Dll
wmpshell.dll  12.0.9600.16384  Windows Media Player Launcher
wmsgapi.dll  6.3.9600.16384  WinLogon IPC Client
wmspdmod.dll  6.3.9600.16384  Windows Media Audio Voice Decoder
wmspdmoe.dll  6.3.9600.16384  Windows Media Audio Voice Encoder
wmvcore.dll  12.0.9600.16384  Windows Media Playback/Authoring DLL
wmvdecod.dll  6.3.9600.16384  Windows Media Video Decoder
wmvdspa.dll  6.3.9600.16384  Windows Media Video DSP Components - Advanced
wmvencod.dll  6.3.9600.16384  Windows Media Video 9 Encoder
wmvsdecd.dll  6.3.9600.16384  Windows Media Screen Decoder
wmvsencd.dll  6.3.9600.16384  Windows Media Screen Encoder
wmvxencd.dll  6.3.9600.16384  Windows Media Video Encoder
workerdd.dll  6.3.9600.16384  Framebuffer Display Driver
workfolderscontrol.dll  6.3.9600.16384  Microsoft (C) Work Folders Control Panel
workfoldersgpext.dll  6.3.9600.16384  Microsoft (C) Work Folders Group Policy Client Extension
workfoldersres.dll  6.2.9200.16384  Work Folders Resources
workfoldersshell.dll  6.3.9600.16384  Microsoft (C) Work Folders Shell Extension
workfolderssvc.dll  6.3.9600.16384  Microsoft (C) Work Folders Service
wow32.dll  6.3.9600.16384  32-bit WOW Subsystem Library
wpc.dll  6.3.9600.16384  WPC Settings Library
wpccpl.dll  6.3.9600.16384  Parental Controls Control Panel
wpcwebsync.dll  6.3.9600.16384  Family Safety Web Synchronization Library
wpcsvc.dll  6.3.9600.16384  WPC Filtering Service
wpd_ci.dll  6.3.9600.16384  Driver Setup Class Installer for Windows Portable Devices
wpdbusenum.dll  6.3.9600.16384  Portable Device Enumerator
wpdshext.dll  6.3.9600.16384  Portable Devices Shell Extension
wpdshserviceobj.dll  6.3.9600.16384  Windows Portable Device Shell Service Object
wpdsp.dll  6.3.9600.16384  WMDM Service Provider for Windows Portable Devices
wpnapps.dll  6.3.9600.16384  Windows Push Notification Apps
wpncore.dll  6.3.9600.16384  Windows Push Notification Core
wpninprc.dll  6.3.9600.16384  Windows Push Notification InProc
wpnprv.dll  6.3.9600.16384  Windows Push Notification Platform Connection Provider
wpnsruprov.dll  6.3.9600.16384  SRUM provider for WPN
ws2_32.dll  6.3.9600.16384  Windows Socket 2.0 32-Bit DLL
ws2help.dll  6.3.9600.16384  Windows Socket 2.0 Helper for Windows NT
wscapi.dll  6.3.9600.16384  Windows Security Center API
wscinterop.dll  6.3.9600.16384  Windows Health Center WSC Interop
wscisvif.dll  6.3.9600.16384  Windows Security Center ISV API
wsclient.dll  6.3.9600.16384  Windows Store Licensing Client
wscproxystub.dll  6.3.9600.16384  Windows Security Center ISV Proxy Stub
wscsvc.dll  6.3.9600.16384  Windows Security Center Service
wsdapi.dll  6.3.9600.16384  Web Services for Devices API DLL
wsdchngr.dll  6.3.9600.16384  WSD Challenge Component
wsdmon.dll  6.3.9600.16384  WSD Printer Port Monitor
wsdprintproxy.dll  6.3.9600.16384  Function Discovery Printer Proxy Dll
wsdscanproxy.dll  6.3.9600.16384  Function Discovery WSD Scanner Proxy Dll
wsecedit.dll  6.3.9600.16384  Security Configuration UI Module
wsepno.dll  7.0.9600.16384  Profile notification support for Windows Search Service
wshbth.dll  6.3.9600.16384  Windows Sockets Helper DLL
wshcon.dll  5.8.9600.16384  Microsoft ® Windows Script Controller
wshelper.dll  6.3.9600.16384  Winsock Net shell helper DLL for winsock
wshext.dll  5.8.9600.16384  Microsoft ® Shell Extension for Windows Script Host
wship6.dll  6.3.9600.16384  Winsock2 Helper DLL (TL/IPv6)
wshirda.dll  6.3.9600.16384  Windows Sockets Helper DLL
wshnetbs.dll  6.3.9600.16384  Netbios Windows Sockets Helper DLL
wshqos.dll  6.3.9600.16384  QoS Winsock2 Helper DLL
wshrm.dll  6.3.9600.16384  Windows Sockets Helper DLL for PGM
wshtcpip.dll  6.3.9600.16384  Winsock2 Helper DLL (TL/IPv4)
wsmagent.dll  6.3.9600.16384  WinRM Agent
wsmanmigrationplugin.dll  6.3.9600.16384  WinRM Migration Plugin
wsmauto.dll  6.3.9600.16384  WSMAN Automation
wsmplpxy.dll  6.3.9600.16384  wsmplpxy
wsmres.dll  6.3.9600.16384  WSMan Resource DLL
wsmsvc.dll  6.3.9600.16384  WSMan Service
wsmwmipl.dll  6.3.9600.16384  WSMAN WMI Provider
wsnmp32.dll  6.3.9600.16384  Microsoft WinSNMP v2.0 Manager API
wsock32.dll  6.3.9600.16384  Windows Socket 32-Bit DLL
wsservice.dll  6.3.9600.16384  Windows Store Service
wsshared.dll  6.3.9600.16384  WSShared DLL
wssync.dll  6.3.9600.16384  Windows Store Licensing Sync Client
wtsapi32.dll  6.3.9600.16384  Windows Remote Desktop Session Host Server SDK APIs
wuaext.dll  7.9.9600.16384  Windows Update Wu exports
wuapi.dll  7.9.9600.16384  Windows Update Client API
wuaueng.dll  7.9.9600.16384  Windows Update Agent
wucltux.dll  7.9.9600.16384  Windows Update Client User Experience
wudfcoinstaller.dll  6.3.9600.16384  Windows Driver Foundation - User-mode Platform Device Co-Installer
wudfplatform.dll  6.3.9600.16384  Windows Driver Foundation - User-mode Platform Library
wudfsvc.dll  6.3.9600.16384  Windows Driver Foundation - User-mode Driver Framework Service
wudfx.dll  6.3.9600.16384  WDF:UMDF Framework Library
wudfx02000.dll  6.3.9600.16384  WDF:UMDF Framework Library
wudriver.dll  7.9.9600.16384  Windows Update WUDriver Stub
wups.dll  7.9.9600.16384  Windows Update client proxy stub
wups2.dll  7.9.9600.16384  Windows Update client proxy stub 2
wusettingsprovider.dll  7.9.9600.16384  Windows Update Modern WuApp
wushareduxresources.dll  7.9.9600.16384  Windows Update Shared UI Resources
wuwebv.dll  7.9.9600.16384  Windows Update Vista Web Control
wvc.dll  6.3.9600.16384  Windows Visual Components
wwaapi.dll  6.3.9600.16384  Microsoft Web Application Host API library
wwanapi.dll  6.3.9600.16384  Mbnapi
wwancfg.dll  6.3.9600.16384  MBN Netsh Helper DLL
wwanconn.dll  8.1.9600.16384  Wireless WAN Connection Flows
wwanhc.dll  8.1.9600.16384  Wireless WAN Helper Class
wwaninst.dll  8.1.9600.16384  Windows NET Device Class Co-Installer for Wireless WAN
wwanmm.dll  8.1.9600.16384  WWan Media Manager
wwanpref.dll  8.1.9600.16384  Wireless WAN Profile Settings Editor
wwanprotdim.dll  8.1.9600.16384  WWAN Device Interface Module
wwanradiomanager.dll  6.3.9600.16384  Wwan Radio Manager
wwansvc.dll  8.1.9600.16384  WWAN Auto Config Service
wwapi.dll  8.1.9600.16384  WWAN API
xaudio2_8.dll  6.3.9600.16384  XAudio2 Game Audio API
xinput1_4.dll  6.3.9600.16384  Microsoft Common Controller API
xinput9_1_0.dll  6.3.9600.16384  XNA Common Controller
xmlfilter.dll  2008.0.9600.16384  XML Filter
xmllite.dll  6.3.9600.16384  Microsoft XmlLite Library
xmlprovi.dll  6.3.9600.16384  Network Provisioning Service Client API
xolehlp.dll  2001.12.10530.16384  Microsoft Distributed Transaction Coordinator Helper APIs DLL
xpsfilt.dll  6.3.9600.16384  XML Paper Specification Document IFilter
xpsgdiconverter.dll  6.3.9600.16384  XPS to GDI Converter
xpsprint.dll  6.3.9600.16384  XPS Printing DLL
xpsrasterservice.dll  6.3.9600.16384  XPS Rasterization Service Component
xpsservices.dll  6.3.9600.16384  Xps Object Model in memory creation and deserialization
xpsshhdr.dll  6.3.9600.16384  OPC Shell Metadata Handler
xpssvcs.dll  6.3.9600.16384  Native Code Xps Services Library
xwizards.dll  6.3.9600.16384  Extensible Wizards Manager Module
xwreg.dll  6.3.9600.16384  Extensible Wizard Registration Manager Module
xwtpdui.dll  6.3.9600.16384  Extensible Wizard Type Plugin for DUI
xwtpw32.dll  6.3.9600.16384  Extensible Wizard Type Plugin for Win32
zipfldr.dll  6.3.9600.16384  Compressed (zipped) Folders


UpTime

 
Current Session:
Last Shutdown Time  2013.11.28. 18:56:30
Last Boot Time  2013.11.28. 18:56:50
Current Time  2013.11.29. 2:46:45
UpTime  28202 sec (0 days, 7 hours, 50 min, 2 sec)
 
UpTime Statistics:
First Boot Time  2013.11.07. 5:33:12
First Shutdown Time  2013.11.07. 5:33:43
Total UpTime  32990 sec (0 days, 9 hours, 9 min, 50 sec)
Total DownTime  1857859 sec (21 days, 12 hours, 4 min, 19 sec)
Longest UpTime  28202 sec (0 days, 7 hours, 50 min, 2 sec)
Longest DownTime  1857722 sec (21 days, 12 hours, 2 min, 2 sec)
Total Reboots  7
System Availability  1.74%
 
Bluescreen Statistics:
Total Bluescreens  0
 
Information:
Information  The above statistics are based on System Event Log entries


Share

 
Share Name  Type  Remark  Local Path
ADMIN$  Folder  Remote Admin  C:\Windows
C$  Folder  Default share  C:\
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]


Account Security

 
Account Security Properties:
Computer Role  Primary
Domain Name  T100
Primary Domain Controller  Not Specified
Forced Logoff Time  Disabled
Min / Max Password Age  0 / 42 days
Minimum Password Length  0 chars
Password History Length  Disabled
Lockout Threshold  Disabled
Lockout Duration  30 min
Lockout Observation Window  30 min


Logon

 
User  Full Name  Logon Server  Logon Domain
Transformer T100    T100  T100
Transformer T100    T100  T100


Users

 
[ Administrator ]
 
User Properties:
User Name  Administrator
Full Name  Administrator
Comment  Built-in account for administering the computer/domain
Member Of Groups  Administrators
Logon Count  17
Disk Quota  -
 
User Features:
Logon Script Executed  Yes
Account Disabled  Yes
Locked Out User  No
Home Folder Required  No
Password Required  Yes
Read-Only Password  No
Password Never Expires  Yes
 
[ Guest ]
 
User Properties:
User Name  Guest
Full Name  Guest
Comment  Built-in account for guest access to the computer/domain
Member Of Groups  Guests
Logon Count  0
Disk Quota  -
 
User Features:
Logon Script Executed  Yes
Account Disabled  Yes
Locked Out User  No
Home Folder Required  No
Password Required  No
Read-Only Password  Yes
Password Never Expires  Yes
 
[ Transformer T100 ]
 
User Properties:
User Name  Transformer T100
Full Name  Transformer T100
Member Of Groups  Administrators
Logon Count  12
Disk Quota  -
 
User Features:
Logon Script Executed  Yes
Account Disabled  No
Locked Out User  No
Home Folder Required  No
Password Required  No
Read-Only Password  No
Password Never Expires  Yes


Local Groups

 
[ Administrators ]
 
Local Group Properties:
Comment  Administrators have complete and unrestricted access to the computer/domain
 
Group Members:
Administrator  
Transformer T100  
 
[ Distributed COM Users ]
 
Local Group Properties:
Comment  Members are allowed to launch, activate and use Distributed COM objects on this machine.
 
[ Event Log Readers ]
 
Local Group Properties:
Comment  Members of this group can read event logs from local machine
 
[ Guests ]
 
Local Group Properties:
Comment  Guests have the same access as members of the Users group by default, except for the Guest account which is further restricted
 
Group Members:
Guest  
 
[ IIS_IUSRS ]
 
Local Group Properties:
Comment  Built-in group used by Internet Information Services.
 
Group Members:
IUSR  
 
[ Performance Log Users ]
 
Local Group Properties:
Comment  Members of this group may schedule logging of performance counters, enable trace providers, and collect event traces both locally and via remote access to this computer
 
[ Performance Monitor Users ]
 
Local Group Properties:
Comment  Members of this group can access performance counter data locally and remotely
 
[ Remote Management Users ]
 
Local Group Properties:
Comment  Members of this group can access WMI resources over management protocols (such as WS-Management via the Windows Remote Management service). This applies only to WMI namespaces that grant access to the user.
 
[ Users ]
 
Local Group Properties:
Comment  Users are prevented from making accidental or intentional system-wide changes and can run most applications
 
Group Members:
Authenticated Users  
INTERACTIVE  
 
[ WinRMRemoteWMIUsers__ ]
 
Local Group Properties:
Comment  Members of this group can access WMI resources over management protocols (such as WS-Management via the Windows Remote Management service). This applies only to WMI namespaces that grant access to the user.


Global Groups

 
[ None ]
 
Global Group Properties:
Comment  Ordinary users
 
Group Members:
Administrator  
Guest  
Transformer T100  


Windows Video

 
[ Intel(R) HD Graphics ]
 
Video Adapter Properties:
Device Description  Intel(R) HD Graphics
Adapter String  Intel(R) HD Graphics
BIOS String  Intel Video BIOS
Chip Type  Intel(R) HD Graphics
DAC Type  Internal
Driver Date  2013.08.28.
Driver Version  10.18.10.3286
Driver Provider  Intel Corporation
Memory Size  1055352 KB
 
Installed Drivers:
igdumdim32  10.18.10.3286
igd10iumd32  10.18.10.3286
igd10iumd32  10.18.10.3286
 
Video Adapter Manufacturer:
Company Name  Intel Corporation
Product Information  http://www.intel.com/products/chipsets
Driver Download  http://support.intel.com/support/graphics
Driver Update  http://www.aida64.com/driver-updates
 
[ Intel(R) HD Graphics ]
 
Video Adapter Properties:
Device Description  Intel(R) HD Graphics
Adapter String  Intel(R) HD Graphics
BIOS String  Intel Video BIOS
Chip Type  Intel(R) HD Graphics
DAC Type  Internal
Driver Date  2013.08.28.
Driver Version  10.18.10.3286
Driver Provider  Intel Corporation
Memory Size  1055352 KB
 
Installed Drivers:
igdumdim32  10.18.10.3286
igd10iumd32  10.18.10.3286
igd10iumd32  10.18.10.3286
 
Video Adapter Manufacturer:
Company Name  Intel Corporation
Product Information  http://www.intel.com/products/chipsets
Driver Download  http://support.intel.com/support/graphics
Driver Update  http://www.aida64.com/driver-updates


PCI / AGP Video

 
Device Description  Device Type
Intel HD Graphics  Video Adapter
Intel HD Graphics  3D Accelerator


GPU

 
[ Integrated: Intel Bay Trail-T SoC - Integrated Graphics Controller ]
 
Graphics Processor Properties:
Video Adapter  Intel Bay Trail-T SoC - Integrated Graphics Controller
GPU Code Name  Bay Trail-T
PCI Device  8086-0F31 / 1043-14ED (Rev 09)
Process Technology  22 nm
Bus Type  Integrated
GPU Clock  667 MHz
RAMDAC Clock  350 MHz
Pixel Pipelines  4
TMU Per Pipeline  1
Unified Shaders  16 (v5.0)
DirectX Hardware Support  DirectX v11
 
Architecture:
Architecture  Intel Gen7
Execution Units (EU)  4
L1 Instruction Cache  32 KB
L1 Texture Cache  4 KB
L2 Texture Cache  24 KB
L3 Cache  0 MB
Unified Return Buffer  128 KB
 
Theoretical Peak Performance:
Pixel Fillrate  2668 MPixel/s @ 667 MHz
Texel Fillrate  [ TRIAL VERSION ]
Single-Precision FLOPS  21.3 GFLOPS @ 667 MHz
Double-Precision FLOPS  [ TRIAL VERSION ]
 
Utilization:
Dynamic Memory  67 MB
 
Graphics Processor Manufacturer:
Company Name  Intel Corporation
Product Information  http://www.intel.com/products/chipsets
Driver Download  http://support.intel.com/support/graphics
Driver Update  http://www.aida64.com/driver-updates


Monitor

 
[ Generic PnP Monitor [NoDB] ]
 
Monitor Properties:
Monitor Name  Generic PnP Monitor [NoDB]
Monitor ID  CMN1001
Model  N101BCG-GK1
Manufacture Date  Week 37 / 2012
Serial Number  None
Max. Visible Display Size  23 cm x 13 cm (10.4")
Picture Aspect Ratio  16:9
Horizontal Frequency  0 - 45 kHz
Vertical Frequency  0 - 60 Hz
Maximum Pixel Clock  70 MHz
Gamma  3.55
DPMS Mode Support  Active-Off
 
[ Intel Imaging Signal Processor 2400 ]
 
Monitor Properties:
Monitor Name  Intel Imaging Signal Processor 2400
Monitor ID  INT0F38
Serial Number  None
Gamma  3.55
DPMS Mode Support  Standby, Suspend, Active-Off


Desktop

 
Desktop Properties:
Device Technology  Raster Display
Resolution  1368 x 768
Color Depth  32-bit
Color Planes  1
Font Resolution  96 dpi
Pixel Width / Height  36 / 36
Pixel Diagonal  51
Vertical Refresh Rate  60 Hz
Desktop Wallpaper  C:\Windows\asus\wallpapers\asus.jpg
 
Desktop Effects:
Combo-Box Animation  Enabled
Drop Shadow Effect  Enabled
Flat Menu Effect  Enabled
Font Smoothing  Enabled
ClearType  Enabled
Full Window Dragging  Enabled
Gradient Window Title Bars  Enabled
Hide Menu Access Keys  Enabled
Hot Tracking Effect  Enabled
Icon Title Wrapping  Enabled
List-Box Smooth Scrolling  Enabled
Menu Animation  Enabled
Menu Fade Effect  Enabled
Minimize/Restore Animation  Enabled
Mouse Cursor Shadow  Disabled
Selection Fade Effect  Enabled
ShowSounds Accessibility Feature  Disabled
ToolTip Animation  Enabled
ToolTip Fade Effect  Enabled
Windows Aero  Enabled
Windows Plus! Extension  Disabled


Multi-Monitor

 
Device ID  Primary  Upper Left Corner  Bottom Right Corner
\\.\DISPLAY1  Yes  (0,0)  (1368,768)


Video Modes

 
Resolution  Color Depth  Refresh Rate
320 x 200  8-bit  60 Hz
320 x 200  16-bit  60 Hz
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
320 x 240  8-bit  60 Hz
320 x 240  16-bit  60 Hz
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
400 x 300  8-bit  60 Hz
400 x 300  16-bit  60 Hz
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
512 x 384  8-bit  60 Hz
512 x 384  16-bit  60 Hz
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
640 x 400  8-bit  60 Hz
640 x 400  16-bit  60 Hz
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
640 x 480  8-bit  60 Hz
640 x 480  16-bit  60 Hz
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
800 x 600  8-bit  60 Hz
800 x 600  16-bit  60 Hz
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
1024 x 768  8-bit  60 Hz
1024 x 768  16-bit  60 Hz
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
1280 x 600  8-bit  60 Hz
1280 x 600  16-bit  60 Hz
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
1280 x 720  8-bit  60 Hz
1280 x 720  16-bit  60 Hz
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
1280 x 768  8-bit  60 Hz
1280 x 768  16-bit  60 Hz
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
1360 x 768  8-bit  60 Hz
1360 x 768  16-bit  60 Hz
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
1366 x 768  8-bit  60 Hz
1366 x 768  16-bit  60 Hz
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
1368 x 768  8-bit  60 Hz
1368 x 768  16-bit  60 Hz
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]


OpenGL

 
OpenGL Properties:
Vendor  Intel
Renderer  Intel(R) HD Graphics
Version  4.0.0 - Build 10.18.10.3286
Shading Language Version  4.00 - Build 10.18.10.3286
OpenGL DLL  6.3.9600.16384(winblue_rtm.130821-1623)
Multitexture Texture Units  8
Occlusion Query Counter Bits  64
Sub-Pixel Precision  4-bit
Max Viewport Size  16384 x 16384
Max Cube Map Texture Size  16384 x 16384
Max Rectangle Texture Size  16384 x 16384
Max 3D Texture Size  2048 x 2048 x 2048
Max Anisotropy  16
Max Clipping Planes  8
Max Display-List Nesting Level  64
Max Draw Buffers  8
Max Evaluator Order  32
Max Light Sources  8
Max Pixel Map Table Size  65536
Min / Max Program Texel Offset  -8 / 7
Max Texture Array Layers  2048
Max Texture LOD Bias  15
 
OpenGL Compliancy:
OpenGL 1.1  Yes (100%)
OpenGL 1.2  Yes (100%)
OpenGL 1.3  Yes (100%)
OpenGL 1.4  Yes (100%)
OpenGL 1.5  Yes (100%)
OpenGL 2.0  Yes (100%)
OpenGL 2.1  Yes (100%)
OpenGL 3.0  Yes (100%)
OpenGL 3.1  Yes (100%)
OpenGL 3.2  Yes (100%)
OpenGL 3.3  Yes (100%)
OpenGL 4.0  Yes (100%)
OpenGL 4.1  No (85%)
OpenGL 4.2  No (83%)
OpenGL 4.3  No (23%)
OpenGL 4.4  No (0%)
 
Max Stack Depth:
Attribute Stack  16
Client Attribute Stack  16
Modelview Matrix Stack  32
Name Stack  128
Projection Matrix Stack  4
Texture Matrix Stack  10
 
Draw Range Elements:
Max Index Count  1048576
Max Vertex Count  1048576
 
Transform Feedback:
Max Interleaved Components  128
Max Separate Attributes  4
Max Separate Components  4
 
Framebuffer Object:
Max Color Attachments  8
Max Render Buffer Size  16384 x 16384
 
Vertex Shader:
Max Uniform Vertex Components  4096
Max Varying Floats  64
Max Vertex Texture Image Units  16
Max Combined Texture Image Units  96
 
Geometry Shader:
Max Geometry Texture Units  16
Max Varying Components  64
Max Geometry Varying Components  64
Max Vertex Varying Components  32
Max Geometry Uniform Components  4096
Max Geometry Output Vertices  256
Max Geometry Total Output Components  1024
 
Fragment Shader:
Max Uniform Fragment Components  4096
 
Vertex Program:
Max Local Parameters  256
Max Environment Parameters  300
Max Program Matrices  8
Max Program Matrix Stack Depth  2
Max Vertex Attributes  16
Max Instructions  1024
Max Native Instructions  1024
Max Temporaries  31
Max Native Temporaries  31
Max Parameters  512
Max Native Parameters  400
Max Attributes  16
Max Native Attributes  16
Max Address Registers  1
Max Native Address Registers  1
 
Fragment Program:
Max Local Parameters  256
Max Environment Parameters  256
Max Texture Coordinates  8
Max Texture Image Units  16
Max Instructions  1447
Max Native Instructions  1447
Max Temporaries  256
Max Native Temporaries  256
Max Parameters  512
Max Native Parameters  32
Max Attributes  13
Max Native Attributes  13
Max Address Registers  0
Max Native Address Registers  0
Max ALU Instructions  1447
Max Native ALU Instructions  1447
Max Texture Instructions  1447
Max Native Texture Instructions  1447
Max Texture Indirections  128
Max Native Texture Indirections  128
 
OpenGL Extensions:
Total / Supported Extensions  839 / 180
GL_3DFX_multisample  Not Supported
GL_3DFX_tbuffer  Not Supported
GL_3DFX_texture_compression_FXT1  Supported
GL_3DL_direct_texture_access2  Not Supported
GL_3Dlabs_multisample_transparency_id  Not Supported
GL_3Dlabs_multisample_transparency_range  Not Supported
GL_AMD_blend_minmax_factor  Not Supported
GL_AMD_compressed_3DC_texture  Not Supported
GL_AMD_compressed_ATC_texture  Not Supported
GL_AMD_conservative_depth  Not Supported
GL_AMD_debug_output  Not Supported
GL_AMD_depth_clamp_separate  Not Supported
GL_AMD_draw_buffers_blend  Not Supported
GL_AMD_interleaved_elements  Not Supported
GL_AMD_multi_draw_indirect  Not Supported
GL_AMD_name_gen_delete  Not Supported
GL_AMD_occlusion_query_event  Not Supported
GL_AMD_performance_monitor  Not Supported
GL_AMD_pinned_memory  Not Supported
GL_AMD_program_binary_Z400  Not Supported
GL_AMD_query_buffer_object  Not Supported
GL_AMD_sample_positions  Not Supported
GL_AMD_seamless_cubemap_per_texture  Not Supported
GL_AMD_shader_atomic_counter_ops  Not Supported
GL_AMD_shader_stencil_export  Not Supported
GL_AMD_shader_stencil_value_export  Not Supported
GL_AMD_shader_trace  Not Supported
GL_AMD_shader_trinary_minmax  Not Supported
GL_AMD_sparse_texture  Not Supported
GL_AMD_stencil_operation_extended  Not Supported
GL_AMD_texture_compression_dxt6  Not Supported
GL_AMD_texture_compression_dxt7  Not Supported
GL_AMD_texture_cube_map_array  Not Supported
GL_AMD_texture_texture4  Not Supported
GL_AMD_texture_tile_pool  Not Supported
GL_AMD_transform_feedback3_lines_triangles  Not Supported
GL_AMD_transform_feedback4  Not Supported
GL_AMD_vertex_shader_layer  Not Supported
GL_AMD_vertex_shader_tessellator  Not Supported
GL_AMD_vertex_shader_viewport_index  Not Supported
GL_AMDX_debug_output  Not Supported
GL_AMDX_name_gen_delete  Not Supported
GL_AMDX_random_access_target  Not Supported
GL_AMDX_vertex_shader_tessellator  Not Supported
GL_ANGLE_framebuffer_blit  Not Supported
GL_ANGLE_framebuffer_multisample  Not Supported
GL_ANGLE_instanced_arrays  Not Supported
GL_ANGLE_pack_reverse_row_order  Not Supported
GL_ANGLE_texture_compression_dxt3  Not Supported
GL_ANGLE_texture_compression_dxt5  Not Supported
GL_ANGLE_texture_usage  Not Supported
GL_ANGLE_translated_shader_source  Not Supported
GL_APPLE_aux_depth_stencil  Not Supported
GL_APPLE_client_storage  Not Supported
GL_APPLE_copy_texture_levels  Not Supported
GL_APPLE_element_array  Not Supported
GL_APPLE_fence  Not Supported
GL_APPLE_float_pixels  Not Supported
GL_APPLE_flush_buffer_range  Not Supported
GL_APPLE_flush_render  Not Supported
GL_APPLE_framebuffer_multisample  Not Supported
GL_APPLE_object_purgeable  Not Supported
GL_APPLE_packed_pixel  Not Supported
GL_APPLE_packed_pixels  Not Supported
GL_APPLE_pixel_buffer  Not Supported
GL_APPLE_rgb_422  Not Supported
GL_APPLE_specular_vector  Not Supported
GL_APPLE_sync  Not Supported
GL_APPLE_texture_2D_limited_npot  Not Supported
GL_APPLE_texture_format_BGRA8888  Not Supported
GL_APPLE_texture_max_level  Not Supported
GL_APPLE_texture_range  Not Supported
GL_APPLE_transform_hint  Not Supported
GL_APPLE_vertex_array_object  Not Supported
GL_APPLE_vertex_array_range  Not Supported
GL_APPLE_vertex_program_evaluators  Not Supported
GL_APPLE_ycbcr_422  Not Supported
GL_ARB_arrays_of_arrays  Supported
GL_ARB_base_instance  Supported
GL_ARB_bindless_texture  Not Supported
GL_ARB_blend_func_extended  Supported
GL_ARB_buffer_storage  Not Supported
GL_ARB_clear_buffer_object  Not Supported
GL_ARB_clear_texture  Not Supported
GL_ARB_color_buffer_float  Supported
GL_ARB_compatibility  Supported
GL_ARB_compressed_texture_pixel_storage  Supported
GL_ARB_compute_shader  Not Supported
GL_ARB_compute_variable_group_size  Not Supported
GL_ARB_conservative_depth  Supported
GL_ARB_copy_buffer  Supported
GL_ARB_copy_image  Not Supported
GL_ARB_debug_group  Not Supported
GL_ARB_debug_label  Not Supported
GL_ARB_debug_output  Supported
GL_ARB_debug_output2  Not Supported
GL_ARB_depth_buffer_float  Supported
GL_ARB_depth_clamp  Supported
GL_ARB_depth_texture  Supported
GL_ARB_draw_buffers  Supported
GL_ARB_draw_buffers_blend  Supported
GL_ARB_draw_elements_base_vertex  Supported
GL_ARB_draw_indirect  Supported
GL_ARB_draw_instanced  Supported
GL_ARB_enhanced_layouts  Not Supported
GL_ARB_ES2_compatibility  Supported
GL_ARB_ES3_compatibility  Not Supported
GL_ARB_explicit_attrib_location  Supported
GL_ARB_explicit_uniform_location  Not Supported
GL_ARB_fragment_coord_conventions  Supported
GL_ARB_fragment_layer_viewport  Not Supported
GL_ARB_fragment_program  Supported
GL_ARB_fragment_program_shadow  Supported
GL_ARB_fragment_shader  Supported
GL_ARB_framebuffer_no_attachments  Not Supported
GL_ARB_framebuffer_object  Supported
GL_ARB_framebuffer_sRGB  Supported
GL_ARB_geometry_shader4  Supported
GL_ARB_get_program_binary  Supported
GL_ARB_gpu_shader_fp64  Supported
GL_ARB_gpu_shader5  Supported
GL_ARB_half_float_pixel  Supported
GL_ARB_half_float_vertex  Supported
GL_ARB_imaging  Not Supported
GL_ARB_indirect_parameters  Not Supported
GL_ARB_instanced_arrays  Supported
GL_ARB_internalformat_query  Supported
GL_ARB_internalformat_query2  Supported
GL_ARB_invalidate_subdata  Not Supported
GL_ARB_make_current_read  Not Supported
GL_ARB_map_buffer_alignment  Supported
GL_ARB_map_buffer_range  Supported
GL_ARB_matrix_palette  Not Supported
GL_ARB_multi_bind  Not Supported
GL_ARB_multi_draw_indirect  Supported
GL_ARB_multisample  Supported
GL_ARB_multitexture  Supported
GL_ARB_occlusion_query  Supported
GL_ARB_occlusion_query2  Supported
GL_ARB_pixel_buffer_object  Supported
GL_ARB_point_parameters  Supported
GL_ARB_point_sprite  Supported
GL_ARB_program_interface_query  Supported
GL_ARB_provoking_vertex  Supported
GL_ARB_query_buffer_object  Not Supported
GL_ARB_robust_buffer_access_behavior  Not Supported
GL_ARB_robustness  Supported
GL_ARB_robustness_isolation  Not Supported
GL_ARB_sample_shading  Supported
GL_ARB_sampler_objects  Supported
GL_ARB_seamless_cube_map  Supported
GL_ARB_seamless_cubemap_per_texture  Not Supported
GL_ARB_separate_shader_objects  Supported
GL_ARB_shader_atomic_counters  Supported
GL_ARB_shader_bit_encoding  Supported
GL_ARB_shader_draw_parameters  Not Supported
GL_ARB_shader_group_vote  Not Supported
GL_ARB_shader_image_load_store  Not Supported
GL_ARB_shader_image_size  Not Supported
GL_ARB_shader_objects  Supported
GL_ARB_shader_precision  Supported
GL_ARB_shader_stencil_export  Not Supported
GL_ARB_shader_storage_buffer_object  Not Supported
GL_ARB_shader_subroutine  Supported
GL_ARB_shader_texture_lod  Not Supported
GL_ARB_shading_language_100  Supported
GL_ARB_shading_language_120  Not Supported
GL_ARB_shading_language_420pack  Supported
GL_ARB_shading_language_include  Not Supported
GL_ARB_shading_language_packing  Supported
GL_ARB_shadow  Supported
GL_ARB_shadow_ambient  Not Supported
GL_ARB_sparse_texture  Not Supported
GL_ARB_stencil_texturing  Not Supported
GL_ARB_swap_buffers  Not Supported
GL_ARB_sync  Supported
GL_ARB_tessellation_shader  Supported
GL_ARB_texture_border_clamp  Supported
GL_ARB_texture_buffer_object  Not Supported
GL_ARB_texture_buffer_object_rgb32  Supported
GL_ARB_texture_buffer_range  Supported
GL_ARB_texture_compression  Supported
GL_ARB_texture_compression_bptc  Supported
GL_ARB_texture_compression_rgtc  Supported
GL_ARB_texture_compression_rtgc  Not Supported
GL_ARB_texture_cube_map  Supported
GL_ARB_texture_cube_map_array  Supported
GL_ARB_texture_env_add  Supported
GL_ARB_texture_env_combine  Supported
GL_ARB_texture_env_crossbar  Supported
GL_ARB_texture_env_dot3  Supported
GL_ARB_texture_float  Supported
GL_ARB_texture_gather  Supported
GL_ARB_texture_mirror_clamp_to_edge  Not Supported
GL_ARB_texture_mirrored_repeat  Not Supported
GL_ARB_texture_multisample  Supported
GL_ARB_texture_non_power_of_two  Supported
GL_ARB_texture_query_levels  Not Supported
GL_ARB_texture_query_lod  Supported
GL_ARB_texture_rectangle  Supported
GL_ARB_texture_rg  Supported
GL_ARB_texture_rgb10_a2ui  Supported
GL_ARB_texture_snorm  Not Supported
GL_ARB_texture_stencil8  Not Supported
GL_ARB_texture_storage  Supported
GL_ARB_texture_storage_multisample  Not Supported
GL_ARB_texture_swizzle  Supported
GL_ARB_texture_view  Not Supported
GL_ARB_timer_query  Supported
GL_ARB_transform_feedback_instanced  Supported
GL_ARB_transform_feedback2  Supported
GL_ARB_transform_feedback3  Supported
GL_ARB_transpose_matrix  Supported
GL_ARB_uber_buffers  Not Supported
GL_ARB_uber_mem_image  Not Supported
GL_ARB_uber_vertex_array  Not Supported
GL_ARB_uniform_buffer_object  Supported
GL_ARB_vertex_array_bgra  Supported
GL_ARB_vertex_array_object  Supported
GL_ARB_vertex_attrib_64bit  Supported
GL_ARB_vertex_attrib_binding  Not Supported
GL_ARB_vertex_blend  Not Supported
GL_ARB_vertex_buffer_object  Supported
GL_ARB_vertex_program  Supported
GL_ARB_vertex_shader  Supported
GL_ARB_vertex_type_10f_11f_11f_rev  Not Supported
GL_ARB_vertex_type_2_10_10_10_rev  Supported
GL_ARB_viewport_array  Supported
GL_ARB_window_pos  Supported
GL_ARM_mali_program_binary  Not Supported
GL_ARM_mali_shader_binary  Not Supported
GL_ARM_rgba8  Not Supported
GL_ATI_array_rev_comps_in_4_bytes  Not Supported
GL_ATI_blend_equation_separate  Not Supported
GL_ATI_blend_weighted_minmax  Not Supported
GL_ATI_draw_buffers  Not Supported
GL_ATI_element_array  Not Supported
GL_ATI_envmap_bumpmap  Not Supported
GL_ATI_fragment_shader  Not Supported
GL_ATI_lock_texture  Not Supported
GL_ATI_map_object_buffer  Not Supported
GL_ATI_meminfo  Not Supported
GL_ATI_pixel_format_float  Not Supported
GL_ATI_pn_triangles  Not Supported
GL_ATI_point_cull_mode  Not Supported
GL_ATI_separate_stencil  Supported
GL_ATI_shader_texture_lod  Not Supported
GL_ATI_text_fragment_shader  Not Supported
GL_ATI_texture_compression_3dc  Not Supported
GL_ATI_texture_env_combine3  Not Supported
GL_ATI_texture_float  Not Supported
GL_ATI_texture_mirror_once  Not Supported
GL_ATI_vertex_array_object  Not Supported
GL_ATI_vertex_attrib_array_object  Not Supported
GL_ATI_vertex_blend  Not Supported
GL_ATI_vertex_shader  Not Supported
GL_ATI_vertex_streams  Not Supported
GL_ATIX_pn_triangles  Not Supported
GL_ATIX_texture_env_combine3  Not Supported
GL_ATIX_texture_env_route  Not Supported
GL_ATIX_vertex_shader_output_point_size  Not Supported
GL_Autodesk_facet_normal  Not Supported
GL_Autodesk_valid_back_buffer_hint  Not Supported
GL_DIMD_YUV  Not Supported
GL_DMP_shader_binary  Not Supported
GL_EXT_422_pixels  Not Supported
GL_EXT_abgr  Supported
GL_EXT_bgra  Supported
GL_EXT_bindable_uniform  Not Supported
GL_EXT_blend_color  Supported
GL_EXT_blend_equation_separate  Supported
GL_EXT_blend_func_separate  Supported
GL_EXT_blend_logic_op  Not Supported
GL_EXT_blend_minmax  Supported
GL_EXT_blend_subtract  Supported
GL_EXT_Cg_shader  Not Supported
GL_EXT_clip_volume_hint  Supported
GL_EXT_cmyka  Not Supported
GL_EXT_color_buffer_half_float  Not Supported
GL_EXT_color_matrix  Not Supported
GL_EXT_color_subtable  Not Supported
GL_EXT_color_table  Not Supported
GL_EXT_compiled_vertex_array  Supported
GL_EXT_convolution  Not Supported
GL_EXT_convolution_border_modes  Not Supported
GL_EXT_coordinate_frame  Not Supported
GL_EXT_copy_buffer  Not Supported
GL_EXT_copy_texture  Not Supported
GL_EXT_cull_vertex  Not Supported
GL_EXT_debug_label  Not Supported
GL_EXT_debug_marker  Not Supported
GL_EXT_depth_bounds_test  Not Supported
GL_EXT_depth_buffer_float  Not Supported
GL_EXT_direct_state_access  Not Supported
GL_EXT_discard_framebuffer  Not Supported
GL_EXT_draw_buffers2  Supported
GL_EXT_draw_indirect  Not Supported
GL_EXT_draw_instanced  Not Supported
GL_EXT_draw_range_elements  Supported
GL_EXT_fog_coord  Supported
GL_EXT_fog_function  Not Supported
GL_EXT_fog_offset  Not Supported
GL_EXT_frag_depth  Not Supported
GL_EXT_fragment_lighting  Not Supported
GL_EXT_framebuffer_blit  Supported
GL_EXT_framebuffer_multisample  Supported
GL_EXT_framebuffer_multisample_blit_scaled  Not Supported
GL_EXT_framebuffer_object  Supported
GL_EXT_framebuffer_sRGB  Not Supported
GL_EXT_generate_mipmap  Not Supported
GL_EXT_geometry_shader4  Supported
GL_EXT_gpu_program_parameters  Supported
GL_EXT_gpu_shader_fp64  Not Supported
GL_EXT_gpu_shader4  Supported
GL_EXT_gpu_shader5  Not Supported
GL_EXT_histogram  Not Supported
GL_EXT_import_sync_object  Not Supported
GL_EXT_index_array_formats  Not Supported
GL_EXT_index_func  Not Supported
GL_EXT_index_material  Not Supported
GL_EXT_index_texture  Not Supported
GL_EXT_interlace  Not Supported
GL_EXT_light_texture  Not Supported
GL_EXT_map_buffer_range  Not Supported
GL_EXT_misc_attribute  Not Supported
GL_EXT_multi_draw_arrays  Supported
GL_EXT_multisample  Not Supported
GL_EXT_multisampled_render_to_texture  Not Supported
GL_EXT_multiview_draw_buffers  Not Supported
GL_EXT_occlusion_query_boolean  Not Supported
GL_EXT_packed_depth_stencil  Supported
GL_EXT_packed_float  Supported
GL_EXT_packed_pixels  Supported
GL_EXT_packed_pixels_12  Not Supported
GL_EXT_paletted_texture  Not Supported
GL_EXT_pixel_buffer_object  Not Supported
GL_EXT_pixel_format  Not Supported
GL_EXT_pixel_texture  Not Supported
GL_EXT_pixel_transform  Not Supported
GL_EXT_pixel_transform_color_table  Not Supported
GL_EXT_point_parameters  Not Supported
GL_EXT_polygon_offset  Not Supported
GL_EXT_provoking_vertex  Not Supported
GL_EXT_read_format_bgra  Not Supported
GL_EXT_rescale_normal  Supported
GL_EXT_robustness  Not Supported
GL_EXT_scene_marker  Not Supported
GL_EXT_secondary_color  Supported
GL_EXT_separate_shader_objects  Not Supported
GL_EXT_separate_specular_color  Supported
GL_EXT_shader_atomic_counters  Not Supported
GL_EXT_shader_framebuffer_fetch  Not Supported
GL_EXT_shader_image_load_store  Not Supported
GL_EXT_shader_subroutine  Not Supported
GL_EXT_shader_texture_lod  Not Supported
GL_EXT_shadow_funcs  Supported
GL_EXT_shadow_samplers  Not Supported
GL_EXT_shared_texture_palette  Not Supported
GL_EXT_sRGB  Not Supported
GL_EXT_static_vertex_array  Not Supported
GL_EXT_stencil_clear_tag  Not Supported
GL_EXT_stencil_two_side  Supported
GL_EXT_stencil_wrap  Supported
GL_EXT_subtexture  Not Supported
GL_EXT_swap_control  Not Supported
GL_EXT_tessellation_shader  Not Supported
GL_EXT_texgen_reflection  Not Supported
GL_EXT_texture  Not Supported
GL_EXT_texture_array  Supported
GL_EXT_texture_border_clamp  Not Supported
GL_EXT_texture_buffer_object  Not Supported
GL_EXT_texture_buffer_object_rgb32  Not Supported
GL_EXT_texture_color_table  Not Supported
GL_EXT_texture_compression_bptc  Not Supported
GL_EXT_texture_compression_dxt1  Not Supported
GL_EXT_texture_compression_latc  Not Supported
GL_EXT_texture_compression_rgtc  Not Supported
GL_EXT_texture_compression_s3tc  Supported
GL_EXT_texture_cube_map  Not Supported
GL_EXT_texture_edge_clamp  Supported
GL_EXT_texture_env  Not Supported
GL_EXT_texture_env_add  Supported
GL_EXT_texture_env_combine  Supported
GL_EXT_texture_env_dot3  Not Supported
GL_EXT_texture_filter_anisotropic  Supported
GL_EXT_texture_format_BGRA8888  Not Supported
GL_EXT_texture_integer  Supported
GL_EXT_texture_lod  Not Supported
GL_EXT_texture_lod_bias  Supported
GL_EXT_texture_mirror_clamp  Not Supported
GL_EXT_texture_object  Not Supported
GL_EXT_texture_perturb_normal  Not Supported
GL_EXT_texture_rectangle  Supported
GL_EXT_texture_rg  Not Supported
GL_EXT_texture_shared_exponent  Supported
GL_EXT_texture_snorm  Supported
GL_EXT_texture_sRGB  Supported
GL_EXT_texture_sRGB_decode  Supported
GL_EXT_texture_storage  Supported
GL_EXT_texture_swizzle  Supported
GL_EXT_texture_type_2_10_10_10_REV  Not Supported
GL_EXT_texture3D  Supported
GL_EXT_texture4D  Not Supported
GL_EXT_timer_query  Not Supported
GL_EXT_transform_feedback  Supported
GL_EXT_transform_feedback2  Not Supported
GL_EXT_transform_feedback3  Not Supported
GL_EXT_unpack_subimage  Not Supported
GL_EXT_vertex_array  Not Supported
GL_EXT_vertex_array_bgra  Not Supported
GL_EXT_vertex_array_set  Not Supported
GL_EXT_vertex_array_setXXX  Not Supported
GL_EXT_vertex_attrib_64bit  Not Supported
GL_EXT_vertex_shader  Not Supported
GL_EXT_vertex_weighting  Not Supported
GL_EXTX_framebuffer_mixed_formats  Not Supported
GL_EXTX_packed_depth_stencil  Not Supported
GL_FGL_lock_texture  Not Supported
GL_FJ_shader_binary_GCCSO  Not Supported
GL_GL2_geometry_shader  Not Supported
GL_GREMEDY_frame_terminator  Not Supported
GL_GREMEDY_string_marker  Not Supported
GL_HP_convolution_border_modes  Not Supported
GL_HP_image_transform  Not Supported
GL_HP_occlusion_test  Not Supported
GL_HP_texture_lighting  Not Supported
GL_I3D_argb  Not Supported
GL_I3D_color_clamp  Not Supported
GL_I3D_interlace_read  Not Supported
GL_IBM_clip_check  Not Supported
GL_IBM_cull_vertex  Not Supported
GL_IBM_load_named_matrix  Not Supported
GL_IBM_multi_draw_arrays  Not Supported
GL_IBM_multimode_draw_arrays  Not Supported
GL_IBM_occlusion_cull  Not Supported
GL_IBM_pixel_filter_hint  Not Supported
GL_IBM_rasterpos_clip  Not Supported
GL_IBM_rescale_normal  Not Supported
GL_IBM_static_data  Not Supported
GL_IBM_texture_clamp_nodraw  Not Supported
GL_IBM_texture_mirrored_repeat  Supported
GL_IBM_vertex_array_lists  Not Supported
GL_IBM_YCbCr  Not Supported
GL_IMG_multisampled_render_to_texture  Not Supported
GL_IMG_program_binary  Not Supported
GL_IMG_read_format  Not Supported
GL_IMG_shader_binary  Not Supported
GL_IMG_texture_compression_pvrtc  Not Supported
GL_IMG_texture_env_enhanced_fixed_function  Not Supported
GL_IMG_texture_format_BGRA8888  Not Supported
GL_IMG_user_clip_plane  Not Supported
GL_IMG_vertex_program  Not Supported
GL_INGR_blend_func_separate  Not Supported
GL_INGR_color_clamp  Not Supported
GL_INGR_interlace_read  Not Supported
GL_INGR_multiple_palette  Not Supported
GL_INTEL_compute_shader_lane_shift  Supported
GL_INTEL_fragment_shader_span_sharing  Supported
GL_INTEL_image_serialize  Not Supported
GL_INTEL_map_texture  Supported
GL_INTEL_parallel_arrays  Not Supported
GL_INTEL_performance_queries  Supported
GL_INTEL_texture_scissor  Not Supported
GL_KHR_debug  Supported
GL_KHR_texture_compression_astc_ldr  Not Supported
GL_KTX_buffer_region  Not Supported
GL_MESA_pack_invert  Not Supported
GL_MESA_program_debug  Not Supported
GL_MESA_resize_buffers  Not Supported
GL_MESA_window_pos  Not Supported
GL_MESA_ycbcr_texture  Not Supported
GL_MESAX_texture_stack  Not Supported
GL_MTX_fragment_shader  Not Supported
GL_MTX_precision_dpi  Not Supported
GL_NV_alpha_test  Not Supported
GL_NV_bindless_multi_draw_indirect  Not Supported
GL_NV_bindless_texture  Not Supported
GL_NV_blend_equation_advanced  Not Supported
GL_NV_blend_minmax  Not Supported
GL_NV_blend_square  Supported
GL_NV_centroid_sample  Not Supported
GL_NV_complex_primitives  Not Supported
GL_NV_compute_program5  Not Supported
GL_NV_conditional_render  Supported
GL_NV_copy_depth_to_color  Not Supported
GL_NV_copy_image  Not Supported
GL_NV_coverage_sample  Not Supported
GL_NV_depth_buffer_float  Not Supported
GL_NV_depth_clamp  Not Supported
GL_NV_depth_nonlinear  Not Supported
GL_NV_depth_range_unclamped  Not Supported
GL_NV_draw_buffers  Not Supported
GL_NV_draw_texture  Not Supported
GL_NV_EGL_stream_consumer_external  Not Supported
GL_NV_ES1_1_compatibility  Not Supported
GL_NV_evaluators  Not Supported
GL_NV_explicit_multisample  Not Supported
GL_NV_fbo_color_attachments  Not Supported
GL_NV_fence  Not Supported
GL_NV_float_buffer  Not Supported
GL_NV_fog_distance  Not Supported
GL_NV_fragdepth  Not Supported
GL_NV_fragment_program  Not Supported
GL_NV_fragment_program_option  Not Supported
GL_NV_fragment_program2  Not Supported
GL_NV_fragment_program4  Not Supported
GL_NV_framebuffer_multisample_coverage  Not Supported
GL_NV_framebuffer_multisample_ex  Not Supported
GL_NV_geometry_program4  Not Supported
GL_NV_geometry_shader4  Not Supported
GL_NV_gpu_program_fp64  Not Supported
GL_NV_gpu_program4  Not Supported
GL_NV_gpu_program4_1  Not Supported
GL_NV_gpu_program5  Not Supported
GL_NV_gpu_program5_mem_extended  Not Supported
GL_NV_gpu_shader5  Not Supported
GL_NV_half_float  Not Supported
GL_NV_light_max_exponent  Not Supported
GL_NV_multisample_coverage  Not Supported
GL_NV_multisample_filter_hint  Not Supported
GL_NV_occlusion_query  Not Supported
GL_NV_packed_depth_stencil  Not Supported
GL_NV_parameter_buffer_object  Not Supported
GL_NV_parameter_buffer_object2  Not Supported
GL_NV_path_rendering  Not Supported
GL_NV_pixel_buffer_object  Not Supported
GL_NV_pixel_data_range  Not Supported
GL_NV_point_sprite  Not Supported
GL_NV_present_video  Not Supported
GL_NV_primitive_restart  Supported
GL_NV_read_buffer  Not Supported
GL_NV_read_depth_stencil  Not Supported
GL_NV_register_combiners  Not Supported
GL_NV_register_combiners2  Not Supported
GL_NV_shader_atomic_counters  Not Supported
GL_NV_shader_atomic_float  Not Supported
GL_NV_shader_buffer_load  Not Supported
GL_NV_shader_buffer_store  Not Supported
GL_NV_shader_storage_buffer_object  Not Supported
GL_NV_tessellation_program5  Not Supported
GL_NV_texgen_emboss  Not Supported
GL_NV_texgen_reflection  Supported
GL_NV_texture_barrier  Not Supported
GL_NV_texture_compression_latc  Not Supported
GL_NV_texture_compression_s3tc_update  Not Supported
GL_NV_texture_compression_vtc  Not Supported
GL_NV_texture_env_combine4  Not Supported
GL_NV_texture_expand_normal  Not Supported
GL_NV_texture_lod_clamp  Not Supported
GL_NV_texture_multisample  Not Supported
GL_NV_texture_npot_2D_mipmap  Not Supported
GL_NV_texture_rectangle  Not Supported
GL_NV_texture_shader  Not Supported
GL_NV_texture_shader2  Not Supported
GL_NV_texture_shader3  Not Supported
GL_NV_timer_query  Not Supported
GL_NV_transform_feedback  Not Supported
GL_NV_transform_feedback2  Not Supported
GL_NV_vdpau_interop  Not Supported
GL_NV_vertex_array_range  Not Supported
GL_NV_vertex_array_range2  Not Supported
GL_NV_vertex_attrib_64bit  Not Supported
GL_NV_vertex_attrib_integer_64bit  Not Supported
GL_NV_vertex_buffer_unified_memory  Not Supported
GL_NV_vertex_program  Not Supported
GL_NV_vertex_program1_1  Not Supported
GL_NV_vertex_program2  Not Supported
GL_NV_vertex_program2_option  Not Supported
GL_NV_vertex_program3  Not Supported
GL_NV_vertex_program4  Not Supported
GL_NVX_conditional_render  Not Supported
GL_NVX_flush_hold  Not Supported
GL_NVX_gpu_memory_info  Not Supported
GL_NVX_instanced_arrays  Not Supported
GL_NVX_nvenc_interop  Not Supported
GL_NVX_ycrcb  Not Supported
GL_OES_blend_equation_separate  Not Supported
GL_OES_blend_func_separate  Not Supported
GL_OES_blend_subtract  Not Supported
GL_OES_byte_coordinates  Not Supported
GL_OES_compressed_EAC_R11_signed_texture  Not Supported
GL_OES_compressed_EAC_R11_unsigned_texture  Not Supported
GL_OES_compressed_EAC_RG11_signed_texture  Not Supported
GL_OES_compressed_EAC_RG11_unsigned_texture  Not Supported
GL_OES_compressed_ETC1_RGB8_texture  Not Supported
GL_OES_compressed_ETC2_punchthroughA_RGBA8_texture  Not Supported
GL_OES_compressed_ETC2_punchthroughA_sRGB8_alpha_texture  Not Supported
GL_OES_compressed_ETC2_RGB8_texture  Not Supported
GL_OES_compressed_ETC2_RGBA8_texture  Not Supported
GL_OES_compressed_ETC2_sRGB8_alpha8_texture  Not Supported
GL_OES_compressed_ETC2_sRGB8_texture  Not Supported
GL_OES_compressed_paletted_texture  Not Supported
GL_OES_conditional_query  Not Supported
GL_OES_depth_texture  Not Supported
GL_OES_depth24  Not Supported
GL_OES_depth32  Not Supported
GL_OES_draw_texture  Not Supported
GL_OES_EGL_image  Not Supported
GL_OES_EGL_image_external  Not Supported
GL_OES_EGL_sync  Not Supported
GL_OES_element_index_uint  Not Supported
GL_OES_extended_matrix_palette  Not Supported
GL_OES_fbo_render_mipmap  Not Supported
GL_OES_fixed_point  Not Supported
GL_OES_fragment_precision_high  Not Supported
GL_OES_framebuffer_object  Not Supported
GL_OES_get_program_binary  Not Supported
GL_OES_mapbuffer  Not Supported
GL_OES_matrix_get  Not Supported
GL_OES_matrix_palette  Not Supported
GL_OES_packed_depth_stencil  Not Supported
GL_OES_point_size_array  Not Supported
GL_OES_point_sprite  Not Supported
GL_OES_query_matrix  Not Supported
GL_OES_read_format  Not Supported
GL_OES_required_internalformat  Not Supported
GL_OES_rgb8_rgba8  Not Supported
GL_OES_single_precision  Not Supported
GL_OES_standard_derivatives  Not Supported
GL_OES_stencil_wrap  Not Supported
GL_OES_stencil1  Not Supported
GL_OES_stencil4  Not Supported
GL_OES_stencil8  Not Supported
GL_OES_surfaceless_context  Not Supported
GL_OES_texture_3D  Not Supported
GL_OES_texture_cube_map  Not Supported
GL_OES_texture_env_crossbar  Not Supported
GL_OES_texture_float  Not Supported
GL_OES_texture_float_linear  Not Supported
GL_OES_texture_half_float  Not Supported
GL_OES_texture_half_float_linear  Not Supported
GL_OES_texture_mirrored_repeat  Not Supported
GL_OES_texture_npot  Not Supported
GL_OES_vertex_array_object  Not Supported
GL_OES_vertex_half_float  Not Supported
GL_OES_vertex_type_10_10_10_2  Not Supported
GL_OML_interlace  Not Supported
GL_OML_resample  Not Supported
GL_OML_subsample  Not Supported
GL_PGI_misc_hints  Not Supported
GL_PGI_vertex_hints  Not Supported
GL_QCOM_alpha_test  Not Supported
GL_QCOM_binning_control  Not Supported
GL_QCOM_driver_control  Not Supported
GL_QCOM_extended_get  Not Supported
GL_QCOM_extended_get2  Not Supported
GL_QCOM_perfmon_global_mode  Not Supported
GL_QCOM_tiled_rendering  Not Supported
GL_QCOM_writeonly_rendering  Not Supported
GL_REND_screen_coordinates  Not Supported
GL_S3_performance_analyzer  Not Supported
GL_S3_s3tc  Not Supported
GL_SGI_color_matrix  Not Supported
GL_SGI_color_table  Not Supported
GL_SGI_compiled_vertex_array  Not Supported
GL_SGI_cull_vertex  Not Supported
GL_SGI_index_array_formats  Not Supported
GL_SGI_index_func  Not Supported
GL_SGI_index_material  Not Supported
GL_SGI_index_texture  Not Supported
GL_SGI_make_current_read  Not Supported
GL_SGI_texture_add_env  Not Supported
GL_SGI_texture_color_table  Not Supported
GL_SGI_texture_edge_clamp  Not Supported
GL_SGI_texture_lod  Not Supported
GL_SGIS_color_range  Not Supported
GL_SGIS_detail_texture  Not Supported
GL_SGIS_fog_function  Not Supported
GL_SGIS_generate_mipmap  Supported
GL_SGIS_multisample  Not Supported
GL_SGIS_multitexture  Not Supported
GL_SGIS_pixel_texture  Not Supported
GL_SGIS_point_line_texgen  Not Supported
GL_SGIS_sharpen_texture  Not Supported
GL_SGIS_texture_border_clamp  Not Supported
GL_SGIS_texture_color_mask  Not Supported
GL_SGIS_texture_edge_clamp  Supported
GL_SGIS_texture_filter4  Not Supported
GL_SGIS_texture_lod  Supported
GL_SGIS_texture_select  Not Supported
GL_SGIS_texture4D  Not Supported
GL_SGIX_async  Not Supported
GL_SGIX_async_histogram  Not Supported
GL_SGIX_async_pixel  Not Supported
GL_SGIX_blend_alpha_minmax  Not Supported
GL_SGIX_clipmap  Not Supported
GL_SGIX_convolution_accuracy  Not Supported
GL_SGIX_depth_pass_instrument  Not Supported
GL_SGIX_depth_texture  Not Supported
GL_SGIX_flush_raster  Not Supported
GL_SGIX_fog_offset  Not Supported
GL_SGIX_fog_texture  Not Supported
GL_SGIX_fragment_specular_lighting  Not Supported
GL_SGIX_framezoom  Not Supported
GL_SGIX_instruments  Not Supported
GL_SGIX_interlace  Not Supported
GL_SGIX_ir_instrument1  Not Supported
GL_SGIX_list_priority  Not Supported
GL_SGIX_pbuffer  Not Supported
GL_SGIX_pixel_texture  Not Supported
GL_SGIX_pixel_texture_bits  Not Supported
GL_SGIX_reference_plane  Not Supported
GL_SGIX_resample  Not Supported
GL_SGIX_shadow  Not Supported
GL_SGIX_shadow_ambient  Not Supported
GL_SGIX_sprite  Not Supported
GL_SGIX_subsample  Not Supported
GL_SGIX_tag_sample_buffer  Not Supported
GL_SGIX_texture_add_env  Not Supported
GL_SGIX_texture_coordinate_clamp  Not Supported
GL_SGIX_texture_lod_bias  Not Supported
GL_SGIX_texture_multi_buffer  Not Supported
GL_SGIX_texture_range  Not Supported
GL_SGIX_texture_scale_bias  Not Supported
GL_SGIX_vertex_preclip  Not Supported
GL_SGIX_vertex_preclip_hint  Not Supported
GL_SGIX_ycrcb  Not Supported
GL_SGIX_ycrcb_subsample  Not Supported
GL_SUN_convolution_border_modes  Not Supported
GL_SUN_global_alpha  Not Supported
GL_SUN_mesh_array  Not Supported
GL_SUN_multi_draw_arrays  Supported
GL_SUN_read_video_pixels  Not Supported
GL_SUN_slice_accum  Not Supported
GL_SUN_triangle_list  Not Supported
GL_SUN_vertex  Not Supported
GL_SUNX_constant_data  Not Supported
GL_VIV_shader_binary  Not Supported
GL_WGL_ARB_extensions_string  Not Supported
GL_WGL_EXT_extensions_string  Not Supported
GL_WGL_EXT_swap_control  Not Supported
GL_WIN_phong_shading  Not Supported
GL_WIN_specular_fog  Not Supported
GL_WIN_swap_hint  Supported
GLU_EXT_nurbs_tessellator  Not Supported
GLU_EXT_object_space_tess  Not Supported
GLU_SGI_filter4_parameters  Not Supported
GLX_ARB_create_context  Not Supported
GLX_ARB_fbconfig_float  Not Supported
GLX_ARB_framebuffer_sRGB  Not Supported
GLX_ARB_get_proc_address  Not Supported
GLX_ARB_multisample  Not Supported
GLX_EXT_fbconfig_packed_float  Not Supported
GLX_EXT_framebuffer_sRGB  Not Supported
GLX_EXT_import_context  Not Supported
GLX_EXT_scene_marker  Not Supported
GLX_EXT_texture_from_pixmap  Not Supported
GLX_EXT_visual_info  Not Supported
GLX_EXT_visual_rating  Not Supported
GLX_MESA_agp_offset  Not Supported
GLX_MESA_copy_sub_buffer  Not Supported
GLX_MESA_pixmap_colormap  Not Supported
GLX_MESA_release_buffers  Not Supported
GLX_MESA_set_3dfx_mode  Not Supported
GLX_NV_present_video  Not Supported
GLX_NV_swap_group  Not Supported
GLX_NV_video_output  Not Supported
GLX_OML_interlace  Not Supported
GLX_OML_swap_method  Not Supported
GLX_OML_sync_control  Not Supported
GLX_SGI_cushion  Not Supported
GLX_SGI_make_current_read  Not Supported
GLX_SGI_swap_control  Not Supported
GLX_SGI_video_sync  Not Supported
GLX_SGIS_blended_overlay  Not Supported
GLX_SGIS_color_range  Not Supported
GLX_SGIS_multisample  Not Supported
GLX_SGIX_dm_buffer  Not Supported
GLX_SGIX_fbconfig  Not Supported
GLX_SGIX_hyperpipe  Not Supported
GLX_SGIX_pbuffer  Not Supported
GLX_SGIX_swap_barrier  Not Supported
GLX_SGIX_swap_group  Not Supported
GLX_SGIX_video_resize  Not Supported
GLX_SGIX_video_source  Not Supported
GLX_SGIX_visual_select_group  Not Supported
GLX_SUN_get_transparent_index  Not Supported
GLX_SUN_video_resize  Not Supported
WGL_3DFX_gamma_control  Not Supported
WGL_3DFX_multisample  Not Supported
WGL_3DL_stereo_control  Not Supported
WGL_AMD_gpu_association  Not Supported
WGL_AMDX_gpu_association  Not Supported
WGL_ARB_buffer_region  Supported
WGL_ARB_create_context  Supported
WGL_ARB_create_context_profile  Supported
WGL_ARB_create_context_robustness  Supported
WGL_ARB_extensions_string  Supported
WGL_ARB_framebuffer_sRGB  Supported
WGL_ARB_make_current_read  Supported
WGL_ARB_multisample  Supported
WGL_ARB_pbuffer  Supported
WGL_ARB_pixel_format  Supported
WGL_ARB_pixel_format_float  Supported
WGL_ARB_render_texture  Not Supported
WGL_ATI_pbuffer_memory_hint  Not Supported
WGL_ATI_pixel_format_float  Not Supported
WGL_ATI_render_texture_rectangle  Not Supported
WGL_EXT_buffer_region  Not Supported
WGL_EXT_create_context_es_profile  Supported
WGL_EXT_create_context_es2_profile  Supported
WGL_EXT_depth_float  Supported
WGL_EXT_display_color_table  Not Supported
WGL_EXT_extensions_string  Supported
WGL_EXT_framebuffer_sRGB  Not Supported
WGL_EXT_framebuffer_sRGBWGL_ARB_create_context  Not Supported
WGL_EXT_gamma_control  Not Supported
WGL_EXT_make_current_read  Not Supported
WGL_EXT_multisample  Not Supported
WGL_EXT_pbuffer  Not Supported
WGL_EXT_pixel_format  Not Supported
WGL_EXT_pixel_format_packed_float  Supported
WGL_EXT_render_texture  Not Supported
WGL_EXT_swap_control  Supported
WGL_EXT_swap_control_tear  Supported
WGL_EXT_swap_interval  Not Supported
WGL_I3D_digital_video_control  Not Supported
WGL_I3D_gamma  Not Supported
WGL_I3D_genlock  Not Supported
WGL_I3D_image_buffer  Not Supported
WGL_I3D_swap_frame_lock  Not Supported
WGL_I3D_swap_frame_usage  Not Supported
WGL_MTX_video_preview  Not Supported
WGL_NV_copy_image  Not Supported
WGL_NV_delay_before_swap  Not Supported
WGL_NV_DX_interop  Supported
WGL_NV_DX_interop2  Not Supported
WGL_NV_float_buffer  Not Supported
WGL_NV_gpu_affinity  Not Supported
WGL_NV_multisample_coverage  Not Supported
WGL_NV_present_video  Not Supported
WGL_NV_render_depth_texture  Not Supported
WGL_NV_render_texture_rectangle  Not Supported
WGL_NV_swap_group  Not Supported
WGL_NV_vertex_array_range  Not Supported
WGL_NV_video_output  Not Supported
WGL_NVX_DX_interop  Not Supported
WGL_OML_sync_control  Not Supported
WGL_S3_cl_sharingWGL_ARB_create_context_profile  Not Supported
 
Supported Compressed Texture Formats:
RGB DXT1  Supported
RGBA DXT1  Supported
RGBA DXT3  Supported
RGBA DXT5  Supported
RGB FXT1  Supported
RGBA FXT1  Supported
3Dc  Not Supported
 
Video Adapter Manufacturer:
Company Name  Intel Corporation
Product Information  http://www.intel.com/products/chipsets
Driver Download  http://support.intel.com/support/graphics
Driver Update  http://www.aida64.com/driver-updates


GPGPU

 
[ Direct3D: Intel(R) HD Graphics ]
 
Device Properties:
Device Name  Intel(R) HD Graphics
Driver Name  igdumdim32.dll
Driver Version  10.18.10.3286
Shader Model  SM 5.0
Max Threads  1024
Multiple UAV Access  8 UAVs
Thread Dispatch  3D
Thread Local Storage  32 KB
 
Device Features:
10-bit Precision Floating-Point  Not Supported
16-bit Precision Floating-Point  Not Supported
Append/Consume Buffers  Supported
Atomic Operations  Supported
Double-Precision Floating-Point  Supported
Gather4  Supported
Indirect Compute Dispatch  Supported
Map On Default Buffers  Supported
 
Device Manufacturer:
Company Name  Intel Corporation
Product Information  http://www.intel.com/products/chipsets
Driver Download  http://support.intel.com/support/graphics
Driver Update  http://www.aida64.com/driver-updates
 
[ OpenCL: Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz ]
 
OpenCL Properties:
Platform Name  Intel(R) OpenCL
Platform Vendor  Intel(R) Corporation
Platform Version  OpenCL 1.2
Platform Profile  Full
 
Device Properties:
Device Name  Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz
Device Type  CPU
Device Vendor  Intel(R) Corporation
Device Version  OpenCL 1.2 (Build 73988)
Device Profile  Full
Driver Version  3.0.0.8453
OpenCL C Version  OpenCL C 1.2
Clock Rate  1330 MHz
Compute Units  4
Address Space Size  32-bit
Max 2D Image Size  16384 x 16384
Max 3D Image Size  2048 x 2048 x 2048
Max Image Array Size  2048
Max Image Buffer Size  31674112
Max Samplers  480
Max Work-Item Size  1024 x 1024 x 1024
Max Work-Group Size  1024
Max Argument Size  3840 bytes
Max Constant Buffer Size  128 KB
Max Constant Arguments  480
Max Printf Buffer Size  1 MB
Native ISA Vector Widths  char16, short8, int2, float4
Preferred Native Vector Widths  char1, short1, int1, long1, float1, double1
Profiling Timer Resolution  767 ns
OpenCL DLL  opencl.dll (1.2.11.0)
 
Memory Properties:
Global Memory  1933 MB
Global Memory Cache  1024 KB (Read/Write, 64-byte line)
Local Memory  32 KB
Max Memory Object Allocation Size  494908 KB
Memory Base Address Alignment  1024-bit
Min Data Type Alignment  128 bytes
 
OpenCL Compliancy:
OpenCL 1.1  Yes (100%)
OpenCL 1.2  Yes (100%)
OpenCL 2.0  No (62%)
 
Device Features:
Command-Queue Out Of Order Execution  Enabled
Command-Queue Profiling  Enabled
Compiler Available  Yes
Error Correction  Not Supported
Images  Supported
Kernel Execution  Supported
Linker Available  Yes
Little-Endian Device  Yes
Native Kernel Execution  Supported
SVM Atomics  Not Supported
SVM Coarse Grain Buffer  Not Supported
SVM Fine Grain Buffer  Not Supported
SVM Fine Grain System  Not Supported
Thread Trace  Not Supported
Unified Memory  Yes
 
Half-Precision Floating-Point Capabilities:
Correctly Rounded Divide and Sqrt  Not Supported
Denorms  Not Supported
IEEE754-2008 FMA  Not Supported
INF and NaNs  Not Supported
Rounding to Infinity  Not Supported
Rounding to Nearest Even  Not Supported
Rounding to Zero  Not Supported
Software Basic Floating-Point Operations  No
 
Single-Precision Floating-Point Capabilities:
Correctly Rounded Divide and Sqrt  Not Supported
Denorms  Supported
IEEE754-2008 FMA  Not Supported
INF and NaNs  Supported
Rounding to Infinity  Not Supported
Rounding to Nearest Even  Supported
Rounding to Zero  Not Supported
Software Basic Floating-Point Operations  No
 
Double-Precision Floating-Point Capabilities:
Correctly Rounded Divide and Sqrt  Not Supported
Denorms  Not Supported
IEEE754-2008 FMA  Not Supported
INF and NaNs  Not Supported
Rounding to Infinity  Not Supported
Rounding to Nearest Even  Not Supported
Rounding to Zero  Not Supported
Software Basic Floating-Point Operations  No
 
Device Extensions:
Total / Supported Extensions  72 / 13
cl_amd_bus_addressable_memory  Not Supported
cl_amd_c1x_atomics  Not Supported
cl_amd_compile_options  Not Supported
cl_amd_d3d10_interop  Not Supported
cl_amd_d3d9_interop  Not Supported
cl_amd_device_attribute_query  Not Supported
cl_amd_device_board_name  Not Supported
cl_amd_device_memory_flags  Not Supported
cl_amd_device_persistent_memory  Not Supported
cl_amd_device_profiling_timer_offset  Not Supported
cl_amd_device_topology  Not Supported
cl_amd_event_callback  Not Supported
cl_amd_fp64  Not Supported
cl_amd_image2d_from_buffer_read_only  Not Supported
cl_amd_media_ops  Not Supported
cl_amd_media_ops2  Not Supported
cl_amd_offline_devices  Not Supported
cl_amd_popcnt  Not Supported
cl_amd_predefined_macros  Not Supported
cl_amd_printf  Not Supported
cl_amd_vec3  Not Supported
cl_apple_contextloggingfunctions  Not Supported
cl_apple_gl_sharing  Not Supported
cl_apple_setmemobjectdestructor  Not Supported
cl_ext_atomic_counters_32  Not Supported
cl_ext_atomic_counters_64  Not Supported
cl_ext_device_fission  Supported
cl_ext_migrate_memobject  Not Supported
cl_intel_accelerator  Not Supported
cl_intel_device_partition_by_names  Not Supported
cl_intel_dx9_media_sharing  Supported
cl_intel_exec_by_local_thread  Supported
cl_intel_motion_estimation  Not Supported
cl_intel_printf  Supported
cl_intel_thread_local_exec  Not Supported
cl_khr_3d_image_writes  Not Supported
cl_khr_byte_addressable_store  Supported
cl_khr_context_abort  Not Supported
cl_khr_d3d10_sharing  Not Supported
cl_khr_d3d11_sharing  Supported
cl_khr_depth_images  Not Supported
cl_khr_dx9_media_sharing  Supported
cl_khr_egl_event  Not Supported
cl_khr_egl_image  Not Supported
cl_khr_fp16  Not Supported
cl_khr_fp64  Not Supported
cl_khr_gl_depth_images  Not Supported
cl_khr_gl_event  Not Supported
cl_khr_gl_msaa_sharing  Not Supported
cl_khr_gl_sharing  Supported
cl_khr_global_int32_base_atomics  Supported
cl_khr_global_int32_extended_atomics  Supported
cl_khr_icd  Supported
cl_khr_image2d_from_buffer  Not Supported
cl_khr_initialize_memory  Not Supported
cl_khr_int64_base_atomics  Not Supported
cl_khr_int64_extended_atomics  Not Supported
cl_khr_local_int32_base_atomics  Supported
cl_khr_local_int32_extended_atomics  Supported
cl_khr_mipmap_image  Not Supported
cl_khr_mipmap_image_writes  Not Supported
cl_khr_select_fprounding_mode  Not Supported
cl_khr_spir  Not Supported
cl_khr_srgb_image_writes  Not Supported
cl_khr_subgroups  Not Supported
cl_khr_terminate_context  Not Supported
cl_nv_compiler_options  Not Supported
cl_nv_d3d10_sharing  Not Supported
cl_nv_d3d11_sharing  Not Supported
cl_nv_d3d9_sharing  Not Supported
cl_nv_device_attribute_query  Not Supported
cl_nv_pragma_unroll  Not Supported
 
Device Manufacturer:
Company Name  Intel Corporation
Product Information  http://www.intel.com/products/chipsets
Driver Download  http://support.intel.com/support/graphics
Driver Update  http://www.aida64.com/driver-updates
 
[ OpenCL: Intel(R) HD Graphics ]
 
OpenCL Properties:
Platform Name  Intel(R) OpenCL
Platform Vendor  Intel(R) Corporation
Platform Version  OpenCL 1.2
Platform Profile  Full
 
Device Properties:
Device Name  Intel(R) HD Graphics
Device Type  GPU
Device Vendor  Intel(R) Corporation
Device Version  OpenCL 1.2
Device Profile  Full
Driver Version  10.18.10.3286
OpenCL C Version  OpenCL C 1.2
Supported Built-In Kernels  block_motion_estimate_intel
Clock Rate  200 MHz
Compute Units / Cores  4 / 16
Address Space Size  64-bit
Max 2D Image Size  16384 x 16384
Max 3D Image Size  2048 x 2048 x 2048
Max Image Array Size  2048
Max Image Buffer Size  15705984
Max Samplers  16
Max Work-Item Size  256 x 256 x 256
Max Work-Group Size  256
Max Argument Size  1 KB
Max Constant Buffer Size  64 KB
Max Constant Arguments  8
Max Printf Buffer Size  4 MB
Native ISA Vector Widths  char1, short1, int1, half1, float1
Preferred Native Vector Widths  char1, short1, int1, long1, half1, float1
Profiling Timer Resolution  80 ns
OpenCL DLL  opencl.dll (1.2.11.0)
 
Memory Properties:
Global Memory  958 MB
Global Memory Cache  2048 KB (Read/Write, 64-byte line)
Local Memory  64 KB
Max Memory Object Allocation Size  245406 KB
Memory Base Address Alignment  1024-bit
Min Data Type Alignment  128 bytes
Image Row Pitch Alignment  16 pixels
Image Base Address Alignment  16 pixels
 
OpenCL Compliancy:
OpenCL 1.1  Yes (100%)
OpenCL 1.2  Yes (100%)
OpenCL 2.0  Yes (100%)
 
Device Features:
Command-Queue Out Of Order Execution  Disabled
Command-Queue Profiling  Enabled
Compiler Available  Yes
Error Correction  Not Supported
Images  Supported
Kernel Execution  Supported
Linker Available  Yes
Little-Endian Device  Yes
Native Kernel Execution  Not Supported
SVM Atomics  Not Supported
SVM Coarse Grain Buffer  Not Supported
SVM Fine Grain Buffer  Not Supported
SVM Fine Grain System  Not Supported
Thread Trace  Not Supported
Unified Memory  Yes
 
Half-Precision Floating-Point Capabilities:
Correctly Rounded Divide and Sqrt  Not Supported
Denorms  Not Supported
IEEE754-2008 FMA  Not Supported
INF and NaNs  Not Supported
Rounding to Infinity  Not Supported
Rounding to Nearest Even  Not Supported
Rounding to Zero  Not Supported
Software Basic Floating-Point Operations  No
 
Single-Precision Floating-Point Capabilities:
Correctly Rounded Divide and Sqrt  Supported
Denorms  Not Supported
IEEE754-2008 FMA  Not Supported
INF and NaNs  Supported
Rounding to Infinity  Supported
Rounding to Nearest Even  Supported
Rounding to Zero  Supported
Software Basic Floating-Point Operations  No
 
Double-Precision Floating-Point Capabilities:
Correctly Rounded Divide and Sqrt  Not Supported
Denorms  Not Supported
IEEE754-2008 FMA  Not Supported
INF and NaNs  Not Supported
Rounding to Infinity  Not Supported
Rounding to Nearest Even  Not Supported
Rounding to Zero  Not Supported
Software Basic Floating-Point Operations  No
 
Device Extensions:
Total / Supported Extensions  72 / 19
cl_amd_bus_addressable_memory  Not Supported
cl_amd_c1x_atomics  Not Supported
cl_amd_compile_options  Not Supported
cl_amd_d3d10_interop  Not Supported
cl_amd_d3d9_interop  Not Supported
cl_amd_device_attribute_query  Not Supported
cl_amd_device_board_name  Not Supported
cl_amd_device_memory_flags  Not Supported
cl_amd_device_persistent_memory  Not Supported
cl_amd_device_profiling_timer_offset  Not Supported
cl_amd_device_topology  Not Supported
cl_amd_event_callback  Not Supported
cl_amd_fp64  Not Supported
cl_amd_image2d_from_buffer_read_only  Not Supported
cl_amd_media_ops  Not Supported
cl_amd_media_ops2  Not Supported
cl_amd_offline_devices  Not Supported
cl_amd_popcnt  Not Supported
cl_amd_predefined_macros  Not Supported
cl_amd_printf  Not Supported
cl_amd_vec3  Not Supported
cl_apple_contextloggingfunctions  Not Supported
cl_apple_gl_sharing  Not Supported
cl_apple_setmemobjectdestructor  Not Supported
cl_ext_atomic_counters_32  Not Supported
cl_ext_atomic_counters_64  Not Supported
cl_ext_device_fission  Not Supported
cl_ext_migrate_memobject  Not Supported
cl_intel_accelerator  Supported
cl_intel_device_partition_by_names  Not Supported
cl_intel_dx9_media_sharing  Supported
cl_intel_exec_by_local_thread  Not Supported
cl_intel_motion_estimation  Supported
cl_intel_printf  Not Supported
cl_intel_thread_local_exec  Not Supported
cl_khr_3d_image_writes  Supported
cl_khr_byte_addressable_store  Supported
cl_khr_context_abort  Not Supported
cl_khr_d3d10_sharing  Supported
cl_khr_d3d11_sharing  Supported
cl_khr_depth_images  Supported
cl_khr_dx9_media_sharing  Supported
cl_khr_egl_event  Not Supported
cl_khr_egl_image  Not Supported
cl_khr_fp16  Not Supported
cl_khr_fp64  Not Supported
cl_khr_gl_depth_images  Supported
cl_khr_gl_event  Supported
cl_khr_gl_msaa_sharing  Supported
cl_khr_gl_sharing  Supported
cl_khr_global_int32_base_atomics  Supported
cl_khr_global_int32_extended_atomics  Supported
cl_khr_icd  Supported
cl_khr_image2d_from_buffer  Supported
cl_khr_initialize_memory  Not Supported
cl_khr_int64_base_atomics  Not Supported
cl_khr_int64_extended_atomics  Not Supported
cl_khr_local_int32_base_atomics  Supported
cl_khr_local_int32_extended_atomics  Supported
cl_khr_mipmap_image  Not Supported
cl_khr_mipmap_image_writes  Not Supported
cl_khr_select_fprounding_mode  Not Supported
cl_khr_spir  Not Supported
cl_khr_srgb_image_writes  Not Supported
cl_khr_subgroups  Not Supported
cl_khr_terminate_context  Not Supported
cl_nv_compiler_options  Not Supported
cl_nv_d3d10_sharing  Not Supported
cl_nv_d3d11_sharing  Not Supported
cl_nv_d3d9_sharing  Not Supported
cl_nv_device_attribute_query  Not Supported
cl_nv_pragma_unroll  Not Supported
 
Device Manufacturer:
Company Name  Intel Corporation
Product Information  http://www.intel.com/products/chipsets
Driver Download  http://support.intel.com/support/graphics
Driver Update  http://www.aida64.com/driver-updates


Fonts

 
Font Family  Type  Style  Character Set  Char. Size  Char. Weight
@Batang  Roman  Regular  Baltic  16 x 32  40 %
@Batang  Roman  Regular  Central European  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@Batang  Roman  Regular  Greek  16 x 32  40 %
@Batang  Roman  Regular  Hangul  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@Batang  Roman  Regular  Western  16 x 32  40 %
@BatangChe  Modern  Regular  Baltic  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@BatangChe  Modern  Regular  Cyrillic  16 x 32  40 %
@BatangChe  Modern  Regular  Greek  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@BatangChe  Modern  Regular  Turkish  16 x 32  40 %
@BatangChe  Modern  Regular  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@DFKai-SB  Script  Regular  Western  16 x 32  40 %
@Dotum  Swiss  Regular  Baltic  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@Dotum  Swiss  Regular  Cyrillic  16 x 32  40 %
@Dotum  Swiss  Regular  Greek  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@Dotum  Swiss  Regular  Turkish  16 x 32  40 %
@Dotum  Swiss  Regular  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@DotumChe  Modern  Regular  Central European  16 x 32  40 %
@DotumChe  Modern  Regular  Cyrillic  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@DotumChe  Modern  Regular  Hangul  16 x 32  40 %
@DotumChe  Modern  Regular  Turkish  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@FangSong  Modern  Normál  CHINESE_GB2312  16 x 32  40 %
@FangSong  Modern  Normál  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@Gulim  Swiss  Regular  Central European  16 x 32  40 %
@Gulim  Swiss  Regular  Cyrillic  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@Gulim  Swiss  Regular  Hangul  16 x 32  40 %
@Gulim  Swiss  Regular  Turkish  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@GulimChe  Modern  Regular  Baltic  16 x 32  40 %
@GulimChe  Modern  Regular  Central European  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@GulimChe  Modern  Regular  Greek  16 x 32  40 %
@GulimChe  Modern  Regular  Hangul  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@GulimChe  Modern  Regular  Western  16 x 32  40 %
@Gungsuh  Roman  Regular  Baltic  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@Gungsuh  Roman  Regular  Cyrillic  16 x 32  40 %
@Gungsuh  Roman  Regular  Greek  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@Gungsuh  Roman  Regular  Turkish  16 x 32  40 %
@Gungsuh  Roman  Regular  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@GungsuhChe  Modern  Regular  Central European  16 x 32  40 %
@GungsuhChe  Modern  Regular  Cyrillic  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@GungsuhChe  Modern  Regular  Hangul  16 x 32  40 %
@GungsuhChe  Modern  Regular  Turkish  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@KaiTi  Modern  Normál  CHINESE_GB2312  16 x 32  40 %
@KaiTi  Modern  Normál  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 43  40 %
@Malgun Gothic  Swiss  Regular  Western  15 x 43  40 %
@Meiryo UI  Swiss  Normál  Baltic  17 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 41  40 %
@Meiryo UI  Swiss  Normál  Cyrillic  17 x 41  40 %
@Meiryo UI  Swiss  Normál  Greek  17 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 41  40 %
@Meiryo UI  Swiss  Normál  Turkish  17 x 41  40 %
@Meiryo UI  Swiss  Normál  Western  17 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 48  40 %
@Meiryo  Swiss  Normál  Central European  31 x 48  40 %
@Meiryo  Swiss  Normál  Cyrillic  31 x 48  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 48  40 %
@Meiryo  Swiss  Normál  Japanese  31 x 48  40 %
@Meiryo  Swiss  Normál  Turkish  31 x 48  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 48  40 %
@Microsoft JhengHei Light  Swiss  Regular  Baltic  32 x 43  29 %
@Microsoft JhengHei Light  Swiss  Regular  Central European  32 x 43  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  32 x 43  29 %
@Microsoft JhengHei Light  Swiss  Regular  CHINESE_GB2312  32 x 43  29 %
@Microsoft JhengHei Light  Swiss  Regular  Cyrillic  32 x 43  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  32 x 43  29 %
@Microsoft JhengHei Light  Swiss  Regular  Hangul(Johab)  32 x 43  29 %
@Microsoft JhengHei Light  Swiss  Regular  Hangul  32 x 43  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  32 x 43  29 %
@Microsoft JhengHei Light  Swiss  Regular  Japanese  32 x 43  29 %
@Microsoft JhengHei Light  Swiss  Regular  Turkish  32 x 43  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  32 x 43  29 %
@Microsoft JhengHei Light  Swiss  Regular  Western  32 x 43  29 %
@Microsoft JhengHei UI Light  Swiss  Regular  Baltic  32 x 41  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  32 x 41  29 %
@Microsoft JhengHei UI Light  Swiss  Regular  CHINESE_BIG5  32 x 41  29 %
@Microsoft JhengHei UI Light  Swiss  Regular  CHINESE_GB2312  32 x 41  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  32 x 41  29 %
@Microsoft JhengHei UI Light  Swiss  Regular  Greek  32 x 41  29 %
@Microsoft JhengHei UI Light  Swiss  Regular  Hangul(Johab)  32 x 41  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  32 x 41  29 %
@Microsoft JhengHei UI Light  Swiss  Regular  Hebrew  32 x 41  29 %
@Microsoft JhengHei UI Light  Swiss  Regular  Japanese  32 x 41  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  32 x 41  29 %
@Microsoft JhengHei UI Light  Swiss  Regular  Vietnamese  32 x 41  29 %
@Microsoft JhengHei UI Light  Swiss  Regular  Western  32 x 41  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 41  40 %
@Microsoft JhengHei UI  Swiss  Normál  Greek  15 x 41  40 %
@Microsoft JhengHei UI  Swiss  Normál  Western  15 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 43  40 %
@Microsoft JhengHei  Swiss  Normál  Greek  15 x 43  40 %
@Microsoft JhengHei  Swiss  Normál  Western  15 x 43  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 41  29 %
@Microsoft YaHei Light  Swiss  Regular  CHINESE_GB2312  15 x 41  29 %
@Microsoft YaHei Light  Swiss  Regular  Cyrillic  15 x 41  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 41  29 %
@Microsoft YaHei Light  Swiss  Regular  Western  15 x 41  29 %
@Microsoft YaHei UI Light  Swiss  Regular  Central European  15 x 42  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 42  29 %
@Microsoft YaHei UI Light  Swiss  Regular  Cyrillic  15 x 42  29 %
@Microsoft YaHei UI Light  Swiss  Regular  Greek  15 x 42  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 42  29 %
@Microsoft YaHei UI  Swiss  Normál  Central European  15 x 41  40 %
@Microsoft YaHei UI  Swiss  Normál  CHINESE_GB2312  15 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 41  40 %
@Microsoft YaHei UI  Swiss  Normál  Greek  15 x 41  40 %
@Microsoft YaHei UI  Swiss  Normál  Turkish  15 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 41  40 %
@Microsoft YaHei  Swiss  Normál  Central European  15 x 42  40 %
@Microsoft YaHei  Swiss  Normál  CHINESE_GB2312  15 x 42  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 42  40 %
@Microsoft YaHei  Swiss  Normál  Greek  15 x 42  40 %
@Microsoft YaHei  Swiss  Normál  Turkish  15 x 42  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 42  40 %
@MingLiU_HKSCS  Roman  Regular  CHINESE_BIG5  16 x 32  40 %
@MingLiU_HKSCS  Roman  Regular  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@MingLiU_HKSCS-ExtB  Roman  Regular  Western  16 x 32  40 %
@MingLiU  Modern  Regular  CHINESE_BIG5  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@MingLiU-ExtB  Roman  Regular  CHINESE_BIG5  16 x 32  40 %
@MingLiU-ExtB  Roman  Regular  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@MS Gothic  Modern  Regular  Central European  16 x 32  40 %
@MS Gothic  Modern  Regular  Cyrillic  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@MS Gothic  Modern  Regular  Japanese  16 x 32  40 %
@MS Gothic  Modern  Regular  Turkish  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@MS Mincho  Modern  Regular  Baltic  16 x 32  40 %
@MS Mincho  Modern  Regular  Central European  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@MS Mincho  Modern  Regular  Greek  16 x 32  40 %
@MS Mincho  Modern  Regular  Japanese  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@MS Mincho  Modern  Regular  Western  16 x 32  40 %
@MS PGothic  Swiss  Regular  Baltic  13 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 32  40 %
@MS PGothic  Swiss  Regular  Cyrillic  13 x 32  40 %
@MS PGothic  Swiss  Regular  Greek  13 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 32  40 %
@MS PGothic  Swiss  Regular  Turkish  13 x 32  40 %
@MS PGothic  Swiss  Regular  Western  13 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 32  40 %
@MS PMincho  Roman  Regular  Central European  13 x 32  40 %
@MS PMincho  Roman  Regular  Cyrillic  13 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 32  40 %
@MS PMincho  Roman  Regular  Japanese  13 x 32  40 %
@MS PMincho  Roman  Regular  Turkish  13 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 32  40 %
@MS UI Gothic  Swiss  Regular  Baltic  13 x 32  40 %
@MS UI Gothic  Swiss  Regular  Central European  13 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 32  40 %
@MS UI Gothic  Swiss  Regular  Greek  13 x 32  40 %
@MS UI Gothic  Swiss  Regular  Japanese  13 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 32  40 %
@MS UI Gothic  Swiss  Regular  Western  13 x 32  40 %
@NSimSun  Modern  Regular  CHINESE_GB2312  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@PMingLiU  Roman  Regular  CHINESE_BIG5  16 x 32  40 %
@PMingLiU  Roman  Regular  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@PMingLiU-ExtB  Roman  Regular  Western  16 x 32  40 %
@SimHei  Modern  Normál  CHINESE_GB2312  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@SimSun  Special  Regular  CHINESE_GB2312  16 x 32  40 %
@SimSun  Special  Regular  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
@SimSun-ExtB  Modern  Normál  Western  16 x 32  40 %
@Yu Gothic Light  Swiss  Regular  Baltic  31 x 41  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  30 %
@Yu Gothic Light  Swiss  Regular  Cyrillic  31 x 41  30 %
@Yu Gothic Light  Swiss  Regular  Greek  31 x 41  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  30 %
@Yu Gothic Light  Swiss  Regular  Turkish  31 x 41  30 %
@Yu Gothic Light  Swiss  Regular  Western  31 x 41  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  40 %
@Yu Gothic  Swiss  Regular  Central European  31 x 41  40 %
@Yu Gothic  Swiss  Regular  Cyrillic  31 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  40 %
@Yu Gothic  Swiss  Regular  Japanese  31 x 41  40 %
@Yu Gothic  Swiss  Regular  Turkish  31 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  40 %
@Yu Mincho Demibold  Roman  Bold  Baltic  31 x 41  60 %
@Yu Mincho Demibold  Roman  Bold  Central European  31 x 41  60 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  60 %
@Yu Mincho Demibold  Roman  Bold  Greek  31 x 41  60 %
@Yu Mincho Demibold  Roman  Bold  Japanese  31 x 41  60 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  60 %
@Yu Mincho Demibold  Roman  Bold  Western  31 x 41  60 %
@Yu Mincho Light  Roman  Regular  Baltic  31 x 41  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  30 %
@Yu Mincho Light  Roman  Regular  Cyrillic  31 x 41  30 %
@Yu Mincho Light  Roman  Regular  Greek  31 x 41  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  30 %
@Yu Mincho Light  Roman  Regular  Turkish  31 x 41  30 %
@Yu Mincho Light  Roman  Regular  Western  31 x 41  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  40 %
@Yu Mincho  Roman  Regular  Central European  31 x 41  40 %
@Yu Mincho  Roman  Regular  Cyrillic  31 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  40 %
@Yu Mincho  Roman  Regular  Japanese  31 x 41  40 %
@Yu Mincho  Roman  Regular  Turkish  31 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  40 %
Aharoni  Special  Félkövér  Hebrew  15 x 32  70 %
Aharoni  Special  Félkövér  Western  15 x 32  70 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 56  40 %
Aldhabi  Special  Regular  Western  16 x 56  40 %
Andalus  Roman  Normál  Arabic  15 x 49  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 49  40 %
Angsana New  Roman  Normál  Thai  8 x 43  40 %
Angsana New  Roman  Normál  Western  8 x 43  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  8 x 43  40 %
AngsanaUPC  Roman  Normál  Western  8 x 43  40 %
Aparajita  Swiss  Normál  Western  16 x 38  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  9 x 36  40 %
Arabic Typesetting  Script  Normál  Baltic  9 x 36  40 %
Arabic Typesetting  Script  Normál  Central European  9 x 36  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  9 x 36  40 %
Arabic Typesetting  Script  Normál  Western  9 x 36  40 %
Arial Black  Swiss  Normál  Baltic  18 x 45  90 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  18 x 45  90 %
Arial Black  Swiss  Normál  Cyrillic  18 x 45  90 %
Arial Black  Swiss  Normál  Greek  18 x 45  90 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  18 x 45  90 %
Arial Black  Swiss  Normál  Western  18 x 45  90 %
Arial  Swiss  Normál  Arabic  14 x 36  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  14 x 36  40 %
Arial  Swiss  Normál  Central European  14 x 36  40 %
Arial  Swiss  Normál  Cyrillic  14 x 36  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  14 x 36  40 %
Arial  Swiss  Normál  Hebrew  14 x 36  40 %
Arial  Swiss  Normál  Turkish  14 x 36  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  14 x 36  40 %
Arial  Swiss  Normál  Western  14 x 36  40 %
Batang  Roman  Regular  Baltic  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
Batang  Roman  Regular  Cyrillic  16 x 32  40 %
Batang  Roman  Regular  Greek  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
Batang  Roman  Regular  Turkish  16 x 32  40 %
Batang  Roman  Regular  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
BatangChe  Modern  Regular  Central European  16 x 32  40 %
BatangChe  Modern  Regular  Cyrillic  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
BatangChe  Modern  Regular  Hangul  16 x 32  40 %
BatangChe  Modern  Regular  Turkish  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
Browallia New  Swiss  Regular  Thai  9 x 40  40 %
Browallia New  Swiss  Regular  Western  9 x 40  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  9 x 40  40 %
BrowalliaUPC  Swiss  Regular  Western  9 x 40  40 %
Calibri Light  Swiss  Regular  Baltic  17 x 39  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 39  30 %
Calibri Light  Swiss  Regular  Cyrillic  17 x 39  30 %
Calibri Light  Swiss  Regular  Greek  17 x 39  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 39  30 %
Calibri Light  Swiss  Regular  Vietnamese  17 x 39  30 %
Calibri Light  Swiss  Regular  Western  17 x 39  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 39  40 %
Calibri  Swiss  Regular  Central European  17 x 39  40 %
Calibri  Swiss  Regular  Cyrillic  17 x 39  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 39  40 %
Calibri  Swiss  Regular  Turkish  17 x 39  40 %
Calibri  Swiss  Regular  Vietnamese  17 x 39  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 39  40 %
Cambria Math  Roman  Regular  Baltic  20 x 179  40 %
Cambria Math  Roman  Regular  Central European  20 x 179  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  20 x 179  40 %
Cambria Math  Roman  Regular  Greek  20 x 179  40 %
Cambria Math  Roman  Regular  Turkish  20 x 179  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  20 x 179  40 %
Cambria Math  Roman  Regular  Western  20 x 179  40 %
Cambria  Roman  Regular  Baltic  20 x 38  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  20 x 38  40 %
Cambria  Roman  Regular  Cyrillic  20 x 38  40 %
Cambria  Roman  Regular  Greek  20 x 38  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  20 x 38  40 %
Cambria  Roman  Regular  Vietnamese  20 x 38  40 %
Cambria  Roman  Regular  Western  20 x 38  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 39  40 %
Candara  Swiss  Regular  Central European  17 x 39  40 %
Candara  Swiss  Regular  Cyrillic  17 x 39  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 39  40 %
Candara  Swiss  Regular  Turkish  17 x 39  40 %
Candara  Swiss  Regular  Vietnamese  17 x 39  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 39  40 %
Comic Sans MS  Script  Normál  Baltic  15 x 45  40 %
Comic Sans MS  Script  Normál  Central European  15 x 45  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 45  40 %
Comic Sans MS  Script  Normál  Greek  15 x 45  40 %
Comic Sans MS  Script  Normál  Turkish  15 x 45  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 45  40 %
Consolas  Modern  Regular  Baltic  18 x 37  40 %
Consolas  Modern  Regular  Central European  18 x 37  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  18 x 37  40 %
Consolas  Modern  Regular  Greek  18 x 37  40 %
Consolas  Modern  Regular  Turkish  18 x 37  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  18 x 37  40 %
Consolas  Modern  Regular  Western  18 x 37  40 %
Constantia  Roman  Regular  Baltic  17 x 39  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 39  40 %
Constantia  Roman  Regular  Cyrillic  17 x 39  40 %
Constantia  Roman  Regular  Greek  17 x 39  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 39  40 %
Constantia  Roman  Regular  Vietnamese  17 x 39  40 %
Constantia  Roman  Regular  Western  17 x 39  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 39  40 %
Corbel  Swiss  Regular  Central European  17 x 39  40 %
Corbel  Swiss  Regular  Cyrillic  17 x 39  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 39  40 %
Corbel  Swiss  Regular  Turkish  17 x 39  40 %
Corbel  Swiss  Regular  Vietnamese  17 x 39  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 39  40 %
Cordia New  Swiss  Regular  Thai  9 x 44  40 %
Cordia New  Swiss  Regular  Western  9 x 44  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  9 x 44  40 %
CordiaUPC  Swiss  Regular  Western  9 x 44  40 %
Courier New  Modern  Normál  Arabic  19 x 36  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  19 x 36  40 %
Courier New  Modern  Normál  Central European  19 x 36  40 %
Courier New  Modern  Normál  Cyrillic  19 x 36  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  19 x 36  40 %
Courier New  Modern  Normál  Hebrew  19 x 36  40 %
Courier New  Modern  Normál  Turkish  19 x 36  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  19 x 36  40 %
Courier New  Modern  Normál  Western  19 x 36  40 %
Courier  Roman    Central European  8 x 13  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  12 x 43  40 %
David  Swiss  Regular  Hebrew  16 x 31  40 %
David  Swiss  Regular  Western  16 x 31  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
DFKai-SB  Script  Regular  Western  16 x 32  40 %
DilleniaUPC  Roman  Normál  Thai  9 x 42  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  9 x 42  40 %
DokChampa  Swiss  Normál  Thai  19 x 62  40 %
DokChampa  Swiss  Normál  Western  19 x 62  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
Dotum  Swiss  Regular  Central European  16 x 32  40 %
Dotum  Swiss  Regular  Cyrillic  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
Dotum  Swiss  Regular  Hangul  16 x 32  40 %
Dotum  Swiss  Regular  Turkish  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
DotumChe  Modern  Regular  Baltic  16 x 32  40 %
DotumChe  Modern  Regular  Central European  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
DotumChe  Modern  Regular  Greek  16 x 32  40 %
DotumChe  Modern  Regular  Hangul  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
DotumChe  Modern  Regular  Western  16 x 32  40 %
Ebrima  Special  Normál  Baltic  19 x 43  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  19 x 43  40 %
Ebrima  Special  Normál  Turkish  19 x 43  40 %
Ebrima  Special  Normál  Western  19 x 43  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 36  40 %
EucrosiaUPC  Roman  Normál  Thai  9 x 39  40 %
EucrosiaUPC  Roman  Normál  Western  9 x 39  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  22 x 42  40 %
FangSong  Modern  Normál  CHINESE_GB2312  16 x 32  40 %
FangSong  Modern  Normál  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  8 x 15  40 %
Franklin Gothic Medium  Swiss  Normál  Baltic  14 x 36  40 %
Franklin Gothic Medium  Swiss  Normál  Central European  14 x 36  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  14 x 36  40 %
Franklin Gothic Medium  Swiss  Normál  Greek  14 x 36  40 %
Franklin Gothic Medium  Swiss  Normál  Turkish  14 x 36  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  14 x 36  40 %
FrankRuehl  Swiss  Regular  Hebrew  13 x 30  40 %
FrankRuehl  Swiss  Regular  Western  13 x 30  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  9 x 38  40 %
FreesiaUPC  Swiss  Regular  Western  9 x 38  40 %
Gabriola  Decorative  Regular  Baltic  16 x 59  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 59  40 %
Gabriola  Decorative  Regular  Cyrillic  16 x 59  40 %
Gabriola  Decorative  Regular  Greek  16 x 59  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 59  40 %
Gabriola  Decorative  Regular  Western  16 x 59  40 %
Gadugi  Swiss  Normál  Western  18 x 43  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  18 x 56  40 %
Georgia  Roman  Normál  Baltic  14 x 36  40 %
Georgia  Roman  Normál  Central European  14 x 36  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  14 x 36  40 %
Georgia  Roman  Normál  Greek  14 x 36  40 %
Georgia  Roman  Normál  Turkish  14 x 36  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  14 x 36  40 %
Gisha  Swiss  Normál  Hebrew  16 x 38  40 %
Gisha  Swiss  Normál  Western  16 x 38  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
Gulim  Swiss  Regular  Central European  16 x 32  40 %
Gulim  Swiss  Regular  Cyrillic  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
Gulim  Swiss  Regular  Hangul  16 x 32  40 %
Gulim  Swiss  Regular  Turkish  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
GulimChe  Modern  Regular  Baltic  16 x 32  40 %
GulimChe  Modern  Regular  Central European  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
GulimChe  Modern  Regular  Greek  16 x 32  40 %
GulimChe  Modern  Regular  Hangul  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
GulimChe  Modern  Regular  Western  16 x 32  40 %
Gungsuh  Roman  Regular  Baltic  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
Gungsuh  Roman  Regular  Cyrillic  16 x 32  40 %
Gungsuh  Roman  Regular  Greek  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
Gungsuh  Roman  Regular  Turkish  16 x 32  40 %
Gungsuh  Roman  Regular  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
GungsuhChe  Modern  Regular  Central European  16 x 32  40 %
GungsuhChe  Modern  Regular  Cyrillic  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
GungsuhChe  Modern  Regular  Hangul  16 x 32  40 %
GungsuhChe  Modern  Regular  Turkish  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
Impact  Swiss  Normál  Baltic  19 x 39  40 %
Impact  Swiss  Normál  Central European  19 x 39  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  19 x 39  40 %
Impact  Swiss  Normál  Greek  19 x 39  40 %
Impact  Swiss  Normál  Turkish  19 x 39  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  19 x 39  40 %
IrisUPC  Swiss  Regular  Thai  9 x 40  40 %
IrisUPC  Swiss  Regular  Western  9 x 40  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  22 x 36  40 %
JasmineUPC  Roman  Regular  Thai  9 x 34  40 %
JasmineUPC  Roman  Regular  Western  9 x 34  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  26 x 73  40 %
KaiTi  Modern  Normál  CHINESE_GB2312  16 x 32  40 %
KaiTi  Modern  Normál  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  19 x 48  40 %
Kartika  Roman  Normál  Western  27 x 46  40 %
Khmer UI  Swiss  Normál  Western  21 x 36  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  9 x 31  40 %
KodchiangUPC  Roman  Regular  Western  9 x 31  40 %
Kokila  Swiss  Normál  Western  13 x 37  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  18 x 43  40 %
Latha  Swiss  Normál  Western  23 x 44  40 %
Leelawadee UI Semilight  Swiss  Normál  Thai  17 x 43  35 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 43  35 %
Leelawadee UI Semilight  Swiss  Normál  Western  17 x 43  35 %
Leelawadee UI  Swiss  Normál  Thai  17 x 43  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 43  40 %
Leelawadee UI  Swiss  Normál  Western  17 x 43  40 %
Leelawadee  Swiss  Normál  Thai  17 x 38  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 38  40 %
Levenim MT  Special  Regular  Hebrew  16 x 42  40 %
Levenim MT  Special  Regular  Western  16 x 42  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  9 x 30  40 %
LilyUPC  Swiss  Normál  Western  9 x 30  40 %
Lucida Console  Modern  Normál  Central European  19 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  19 x 32  40 %
Lucida Console  Modern  Normál  Greek  19 x 32  40 %
Lucida Console  Modern  Normál  Turkish  19 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  19 x 32  40 %
Lucida Sans Unicode  Swiss  Normál  Baltic  16 x 49  40 %
Lucida Sans Unicode  Swiss  Normál  Central European  16 x 49  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 49  40 %
Lucida Sans Unicode  Swiss  Normál  Greek  16 x 49  40 %
Lucida Sans Unicode  Swiss  Normál  Hebrew  16 x 49  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 49  40 %
Lucida Sans Unicode  Swiss  Normál  Western  16 x 49  40 %
Malgun Gothic  Swiss  Regular  Hangul  15 x 43  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 43  40 %
Mangal  Roman  Normál  Western  19 x 54  40 %
Marlett  Special  Regular  Symbol  31 x 32  50 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 41  40 %
Meiryo UI  Swiss  Normál  Central European  17 x 41  40 %
Meiryo UI  Swiss  Normál  Cyrillic  17 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 41  40 %
Meiryo UI  Swiss  Normál  Japanese  17 x 41  40 %
Meiryo UI  Swiss  Normál  Turkish  17 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 41  40 %
Meiryo  Swiss  Normál  Baltic  31 x 48  40 %
Meiryo  Swiss  Normál  Central European  31 x 48  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 48  40 %
Meiryo  Swiss  Normál  Greek  31 x 48  40 %
Meiryo  Swiss  Normál  Japanese  31 x 48  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 48  40 %
Meiryo  Swiss  Normál  Western  31 x 48  40 %
Microsoft Himalaya  Special  Regular  Western  13 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  32 x 43  29 %
Microsoft JhengHei Light  Swiss  Regular  Central European  32 x 43  29 %
Microsoft JhengHei Light  Swiss  Regular  CHINESE_BIG5  32 x 43  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  32 x 43  29 %
Microsoft JhengHei Light  Swiss  Regular  Cyrillic  32 x 43  29 %
Microsoft JhengHei Light  Swiss  Regular  Greek  32 x 43  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  32 x 43  29 %
Microsoft JhengHei Light  Swiss  Regular  Hangul  32 x 43  29 %
Microsoft JhengHei Light  Swiss  Regular  Hebrew  32 x 43  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  32 x 43  29 %
Microsoft JhengHei Light  Swiss  Regular  Turkish  32 x 43  29 %
Microsoft JhengHei Light  Swiss  Regular  Vietnamese  32 x 43  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  32 x 43  29 %
Microsoft JhengHei UI Light  Swiss  Regular  Baltic  32 x 41  29 %
Microsoft JhengHei UI Light  Swiss  Regular  Central European  32 x 41  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  32 x 41  29 %
Microsoft JhengHei UI Light  Swiss  Regular  CHINESE_GB2312  32 x 41  29 %
Microsoft JhengHei UI Light  Swiss  Regular  Cyrillic  32 x 41  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  32 x 41  29 %
Microsoft JhengHei UI Light  Swiss  Regular  Hangul(Johab)  32 x 41  29 %
Microsoft JhengHei UI Light  Swiss  Regular  Hangul  32 x 41  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  32 x 41  29 %
Microsoft JhengHei UI Light  Swiss  Regular  Japanese  32 x 41  29 %
Microsoft JhengHei UI Light  Swiss  Regular  Turkish  32 x 41  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  32 x 41  29 %
Microsoft JhengHei UI Light  Swiss  Regular  Western  32 x 41  29 %
Microsoft JhengHei UI  Swiss  Normál  CHINESE_BIG5  15 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 41  40 %
Microsoft JhengHei UI  Swiss  Normál  Western  15 x 41  40 %
Microsoft JhengHei  Swiss  Normál  CHINESE_BIG5  15 x 43  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 43  40 %
Microsoft JhengHei  Swiss  Normál  Western  15 x 43  40 %
Microsoft New Tai Lue  Swiss  Normál  Western  19 x 42  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  24 x 41  40 %
Microsoft Sans Serif  Swiss  Normál  Arabic  14 x 36  40 %
Microsoft Sans Serif  Swiss  Normál  Baltic  14 x 36  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  14 x 36  40 %
Microsoft Sans Serif  Swiss  Normál  Cyrillic  14 x 36  40 %
Microsoft Sans Serif  Swiss  Normál  Greek  14 x 36  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  14 x 36  40 %
Microsoft Sans Serif  Swiss  Normál  Thai  14 x 36  40 %
Microsoft Sans Serif  Swiss  Normál  Turkish  14 x 36  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  14 x 36  40 %
Microsoft Sans Serif  Swiss  Normál  Western  14 x 36  40 %
Microsoft Tai Le  Swiss  Normál  Western  19 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 32  40 %
Microsoft Uighur  Special  Normál  Western  13 x 32  40 %
Microsoft YaHei Light  Swiss  Regular  Central European  15 x 41  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 41  29 %
Microsoft YaHei Light  Swiss  Regular  Cyrillic  15 x 41  29 %
Microsoft YaHei Light  Swiss  Regular  Greek  15 x 41  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 41  29 %
Microsoft YaHei UI Light  Swiss  Regular  Central European  15 x 42  29 %
Microsoft YaHei UI Light  Swiss  Regular  CHINESE_GB2312  15 x 42  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 42  29 %
Microsoft YaHei UI Light  Swiss  Regular  Greek  15 x 42  29 %
Microsoft YaHei UI Light  Swiss  Regular  Western  15 x 42  29 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 41  40 %
Microsoft YaHei UI  Swiss  Normál  CHINESE_GB2312  15 x 41  40 %
Microsoft YaHei UI  Swiss  Normál  Cyrillic  15 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 41  40 %
Microsoft YaHei UI  Swiss  Normál  Turkish  15 x 41  40 %
Microsoft YaHei UI  Swiss  Normál  Western  15 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 42  40 %
Microsoft YaHei  Swiss  Normál  CHINESE_GB2312  15 x 42  40 %
Microsoft YaHei  Swiss  Normál  Cyrillic  15 x 42  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 42  40 %
Microsoft YaHei  Swiss  Normál  Turkish  15 x 42  40 %
Microsoft YaHei  Swiss  Normál  Western  15 x 42  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  21 x 32  40 %
MingLiU_HKSCS  Roman  Regular  CHINESE_BIG5  16 x 32  40 %
MingLiU_HKSCS  Roman  Regular  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
MingLiU_HKSCS-ExtB  Roman  Regular  Western  16 x 32  40 %
MingLiU  Modern  Regular  CHINESE_BIG5  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
MingLiU-ExtB  Roman  Regular  CHINESE_BIG5  16 x 32  40 %
MingLiU-ExtB  Roman  Regular  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  19 x 32  40 %
Miriam Fixed  Modern  Regular  Western  19 x 32  40 %
Miriam  Swiss  Regular  Hebrew  13 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 32  40 %
Modern  Modern    OEM/DOS  19 x 37  40 %
Mongolian Baiti  Script  Normál  Western  14 x 34  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 43  40 %
MS Gothic  Modern  Regular  Baltic  16 x 32  40 %
MS Gothic  Modern  Regular  Central European  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
MS Gothic  Modern  Regular  Greek  16 x 32  40 %
MS Gothic  Modern  Regular  Japanese  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
MS Gothic  Modern  Regular  Western  16 x 32  40 %
MS Mincho  Modern  Regular  Baltic  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
MS Mincho  Modern  Regular  Cyrillic  16 x 32  40 %
MS Mincho  Modern  Regular  Greek  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
MS Mincho  Modern  Regular  Turkish  16 x 32  40 %
MS Mincho  Modern  Regular  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 32  40 %
MS PGothic  Swiss  Regular  Central European  13 x 32  40 %
MS PGothic  Swiss  Regular  Cyrillic  13 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 32  40 %
MS PGothic  Swiss  Regular  Japanese  13 x 32  40 %
MS PGothic  Swiss  Regular  Turkish  13 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 32  40 %
MS PMincho  Roman  Regular  Baltic  13 x 32  40 %
MS PMincho  Roman  Regular  Central European  13 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 32  40 %
MS PMincho  Roman  Regular  Greek  13 x 32  40 %
MS PMincho  Roman  Regular  Japanese  13 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 32  40 %
MS PMincho  Roman  Regular  Western  13 x 32  40 %
MS Sans Serif  Swiss    Central European  5 x 13  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  5 x 13  40 %
MS UI Gothic  Swiss  Regular  Baltic  13 x 32  40 %
MS UI Gothic  Swiss  Regular  Central European  13 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 32  40 %
MS UI Gothic  Swiss  Regular  Greek  13 x 32  40 %
MS UI Gothic  Swiss  Regular  Japanese  13 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 32  40 %
MS UI Gothic  Swiss  Regular  Western  13 x 32  40 %
MV Boli  Special  Normál  Western  18 x 52  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  18 x 60  40 %
Narkisim  Swiss  Normál  Hebrew  12 x 32  40 %
Narkisim  Swiss  Normál  Western  12 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 43  35 %
Nirmala UI  Swiss  Normál  Western  31 x 43  40 %
NSimSun  Modern  Regular  CHINESE_GB2312  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
Nyala  Special  Normál  Baltic  18 x 33  40 %
Nyala  Special  Normál  Central European  18 x 33  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  18 x 33  40 %
Nyala  Special  Normál  Western  18 x 33  40 %
Palatino Linotype  Roman  Normál  Baltic  14 x 43  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  14 x 43  40 %
Palatino Linotype  Roman  Normál  Cyrillic  14 x 43  40 %
Palatino Linotype  Roman  Normál  Greek  14 x 43  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  14 x 43  40 %
Palatino Linotype  Roman  Normál  Vietnamese  14 x 43  40 %
Palatino Linotype  Roman  Normál  Western  14 x 43  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  14 x 41  40 %
PMingLiU  Roman  Regular  CHINESE_BIG5  16 x 32  40 %
PMingLiU  Roman  Regular  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
PMingLiU-ExtB  Roman  Regular  Western  16 x 32  40 %
Raavi  Swiss  Normál  Western  13 x 53  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  19 x 31  40 %
Rod  Modern  Regular  Western  19 x 31  40 %
Roman  Roman    OEM/DOS  22 x 37  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 45  40 %
Sakkal Majalla  Special  Normál  Baltic  16 x 45  40 %
Sakkal Majalla  Special  Normál  Central European  16 x 45  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 45  40 %
Sakkal Majalla  Special  Normál  Western  16 x 45  40 %
Script  Script    OEM/DOS  16 x 36  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  21 x 56  40 %
Segoe Print  Special  Regular  Central European  21 x 56  40 %
Segoe Print  Special  Regular  Cyrillic  21 x 56  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  21 x 56  40 %
Segoe Print  Special  Regular  Turkish  21 x 56  40 %
Segoe Print  Special  Regular  Western  21 x 56  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  22 x 51  40 %
Segoe Script  Swiss  Normál  Central European  22 x 51  40 %
Segoe Script  Swiss  Normál  Cyrillic  22 x 51  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  22 x 51  40 %
Segoe Script  Swiss  Normál  Turkish  22 x 51  40 %
Segoe Script  Swiss  Normál  Western  22 x 51  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  20 x 43  90 %
Segoe UI Black  Swiss  Regular  Central European  20 x 43  90 %
Segoe UI Black  Swiss  Regular  Cyrillic  20 x 43  90 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  20 x 43  90 %
Segoe UI Black  Swiss  Regular  Turkish  20 x 43  90 %
Segoe UI Black  Swiss  Regular  Vietnamese  20 x 43  90 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  20 x 43  90 %
Segoe UI Emoji  Swiss  Normál  Western  23 x 43  40 %
Segoe UI Light  Swiss  Regular  Arabic  17 x 43  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 43  30 %
Segoe UI Light  Swiss  Regular  Central European  17 x 43  30 %
Segoe UI Light  Swiss  Regular  Cyrillic  17 x 43  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 43  30 %
Segoe UI Light  Swiss  Regular  Hebrew  17 x 43  30 %
Segoe UI Light  Swiss  Regular  Turkish  17 x 43  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 43  30 %
Segoe UI Light  Swiss  Regular  Western  17 x 43  30 %
Segoe UI Semibold  Swiss  Regular  Arabic  18 x 43  60 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  18 x 43  60 %
Segoe UI Semibold  Swiss  Regular  Central European  18 x 43  60 %
Segoe UI Semibold  Swiss  Regular  Cyrillic  18 x 43  60 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  18 x 43  60 %
Segoe UI Semibold  Swiss  Regular  Hebrew  18 x 43  60 %
Segoe UI Semibold  Swiss  Regular  Turkish  18 x 43  60 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  18 x 43  60 %
Segoe UI Semibold  Swiss  Regular  Western  18 x 43  60 %
Segoe UI Semilight  Swiss  Regular  Arabic  17 x 43  35 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 43  35 %
Segoe UI Semilight  Swiss  Regular  Central European  17 x 43  35 %
Segoe UI Semilight  Swiss  Regular  Cyrillic  17 x 43  35 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 43  35 %
Segoe UI Semilight  Swiss  Regular  Hebrew  17 x 43  35 %
Segoe UI Semilight  Swiss  Regular  Turkish  17 x 43  35 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 43  35 %
Segoe UI Semilight  Swiss  Regular  Western  17 x 43  35 %
Segoe UI Symbol  Swiss  Normál  Western  23 x 43  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 43  40 %
Segoe UI  Swiss  Normál  Baltic  17 x 43  40 %
Segoe UI  Swiss  Normál  Central European  17 x 43  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 43  40 %
Segoe UI  Swiss  Normál  Greek  17 x 43  40 %
Segoe UI  Swiss  Normál  Hebrew  17 x 43  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 43  40 %
Segoe UI  Swiss  Normál  Vietnamese  17 x 43  40 %
Segoe UI  Swiss  Normál  Western  17 x 43  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 41  40 %
Shruti  Swiss  Normál  Western  14 x 54  40 %
SimHei  Modern  Normál  CHINESE_GB2312  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
Simplified Arabic Fixed  Modern  Regular  Arabic  19 x 35  40 %
Simplified Arabic Fixed  Modern  Regular  Western  19 x 35  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 53  40 %
Simplified Arabic  Roman  Normál  Western  13 x 53  40 %
SimSun  Special  Regular  CHINESE_GB2312  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 32  40 %
SimSun-ExtB  Modern  Normál  CHINESE_GB2312  16 x 32  40 %
SimSun-ExtB  Modern  Normál  Western  16 x 32  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 46  40 %
Sitka Banner  Special  Regular  Central European  16 x 46  40 %
Sitka Banner  Special  Regular  Cyrillic  16 x 46  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 46  40 %
Sitka Banner  Special  Regular  Turkish  16 x 46  40 %
Sitka Banner  Special  Regular  Vietnamese  16 x 46  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 46  40 %
Sitka Display  Special  Regular  Baltic  17 x 46  40 %
Sitka Display  Special  Regular  Central European  17 x 46  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 46  40 %
Sitka Display  Special  Regular  Greek  17 x 46  40 %
Sitka Display  Special  Regular  Turkish  17 x 46  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 46  40 %
Sitka Display  Special  Regular  Western  17 x 46  40 %
Sitka Heading  Special  Regular  Baltic  17 x 46  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 46  40 %
Sitka Heading  Special  Regular  Cyrillic  17 x 46  40 %
Sitka Heading  Special  Regular  Greek  17 x 46  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  17 x 46  40 %
Sitka Heading  Special  Regular  Vietnamese  17 x 46  40 %
Sitka Heading  Special  Regular  Western  17 x 46  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  21 x 47  40 %
Sitka Small  Special  Regular  Central European  21 x 47  40 %
Sitka Small  Special  Regular  Cyrillic  21 x 47  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  21 x 47  40 %
Sitka Small  Special  Regular  Turkish  21 x 47  40 %
Sitka Small  Special  Regular  Vietnamese  21 x 47  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  21 x 47  40 %
Sitka Subheading  Special  Regular  Baltic  18 x 46  40 %
Sitka Subheading  Special  Regular  Central European  18 x 46  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  18 x 46  40 %
Sitka Subheading  Special  Regular  Greek  18 x 46  40 %
Sitka Subheading  Special  Regular  Turkish  18 x 46  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  18 x 46  40 %
Sitka Subheading  Special  Regular  Western  18 x 46  40 %
Sitka Text  Special  Regular  Baltic  19 x 46  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  19 x 46  40 %
Sitka Text  Special  Regular  Cyrillic  19 x 46  40 %
Sitka Text  Special  Regular  Greek  19 x 46  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  19 x 46  40 %
Sitka Text  Special  Regular  Vietnamese  19 x 46  40 %
Sitka Text  Special  Regular  Western  19 x 46  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  1 x 3  40 %
Sylfaen  Roman  Normál  Baltic  13 x 42  40 %
Sylfaen  Roman  Normál  Central European  13 x 42  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 42  40 %
Sylfaen  Roman  Normál  Greek  13 x 42  40 %
Sylfaen  Roman  Normál  Turkish  13 x 42  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 42  40 %
Symbol  Roman  Normál  Symbol  19 x 39  40 %
System  Swiss    Central European  7 x 16  70 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  14 x 39  40 %
Tahoma  Swiss  Normál  Baltic  14 x 39  40 %
Tahoma  Swiss  Normál  Central European  14 x 39  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  14 x 39  40 %
Tahoma  Swiss  Normál  Greek  14 x 39  40 %
Tahoma  Swiss  Normál  Hebrew  14 x 39  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  14 x 39  40 %
Tahoma  Swiss  Normál  Turkish  14 x 39  40 %
Tahoma  Swiss  Normál  Vietnamese  14 x 39  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  14 x 39  40 %
Terminal  Modern    OEM/DOS  8 x 12  40 %
Times New Roman  Roman  Normál  Arabic  13 x 35  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 35  40 %
Times New Roman  Roman  Normál  Central European  13 x 35  40 %
Times New Roman  Roman  Normál  Cyrillic  13 x 35  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 35  40 %
Times New Roman  Roman  Normál  Hebrew  13 x 35  40 %
Times New Roman  Roman  Normál  Turkish  13 x 35  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 35  40 %
Times New Roman  Roman  Normál  Western  13 x 35  40 %
Traditional Arabic  Roman  Normál  Arabic  15 x 48  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 48  40 %
Trebuchet MS  Swiss  Normál  Baltic  15 x 37  40 %
Trebuchet MS  Swiss  Normál  Central European  15 x 37  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 37  40 %
Trebuchet MS  Swiss  Normál  Greek  15 x 37  40 %
Trebuchet MS  Swiss  Normál  Turkish  15 x 37  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  15 x 37  40 %
Tunga  Swiss  Normál  Western  18 x 53  40 %
Urdu Typesetting  Script  Normál  Arabic  13 x 55  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  13 x 55  40 %
Utsaah  Swiss  Normál  Western  13 x 36  40 %
Vani  Swiss  Normál  Western  23 x 54  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 39  40 %
Verdana  Swiss  Normál  Central European  16 x 39  40 %
Verdana  Swiss  Normál  Cyrillic  16 x 39  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 39  40 %
Verdana  Swiss  Normál  Turkish  16 x 39  40 %
Verdana  Swiss  Normál  Vietnamese  16 x 39  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  16 x 39  40 %
Vijaya  Swiss  Normál  Western  19 x 32  40 %
Vrinda  Swiss  Normál  Western  20 x 44  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 32  40 %
Wingdings  Special  Regular  Symbol  28 x 36  40 %
Yu Gothic Light  Swiss  Regular  Baltic  31 x 41  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  30 %
Yu Gothic Light  Swiss  Regular  Cyrillic  31 x 41  30 %
Yu Gothic Light  Swiss  Regular  Greek  31 x 41  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  30 %
Yu Gothic Light  Swiss  Regular  Turkish  31 x 41  30 %
Yu Gothic Light  Swiss  Regular  Western  31 x 41  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  40 %
Yu Gothic  Swiss  Regular  Central European  31 x 41  40 %
Yu Gothic  Swiss  Regular  Cyrillic  31 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  40 %
Yu Gothic  Swiss  Regular  Japanese  31 x 41  40 %
Yu Gothic  Swiss  Regular  Turkish  31 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  40 %
Yu Mincho Demibold  Roman  Bold  Baltic  31 x 41  60 %
Yu Mincho Demibold  Roman  Bold  Central European  31 x 41  60 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  60 %
Yu Mincho Demibold  Roman  Bold  Greek  31 x 41  60 %
Yu Mincho Demibold  Roman  Bold  Japanese  31 x 41  60 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  60 %
Yu Mincho Demibold  Roman  Bold  Western  31 x 41  60 %
Yu Mincho Light  Roman  Regular  Baltic  31 x 41  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  30 %
Yu Mincho Light  Roman  Regular  Cyrillic  31 x 41  30 %
Yu Mincho Light  Roman  Regular  Greek  31 x 41  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  30 %
Yu Mincho Light  Roman  Regular  Turkish  31 x 41  30 %
Yu Mincho Light  Roman  Regular  Western  31 x 41  30 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  40 %
Yu Mincho  Roman  Regular  Central European  31 x 41  40 %
Yu Mincho  Roman  Regular  Cyrillic  31 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  40 %
Yu Mincho  Roman  Regular  Japanese  31 x 41  40 %
Yu Mincho  Roman  Regular  Turkish  31 x 41  40 %
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  31 x 41  40 %


Windows Audio

 
Device  Identifier  Device Description
midi-out.0  0001 001B  Microsoft GS Wavetable Synth
mixer.0  0001 0068  Speakers (Intel SST Audio Devic
mixer.1  0001 0068  Microphone (Intel SST Audio Dev
wave-in.0  0001 0065  Microphone (Intel SST Audio Dev
wave-out.0  0001 0064  Speakers (Intel SST Audio Devic


Audio Codecs

 
[ Fraunhofer IIS MPEG Layer-3 Codec (decode only) ]
 
ACM Driver Properties:
Driver Description  Fraunhofer IIS MPEG Layer-3 Codec (decode only)
Copyright Notice  Copyright © 1996-1999 Fraunhofer Institut Integrierte Schaltungen IIS
Driver Features  decoder only version
Driver Version  1.09
 
[ Microsoft ADPCM CODEC ]
 
ACM Driver Properties:
Driver Description  Microsoft ADPCM CODEC
Copyright Notice  Copyright (C) 1992-1996 Microsoft Corporation
Driver Features  Compresses and decompresses Microsoft ADPCM audio data.
Driver Version  4.00
 
[ Microsoft CCITT G.711 A-Law and u-Law CODEC ]
 
ACM Driver Properties:
Driver Description  Microsoft CCITT G.711 A-Law and u-Law CODEC
Copyright Notice  Copyright (c) 1993-1996 Microsoft Corporation
Driver Features  Compresses and decompresses CCITT G.711 A-Law and u-Law audio data.
Driver Version  4.00
 
[ Microsoft GSM 6.10 Audio CODEC ]
 
ACM Driver Properties:
Driver Description  Microsoft GSM 6.10 Audio CODEC
Copyright Notice  Copyright (C) 1993-1996 Microsoft Corporation
Driver Features  Compresses and decompresses audio data conforming to the ETSI-GSM (European Telecommunications Standards Institute-Groupe Special Mobile) recommendation 6.10.
Driver Version  4.00
 
[ Microsoft IMA ADPCM CODEC ]
 
ACM Driver Properties:
Driver Description  Microsoft IMA ADPCM CODEC
Copyright Notice  Copyright (C) 1992-1996 Microsoft Corporation
Driver Features  Compresses and decompresses IMA ADPCM audio data.
Driver Version  4.00
 
[ Microsoft PCM Converter ]
 
ACM Driver Properties:
Driver Description  Microsoft PCM Converter
Copyright Notice  Copyright (C) 1992-1996 Microsoft Corporation
Driver Features  Converts frequency and bits per sample of PCM audio data.
Driver Version  5.00


Video Codecs

 
Driver  Version  Description
iccvid.dll  1.10.0.11  Cinepak® Codec
iyuv_32.dll  6.3.9600.16384 (winblue_rtm.130821-1623)  Intel Indeo(R) Video YUV Codec
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
msvidc32.dll  6.3.9600.16384 (winblue_rtm.130821-1623)  Microsoft Video 1 Compressor
msyuv.dll  6.3.9600.16384 (winblue_rtm.130821-1623)  Microsoft UYVY Video Decompressor
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]


MCI

 
[ AVIVideo ]
 
MCI Device Properties:
Device  AVIVideo
Name  Video for Windows
Description  Video For Windows MCI driver
Type  Digital Video Device
Driver  mciavi32.dll
Status  Enabled
 
MCI Device Features:
Compound Device  Yes
File Based Device  Yes
Can Eject  No
Can Play  Yes
Can Play In Reverse  Yes
Can Record  No
Can Save Data  No
Can Freeze Data  No
Can Lock Data  No
Can Stretch Frame  Yes
Can Stretch Input  No
Can Test  Yes
Audio Capable  Yes
Video Capable  Yes
Still Image Capable  No
 
[ CDAudio ]
 
MCI Device Properties:
Device  CDAudio
Description  MCI driver for cdaudio devices
Driver  mcicda.dll
Status  Enabled
 
[ MPEGVideo ]
 
MCI Device Properties:
Device  MPEGVideo
Name  DirectShow
Description  DirectShow MCI Driver
Type  Digital Video Device
Driver  mciqtz32.dll
Status  Enabled
 
MCI Device Features:
Compound Device  Yes
File Based Device  Yes
Can Eject  No
Can Play  Yes
Can Play In Reverse  No
Can Record  No
Can Save Data  No
Can Freeze Data  No
Can Lock Data  No
Can Stretch Frame  Yes
Can Stretch Input  No
Can Test  Yes
Audio Capable  Yes
Video Capable  Yes
Still Image Capable  No
 
[ Sequencer ]
 
MCI Device Properties:
Device  Sequencer
Name  MIDI Sequencer
Description  MCI driver for MIDI sequencer
Type  Sequencer Device
Driver  mciseq.dll
Status  Enabled
 
MCI Device Features:
Compound Device  Yes
File Based Device  Yes
Can Eject  No
Can Play  Yes
Can Record  No
Can Save Data  No
Audio Capable  Yes
Video Capable  No
 
[ WaveAudio ]
 
MCI Device Properties:
Device  WaveAudio
Name  Sound
Description  MCI driver for waveform audio
Type  Waveform Audio Device
Driver  mciwave.dll
Status  Enabled
 
MCI Device Features:
Compound Device  Yes
File Based Device  Yes
Can Eject  No
Can Play  Yes
Can Record  Yes
Can Save Data  Yes
Audio Capable  Yes
Video Capable  No


SAPI

 
SAPI Properties:
SAPI4 Version  -
SAPI5 Version  5.3.16421.0
 
Voice (SAPI5):
Name  Microsoft David Desktop - English (United States)
Voice Path  C:\Windows\Speech\Engines\TTS\en-US\M1033DAV
Age  Adult
Gender  Male
Language  English (United States)
Vendor  Microsoft
Version  11.0
DLL File  C:\Windows\System32\speech\engines\tts\MSTTSEngine.dll (x86)
CLSID  {C64501F6-E6E6-451f-A150-25D0839BC510}
 
Voice (SAPI5):
Name  Microsoft Hanhan Desktop - Chinese (Taiwan)
Voice Path  C:\Windows\Speech\Engines\TTS\zh-TW\M1028HAN
Age  Adult
Gender  Female
Language  Chinese (Traditional, Taiwan)
Vendor  Microsoft
Version  11.0
DLL File  C:\Windows\System32\speech\engines\tts\MSTTSEngine.dll (x86)
CLSID  {C64501F6-E6E6-451f-A150-25D0839BC510}
 
Voice (SAPI5):
Name  Microsoft Hazel Desktop - English (Great Britain)
Voice Path  C:\Windows\Speech\Engines\TTS\en-GB\M2057HAZ
Age  Adult
Gender  Female
Language  English (United Kingdom)
Vendor  Microsoft
Version  11.0
DLL File  C:\Windows\System32\speech\engines\tts\MSTTSEngine.dll (x86)
CLSID  {C64501F6-E6E6-451f-A150-25D0839BC510}
 
Voice (SAPI5):
Name  Microsoft Helena Desktop - Spanish (Spain)
Voice Path  C:\Windows\Speech\Engines\TTS\es-ES\M3082HEL
Age  Adult
Gender  Female
Language  Spanish (Spain, International Sort)
Vendor  Microsoft
Version  11.0
DLL File  C:\Windows\System32\speech\engines\tts\MSTTSEngine.dll (x86)
CLSID  {C64501F6-E6E6-451f-A150-25D0839BC510}
 
Voice (SAPI5):
Name  Microsoft Hortense Desktop - French
Voice Path  C:\Windows\Speech\Engines\TTS\fr-FR\M1036HOR
Age  Adult
Gender  Female
Language  French (France)
Vendor  Microsoft
Version  11.0
DLL File  C:\Windows\System32\speech\engines\tts\MSTTSEngine.dll (x86)
CLSID  {C64501F6-E6E6-451f-A150-25D0839BC510}
 
Voice (SAPI5):
Name  Microsoft Huihui Desktop - Chinese (Simplified)
Voice Path  C:\Windows\Speech\Engines\TTS\zh-CN\M2052HUI
Age  Adult
Gender  Female
Language  Chinese (Simplified, China)
Vendor  Microsoft
Version  11.0
DLL File  C:\Windows\System32\speech\engines\tts\MSTTSEngine.dll (x86)
CLSID  {C64501F6-E6E6-451f-A150-25D0839BC510}
 
Voice (SAPI5):
Name  Microsoft Sabina Desktop - Spanish (Mexico)
Voice Path  C:\Windows\Speech\Engines\TTS\es-MX\M2058SAB
Age  Adult
Gender  Female
Language  Spanish (Mexico)
Vendor  Microsoft
Version  11.0
DLL File  C:\Windows\System32\speech\engines\tts\MSTTSEngine.dll (x86)
CLSID  {C64501F6-E6E6-451f-A150-25D0839BC510}
 
Voice (SAPI5):
Name  Microsoft Tracy Desktop - Chinese(Traditional, HongKong SAR)
Voice Path  C:\Windows\Speech\Engines\TTS\zh-HK\M3076TRA
Age  Adult
Gender  Female
Language  Chinese (Traditional, Hong Kong SAR)
Vendor  Microsoft
Version  11.0
DLL File  C:\Windows\System32\speech\engines\tts\MSTTSEngine.dll (x86)
CLSID  {C64501F6-E6E6-451f-A150-25D0839BC510}
 
Voice (SAPI5):
Name  Microsoft Zira Desktop - English (United States)
Voice Path  C:\Windows\Speech\Engines\TTS\en-US\M1033ZIR
Age  Adult
Gender  Female
Language  English (United States)
Vendor  Microsoft
Version  11.0
DLL File  C:\Windows\System32\speech\engines\tts\MSTTSEngine.dll (x86)
CLSID  {C64501F6-E6E6-451f-A150-25D0839BC510}
 
Speech Recognizer (SAPI5):
Name  Microsoft Speech Recognizer 8.0 for Windows (Chinese Simplified - PRC)
Description  Microsoft Speech Recognizer 8.0 for Windows (Chinese Simplified - PRC)
FE Config Data File  C:\Windows\Speech\Engines\SR\zh-CN\c2052dsk.fe
Language  Chinese (Simplified, China)
Speaking Style  Discrete;Continuous
Supported Locales  Chinese (Simplified, China); Chinese (Simplified, Singapore); Chinese (Simplified)
Vendor  Microsoft
Version  8.0
DLL File  C:\Windows\System32\Speech\Engines\SR\spsreng.dll (x86)
CLSID  {DAC9F469-0C67-4643-9258-87EC128C5941}
RecoExtension  {4F4DB904-CA35-4A3A-90AF-C9D8BE7532AC}
 
Speech Recognizer (SAPI5):
Name  Microsoft Speech Recognizer 8.0 for Windows (Chinese Traditional - Taiwan)
Description  Microsoft Speech Recognizer 8.0 for Windows (Chinese Traditional - Taiwan)
FE Config Data File  C:\Windows\Speech\Engines\SR\zh-TW\c1028dsk.fe
Language  Chinese (Traditional, Taiwan); Chinese (Traditional, Hong Kong SAR)
Speaking Style  Discrete;Continuous
Supported Locales  Chinese (Traditional, Taiwan); Chinese (Traditional, Hong Kong SAR); Chinese (Traditional, Macao SAR); Chinese (Traditional)
Vendor  Microsoft
Version  8.0
DLL File  C:\Windows\System32\Speech\Engines\SR\spsreng.dll (x86)
CLSID  {DAC9F469-0C67-4643-9258-87EC128C5941}
RecoExtension  {4F4DB904-CA35-4A3A-90AF-C9D8BE7532AC}
 
Speech Recognizer (SAPI5):
Name  Microsoft Speech Recognizer 8.0 for Windows (English - US)
Description  Microsoft Speech Recognizer 8.0 for Windows (English - US)
FE Config Data File  C:\Windows\Speech\Engines\SR\en-US\c1033dsk.fe
Language  English (United States); English
Speaking Style  Discrete;Continuous
Supported Locales  English (United States); English (Canada); English (Philippines); English
Vendor  Microsoft
Version  8.0
DLL File  C:\Windows\System32\Speech\Engines\SR\spsreng.dll (x86)
CLSID  {DAC9F469-0C67-4643-9258-87EC128C5941}
RecoExtension  {4F4DB904-CA35-4A3A-90AF-C9D8BE7532AC}
 
Speech Recognizer (SAPI5):
Name  Microsoft Speech Recognizer 8.0 for Windows (French - France)
Description  Microsoft Speech Recognizer 8.0 for Windows (French - France)
FE Config Data File  C:\Windows\Speech\Engines\SR\fr-FR\c1036dsk.fe
Language  French (France)
Speaking Style  Discrete;Continuous
Supported Locales  French (France); French
Vendor  Microsoft
Version  8.0
DLL File  C:\Windows\System32\Speech\Engines\SR\spsreng.dll (x86)
CLSID  {DAC9F469-0C67-4643-9258-87EC128C5941}
RecoExtension  {4F4DB904-CA35-4A3A-90AF-C9D8BE7532AC}
 
Speech Recognizer (SAPI5):
Name  Microsoft Speech Recognizer 8.0 for Windows (Spanish - Spain)
Description  Microsoft Speech Recognizer 8.0 for Windows (Spanish - Spain)
FE Config Data File  C:\Windows\Speech\Engines\SR\es-ES\c3082dsk.fe
Language  Spanish (Spain, International Sort); Spanish (Spain, Traditional Sort)
Speaking Style  Discrete;Continuous
Supported Locales  Spanish (Spain, International Sort); Spanish (Spain, Traditional Sort); Spanish
Vendor  Microsoft
Version  8.0
DLL File  C:\Windows\System32\Speech\Engines\SR\spsreng.dll (x86)
CLSID  {DAC9F469-0C67-4643-9258-87EC128C5941}
RecoExtension  {4F4DB904-CA35-4A3A-90AF-C9D8BE7532AC}


Windows Storage

 
[ Hynix HCG8e ]
 
Device Properties:
Driver Description  Hynix HCG8e
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  disk.inf
 
[ Microsoft Storage Spaces Controller ]
 
Device Properties:
Driver Description  Microsoft Storage Spaces Controller
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  spaceport.inf
 
[ SD Storage Class Controller ]
 
Device Properties:
Driver Description  SD Storage Class Controller
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  sdstor.inf


Logical Drives

 
Drive  Drive Type  File System  Total Size  Used Space  Free Space  % Free  Volume Serial
[ TRIAL VERSION ]  Local Disk  NTFS  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]


Physical Drives

 
[ Drive #1 - HCG8e (58 GB) ]
 
Partition  Partition Type  Drive  Start Offset  Partition Length
#1  EFI System    1 MB  100 MB
#2  MS Recovery    101 MB  900 MB
#3  MS Reserved    1001 MB  128 MB
#4  Basic Data  C: (OS)  1129 MB  50326 MB
#5  MS Recovery    51455 MB  8192 MB


Windows Network

 
[ Bluetooth Device (Personal Area Network) ]
 
Network Adapter Properties:
Network Adapter  Bluetooth Device (Personal Area Network)
Interface Type  Bluetooth Ethernet
Hardware Address  74-D0-2B-69-F0-B2
Connection Name  Bluetooth Network Connection
Connection Speed  3 Mbps
MTU  1500 bytes
Bytes Received  0
Bytes Sent  0
 
[ Broadcom 802.11abgn Wireless SDIO Adapter ]
 
Network Adapter Properties:
Network Adapter  Broadcom 802.11abgn Wireless SDIO Adapter
Interface Type  802.11 Wireless Ethernet
Hardware Address  74-D0-2B-69-F0-B1
Connection Name  Wi-Fi
Connection Speed  65 Mbps
MTU  1500 bytes
DHCP Lease Obtained  2013.11.29. 2:26:38
DHCP Lease Expires  2013.11.29. 4:26:38
Bytes Received  129114885 (123.1 MB)
Bytes Sent  5754275 (5.5 MB)
 
Network Adapter Addresses:
IP / Subnet Mask  [ TRIAL VERSION ]
Gateway  [ TRIAL VERSION ]
DHCP  [ TRIAL VERSION ]
DNS  [ TRIAL VERSION ]
 
Network Adapter Manufacturer:
Company Name  Broadcom Corporation
Product Information  http://www.broadcom.com/products
Driver Download  http://www.broadcom.com/support/ethernet_nic
Driver Update  http://www.aida64.com/driver-updates
 
[ Microsoft Wi-Fi Direct Virtual Adapter ]
 
Network Adapter Properties:
Network Adapter  Microsoft Wi-Fi Direct Virtual Adapter
Interface Type  802.11 Wireless Ethernet
Hardware Address  76-D0-2B-69-F0-B1
Connection Name  Local Area Connection* 2
MTU  1500 bytes
Bytes Received  0
Bytes Sent  0


Internet

 
Internet Settings:
Start Page  http://asus13.msn.com/?pc=ASJB
Search Page  http://go.microsoft.com/fwlink/?LinkId=54896
Local Page  C:\Windows\system32\blank.htm
Download Folder  
 
Current Proxy:
Proxy Status  Disabled
 
LAN Proxy:
Proxy Status  Disabled


Routes

 
Type  Net Destination  Netmask  Gateway  Metric  Interface
Active  0.0.0.0  0.0.0.0  192.168.1.1  25  192.168.1.103 (Broadcom 802.11abgn Wireless SDIO Adapter)
Active  127.0.0.0  255.0.0.0  127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
Active  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  306  [ TRIAL VERSION ]
Active  127.255.255.255  255.255.255.255  127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
Active  192.168.1.0  255.255.255.0  192.168.1.103  281  192.168.1.103 (Broadcom 802.11abgn Wireless SDIO Adapter)
Active  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  281  [ TRIAL VERSION ]
Active  192.168.1.255  255.255.255.255  192.168.1.103  281  192.168.1.103 (Broadcom 802.11abgn Wireless SDIO Adapter)
Active  224.0.0.0  240.0.0.0  127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
Active  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  281  [ TRIAL VERSION ]
Active  255.255.255.255  255.255.255.255  127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
Active  255.255.255.255  255.255.255.255  192.168.1.103  281  192.168.1.103 (Broadcom 802.11abgn Wireless SDIO Adapter)


IE Cookie

 
Last Access  URL
2013-11-29 02:39:27  transformer t100@aida64.com/


Browser History

 
Last Access  URL
2013-11-29 02:26:43  Transformer T100@http://www.bing.com/?pc=ASJB
2013-11-29 02:38:39  Transformer T100@http://www.bing.com/search?q=aida64&form=IE10TR&src=IE10TR&pc=ASJB
2013-11-29 02:39:38  [ TRIAL VERSION ]
2013-11-29 02:40:21  Transformer T100@https://www.cleverbridge.com/750/uurl-hjgn7b6zze
2013-11-29 02:40:46  Transformer T100@http://www.bing.com/search?q=aida64+extreme+edition+download&form=IE10TR&src=IE10TR&pc=ASJB
2013-11-29 02:41:02  [ TRIAL VERSION ]
2013-11-29 02:41:41  Transformer T100@http://www.aida64.com/downloads/aida64extreme400exe
2013-11-29 02:42:16  Transformer T100@http://asus13.msn.com/?pc=ASJB
2013-11-29 02:42:16  [ TRIAL VERSION ]
2013-11-29 02:42:32  Transformer T100@http://www.aida64.com/downloads
2013-11-29 02:42:32  Transformer T100@https://accounts.google.com/ServiceLogin?service=wise&passive=1209600&continue=https%3A%2F%2Fdrive.google.com%2F%23&followup=https%3A%2F%2Fdrive.google.com%2F<mpl=drive
2013-11-29 02:44:15  [ TRIAL VERSION ]
2013-11-29 02:44:15  Transformer T100@https://docs.google.com/document/d/1fikY2uBFMVKP4rXahrJZOn-QVEFYfV5ekKwAFPrPTXs/edit
2013-11-29 02:44:15  Transformer T100@https://drive.google.com/?authuser=0


DirectX Files

 
Name  Version  Type  Language  Size  Date
amstream.dll  6.06.9600.16384  Final Retail  English  65536  2013.08.22. 4:53:29
bdaplgin.ax  6.03.9600.16384  Final Retail  Hungarian  72704  2013.08.22. 4:45:11
d3d8.dll  6.03.9600.16384  Final Retail  English  1007104  2013.08.22. 4:57:54
d3d8thk.dll  6.03.9600.16384  Final Retail  English  11776  2013.08.22. 5:06:17
d3d9.dll  6.03.9600.16384  Final Retail  English  1799952  2013.08.22. 6:24:56
d3dim.dll  6.03.9600.16384  Final Retail  English  378368  2013.08.22. 4:59:05
d3dim700.dll  6.03.9600.16384  Final Retail  English  867328  2013.08.22. 3:39:46
d3dramp.dll  6.03.9600.16384  Final Retail  English  690176  2013.08.22. 5:06:33
d3dxof.dll  6.03.9600.16384  Final Retail  English  55808  2013.08.22. 4:54:38
ddraw.dll  6.03.9600.16384  Final Retail  English  527872  2013.08.22. 3:33:31
ddrawex.dll  6.03.9600.16384  Final Retail  English  33280  2013.08.22. 3:46:37
devenum.dll  6.06.9600.16384  Final Retail  English  74856  2013.08.22. 6:19:12
dinput.dll  6.03.9600.16384  Final Retail  English  130048  2013.08.22. 5:00:08
dinput8.dll  6.03.9600.16384  Final Retail  English  162304  2013.08.22. 5:00:49
dmband.dll  6.03.9600.16384  Final Retail  English  31744  2013.08.22. 4:55:01
dmcompos.dll  6.03.9600.16384  Final Retail  English  66048  2013.08.22. 4:54:34
dmime.dll  6.03.9600.16384  Final Retail  English  182272  2013.08.22. 4:53:14
dmloader.dll  6.03.9600.16384  Final Retail  English  36352  2013.08.22. 4:55:19
dmscript.dll  6.03.9600.16384  Final Retail  English  85504  2013.08.22. 4:54:46
dmstyle.dll  6.03.9600.16384  Final Retail  English  110080  2013.08.22. 4:54:37
dmsynth.dll  6.03.9600.16384  Final Retail  English  107008  2013.08.22. 4:54:25
dmusic.dll  6.03.9600.16384  Final Retail  English  97280  2013.08.22. 4:50:48
dplaysvr.exe  6.03.9600.16384  Final Retail  English  8192  2013.08.22. 5:05:19
dplayx.dll  6.03.9600.16384  Final Retail  English  8192  2013.08.22. 5:05:19
dpmodemx.dll  6.03.9600.16384  Final Retail  English  8192  2013.08.22. 5:05:19
dpnaddr.dll  6.03.9600.16384  Final Retail  English  8192  2013.08.22. 5:05:19
dpnet.dll  6.03.9600.16384  Final Retail  English  8192  2013.08.22. 5:05:19
dpnhpast.dll  6.03.9600.16384  Final Retail  English  8192  2013.08.22. 5:05:19
dpnhupnp.dll  6.03.9600.16384  Final Retail  English  8192  2013.08.22. 5:05:19
dpnlobby.dll  6.03.9600.16384  Final Retail  English  8192  2013.08.22. 5:05:19
dpnsvr.exe  6.03.9600.16384  Final Retail  English  8192  2013.08.22. 5:05:19
dpwsockx.dll  6.03.9600.16384  Final Retail  English  8192  2013.08.22. 5:05:19
dsdmo.dll  6.03.9600.16384  Final Retail  English  173568  2013.08.22. 4:54:38
dsound.dll  6.03.9600.16384  Final Retail  English  485888  2013.08.22. 4:50:39
dswave.dll  6.03.9600.16384  Final Retail  English  22016  2013.08.22. 4:55:00
dxdiagn.dll  6.03.9600.16384  Final Retail  English  258560  2013.08.22. 4:13:49
dxmasf.dll  12.00.9600.16384  Final Retail  English  4608  2013.08.22. 5:06:56
encapi.dll  6.03.9600.16384  Final Retail  English  19968  2013.08.22. 3:46:50
gcdef.dll  6.03.9600.16384  Final Retail  English  121856  2013.08.22. 4:50:05
iac25_32.ax  2.00.0005.0053  Final Retail  English  197632  2013.08.22. 2:43:11
ir41_32.ax  6.03.9600.16384  Final Retail  English  9216  2013.08.22. 5:06:35
ir41_qc.dll  6.03.9600.16384  Final Retail  English  8704  2013.08.22. 5:06:32
ir41_qcx.dll  6.03.9600.16384  Final Retail  English  8704  2013.08.22. 5:06:32
ir50_32.dll  6.03.9600.16384  Final Retail  English  9216  2013.08.22. 5:06:34
ir50_qc.dll  6.03.9600.16384  Final Retail  English  8704  2013.08.22. 5:06:33
ir50_qcx.dll  6.03.9600.16384  Final Retail  English  9216  2013.08.22. 5:06:34
ivfsrc.ax  5.10.0002.0051  Final Retail  English  146944  2013.08.22. 2:43:11
joy.cpl  6.03.9600.16384  Final Retail  English  137216  2013.08.22. 4:40:19
ks.sys  6.03.9600.16384  Final Retail  Hungarian  212992  2013.08.22. 5:11:17
ksproxy.ax  6.03.9600.16384  Final Retail  Hungarian  206848  2013.08.22. 4:46:39
kstvtune.ax  6.03.9600.16384  Final Retail  English  85504  2013.08.22. 4:41:45
ksuser.dll  6.03.9600.16384  Final Retail  Hungarian  18616  2013.08.22. 6:19:12
kswdmcap.ax  6.03.9600.16384  Final Retail  English  106496  2013.08.22. 4:49:02
ksxbar.ax  6.03.9600.16384  Final Retail  English  48640  2013.08.22. 4:47:40
mciqtz32.dll  6.06.9600.16384  Final Retail  English  36864  2013.08.22. 4:52:28
mfc40.dll  4.01.0000.6140  Final Retail  English  924944  2013.08.22. 0:35:15
mfc42.dll  6.06.8063.0000  Beta Retail  English  1033728  2013.08.22. 4:11:35
mpeg2data.ax  6.06.9600.16384  Final Retail  Hungarian  73216  2013.08.22. 4:47:47
mpg2splt.ax  6.06.9600.16384  Final Retail  English  197632  2013.08.22. 4:52:58
msdmo.dll  6.06.9600.16384  Final Retail  English  39752  2013.08.22. 6:19:22
msdvbnp.ax  6.06.9600.16384  Final Retail  Hungarian  58880  2013.08.22. 4:47:32
mskssrv.sys  6.03.9600.16384  Final Retail  Hungarian  8448  2013.08.22. 5:11:02
mspclock.sys  6.03.9600.16384  Final Retail  Hungarian  6400  2013.08.22. 5:11:02
mspqm.sys  6.03.9600.16384  Final Retail  Hungarian  6400  2013.08.22. 5:11:02
mstee.sys  6.03.9600.16384  Final Retail  Hungarian  6400  2013.08.22. 5:09:57
msvidctl.dll  6.05.9600.16384  Final Retail  English  2284544  2013.08.22. 4:16:37
msyuv.dll  6.03.9600.16384  Final Retail  English  23552  2013.08.22. 5:03:48
pid.dll  6.03.9600.16384  Final Retail  English  37888  2013.08.22. 5:00:41
psisdecd.dll  6.06.9600.16384  Final Retail  Hungarian  457216  2013.08.22. 4:29:48
psisrndr.ax  6.06.9600.16384  Final Retail  Hungarian  77824  2013.08.22. 4:29:39
qasf.dll  12.00.9600.16384  Final Retail  English  185856  2013.08.22. 4:16:33
qcap.dll  6.06.9600.16384  Final Retail  English  179200  2013.08.22. 4:50:04
qdv.dll  6.06.9600.16384  Final Retail  English  273408  2013.08.22. 4:48:10
qdvd.dll  6.06.9600.16384  Final Retail  English  469504  2013.08.22. 4:47:29
qedit.dll  6.06.9600.16384  Final Retail  English  488448  2013.08.22. 4:28:12
qedwipes.dll  6.06.9600.16384  Final Retail  English  733184  2013.08.22. 5:16:59
quartz.dll  6.06.9600.16384  Final Retail  English  1352192  2013.08.22. 4:18:28
stream.sys  6.03.9600.16384  Final Retail  Hungarian  53888  2013.08.22. 5:10:53
swenum.sys  6.03.9600.16384  Final Retail  Hungarian  13920  2013.08.22. 6:32:57
vbisurf.ax  6.03.9600.16384  Final Retail  English  35328  2013.08.22. 4:47:03
vfwwdm32.dll  6.03.9600.16384  Final Retail  English  53760  2013.08.22. 4:49:22
wsock32.dll  6.03.9600.16384  Final Retail  English  15872  2013.08.22. 5:05:51


DirectX Video

 
[ Primary Display Driver ]
 
DirectDraw Device Properties:
DirectDraw Driver Name  display
DirectDraw Driver Description  Primary Display Driver
Hardware Driver  igdumdim32.dll (10.18.10.3286)
Hardware Description  Intel(R) HD Graphics
 
Direct3D Device Properties:
Rendering Bit Depths  16, 32
Z-Buffer Bit Depths  16, 24, 32
Multisample Anti-Aliasing Modes  MSAA 2x, MSAA 4x, MSAA 8x
Min Texture Size  1 x 1
Max Texture Size  8192 x 8192
Unified Shader Version  5.0
DirectX Hardware Support  DirectX v11.0
 
Direct3D Device Features:
Additive Texture Blending  Supported
AGP Texturing  Not Supported
Anisotropic Filtering  Supported
Automatic Mipmap Generation  Supported
Bilinear Filtering  Supported
Compute Shader  Supported
Cubic Environment Mapping  Supported
Cubic Filtering  Not Supported
Decal-Alpha Texture Blending  Supported
Decal Texture Blending  Supported
DirectX Texture Compression  Not Supported
DirectX Volumetric Texture Compression  Not Supported
Dithering  Supported
Dot3 Texture Blending  Supported
Double-Precision Floating-Point  Supported
Driver Concurrent Creates  Supported
Driver Command Lists  Not Supported
Dynamic Textures  Supported
Edge Anti-Aliasing  Not Supported
Environmental Bump Mapping  Supported
Environmental Bump Mapping + Luminance  Supported
Factor Alpha Blending  Supported
Geometric Hidden-Surface Removal  Not Supported
Geometry Shader  Supported
Guard Band  Supported
Hardware Scene Rasterization  Supported
Hardware Transform & Lighting  Supported
Legacy Depth Bias  Supported
Map On Default Buffers  Supported
Mipmap LOD Bias Adjustments  Supported
Mipmapped Cube Textures  Supported
Mipmapped Volume Textures  Supported
Modulate-Alpha Texture Blending  Supported
Modulate Texture Blending  Supported
Non-Square Textures  Supported
N-Patches  Not Supported
Perspective Texture Correction  Supported
Point Sampling  Supported
Projective Textures  Not Supported
Quintic Bezier Curves & B-Splines  Not Supported
Range-Based Fog  Not Supported
Rectangular & Triangular Patches  Not Supported
Rendering In Windowed Mode  Supported
Runtime Shader Linking  Supported
Scissor Test  Supported
Slope-Scale Based Depth Bias  Supported
Specular Flat Shading  Supported
Specular Gouraud Shading  Supported
Specular Phong Shading  Not Supported
Spherical Mapping  Supported
Stencil Buffers  Supported
Sub-Pixel Accuracy  Supported
Subtractive Texture Blending  Supported
Table Fog  Supported
Texture Alpha Blending  Supported
Texture Clamping  Supported
Texture Mirroring  Supported
Texture Transparency  Supported
Texture Wrapping  Supported
Tiled Resources  Not Supported
Triangle Culling  Not Supported
Trilinear Filtering  Supported
Two-Sided Stencil Test  Supported
Vertex Alpha Blending  Supported
Vertex Fog  Supported
Vertex Tweening  Supported
Volume Textures  Supported
W-Based Fog  Supported
W-Buffering  Not Supported
Z-Based Fog  Supported
Z-Bias  Supported
Z-Test  Supported
 
Supported FourCC Codes:
AI44  Supported
AYUV  Supported
I420  Supported
IA44  Supported
IMC1  Supported
IMC2  Supported
IMC3  Supported
IMC4  Supported
IYUV  Supported
NV11  Supported
NV12  Supported
P208  Supported
UYVY  Supported
VYUY  Supported
YUY2  Supported
YV12  Supported
YVU9  Supported
YVYU  Supported
 
Video Adapter Manufacturer:
Company Name  Intel Corporation
Product Information  http://www.intel.com/products/chipsets
Driver Download  http://support.intel.com/support/graphics
Driver Update  http://www.aida64.com/driver-updates


DirectX Sound

 
[ Primary Sound Driver ]
 
DirectSound Device Properties:
Device Description  Primary Sound Driver
Driver Module  
Primary Buffers  1
Min / Max Secondary Buffers Sample Rate  100 / 200000 Hz
Primary Buffers Sound Formats  8-bit, 16-bit, Mono, Stereo
Secondary Buffers Sound Formats  8-bit, 16-bit, Mono, Stereo
Total / Free Sound Buffers  1 / 0
Total / Free Static Sound Buffers  1 / 0
Total / Free Streaming Sound Buffers  1 / 0
Total / Free 3D Sound Buffers  0 / 0
Total / Free 3D Static Sound Buffers  0 / 0
Total / Free 3D Streaming Sound Buffers  0 / 0
 
DirectSound Device Features:
Certified Driver  No
Emulated Device  No
Precise Sample Rate  Supported
DirectSound3D  Not Supported
Creative EAX 1.0  Not Supported
Creative EAX 2.0  Not Supported
Creative EAX 3.0  Not Supported
Creative EAX 4.0  Not Supported
Creative EAX 5.0  Not Supported
I3DL2  Not Supported
Sensaura ZoomFX  Not Supported
 
[ Speakers (Intel SST Audio Device (WDM)) ]
 
DirectSound Device Properties:
Device Description  Speakers (Intel SST Audio Device (WDM))
Driver Module  {0.0.0.00000000}.{9419bbf8-a5df-4689-8eb1-1e1815b934c5}
Primary Buffers  1
Min / Max Secondary Buffers Sample Rate  100 / 200000 Hz
Primary Buffers Sound Formats  8-bit, 16-bit, Mono, Stereo
Secondary Buffers Sound Formats  8-bit, 16-bit, Mono, Stereo
Total / Free Sound Buffers  1 / 0
Total / Free Static Sound Buffers  1 / 0
Total / Free Streaming Sound Buffers  1 / 0
Total / Free 3D Sound Buffers  0 / 0
Total / Free 3D Static Sound Buffers  0 / 0
Total / Free 3D Streaming Sound Buffers  0 / 0
 
DirectSound Device Features:
Certified Driver  No
Emulated Device  No
Precise Sample Rate  Supported
DirectSound3D  Not Supported
Creative EAX 1.0  Not Supported
Creative EAX 2.0  Not Supported
Creative EAX 3.0  Not Supported
Creative EAX 4.0  Not Supported
Creative EAX 5.0  Not Supported
I3DL2  Not Supported
Sensaura ZoomFX  Not Supported


DirectX Input

 
[ Mouse ]
 
DirectInput Device Properties:
Device Description  Mouse
Device Type  Unknown
Device Subtype  Unknown
Axes  3
Buttons/Keys  3
 
DirectInput Device Features:
Emulated Device  Yes
Alias Device  No
Polled Device  No
Polled Data Format  No
Attack Force Feedback  Not Supported
Deadband Force Feedback  Not Supported
Fade Force Feedback  Not Supported
Force Feedback  Not Supported
Saturation Force Feedback  Not Supported
+/- Force Feedback Coefficients  Not Supported
+/- Force Feedback Saturation  Not Supported
 
[ Keyboard ]
 
DirectInput Device Properties:
Device Description  Keyboard
Device Type  Unknown
Device Subtype  Unknown
Buttons/Keys  128
 
DirectInput Device Features:
Emulated Device  Yes
Alias Device  No
Polled Device  No
Polled Data Format  No
Attack Force Feedback  Not Supported
Deadband Force Feedback  Not Supported
Fade Force Feedback  Not Supported
Force Feedback  Not Supported
Saturation Force Feedback  Not Supported
+/- Force Feedback Coefficients  Not Supported
+/- Force Feedback Saturation  Not Supported
 
[ HIDI2C Device ]
 
DirectInput Device Properties:
Device Description  HIDI2C Device
Device Type  Unknown
Device Subtype  Unknown
 
DirectInput Device Features:
Emulated Device  Yes
Alias Device  No
Polled Device  No
Polled Data Format  No
Attack Force Feedback  Not Supported
Deadband Force Feedback  Not Supported
Fade Force Feedback  Not Supported
Force Feedback  Not Supported
Saturation Force Feedback  Not Supported
+/- Force Feedback Coefficients  Not Supported
+/- Force Feedback Saturation  Not Supported
 
[ ASUS Wireless Radio Control ]
 
DirectInput Device Properties:
Device Description  ASUS Wireless Radio Control
Device Type  Unknown
Device Subtype  Unknown
Buttons/Keys  1
 
DirectInput Device Features:
Emulated Device  Yes
Alias Device  No
Polled Device  No
Polled Data Format  No
Attack Force Feedback  Not Supported
Deadband Force Feedback  Not Supported
Fade Force Feedback  Not Supported
Force Feedback  Not Supported
Saturation Force Feedback  Not Supported
+/- Force Feedback Coefficients  Not Supported
+/- Force Feedback Saturation  Not Supported
 
[ ASUS Base Station(T100) ]
 
DirectInput Device Properties:
Device Description  ASUS Base Station(T100)
Device Type  Unknown
Device Subtype  Unknown
Buttons/Keys  1024
 
DirectInput Device Features:
Emulated Device  Yes
Alias Device  No
Polled Device  No
Polled Data Format  No
Attack Force Feedback  Not Supported
Deadband Force Feedback  Not Supported
Fade Force Feedback  Not Supported
Force Feedback  Not Supported
Saturation Force Feedback  Not Supported
+/- Force Feedback Coefficients  Not Supported
+/- Force Feedback Saturation  Not Supported
 
[ GPIO Button Driver ]
 
DirectInput Device Properties:
Device Description  GPIO Button Driver
Device Type  Unknown
Device Subtype  Unknown
Buttons/Keys  2
 
DirectInput Device Features:
Emulated Device  Yes
Alias Device  No
Polled Device  No
Polled Data Format  No
Attack Force Feedback  Not Supported
Deadband Force Feedback  Not Supported
Fade Force Feedback  Not Supported
Force Feedback  Not Supported
Saturation Force Feedback  Not Supported
+/- Force Feedback Coefficients  Not Supported
+/- Force Feedback Saturation  Not Supported
 
[ ASUS Base Station(T100) ]
 
DirectInput Device Properties:
Device Description  ASUS Base Station(T100)
Device Type  Unknown
Device Subtype  Unknown
Buttons/Keys  1
 
DirectInput Device Features:
Emulated Device  Yes
Alias Device  No
Polled Device  No
Polled Data Format  No
Attack Force Feedback  Not Supported
Deadband Force Feedback  Not Supported
Fade Force Feedback  Not Supported
Force Feedback  Not Supported
Saturation Force Feedback  Not Supported
+/- Force Feedback Coefficients  Not Supported
+/- Force Feedback Saturation  Not Supported
 
[ GPIO Button Driver ]
 
DirectInput Device Properties:
Device Description  GPIO Button Driver
Device Type  Unknown
Device Subtype  Unknown
Buttons/Keys  2
 
DirectInput Device Features:
Emulated Device  Yes
Alias Device  No
Polled Device  No
Polled Data Format  No
Attack Force Feedback  Not Supported
Deadband Force Feedback  Not Supported
Fade Force Feedback  Not Supported
Force Feedback  Not Supported
Saturation Force Feedback  Not Supported
+/- Force Feedback Coefficients  Not Supported
+/- Force Feedback Saturation  Not Supported
 
[ ASUS Base Station(T100) ]
 
DirectInput Device Properties:
Device Description  ASUS Base Station(T100)
Device Type  Unknown
Device Subtype  Unknown
 
DirectInput Device Features:
Emulated Device  Yes
Alias Device  No
Polled Device  No
Polled Data Format  No
Attack Force Feedback  Not Supported
Deadband Force Feedback  Not Supported
Fade Force Feedback  Not Supported
Force Feedback  Not Supported
Saturation Force Feedback  Not Supported
+/- Force Feedback Coefficients  Not Supported
+/- Force Feedback Saturation  Not Supported
 
[ ASUS Base Station(T100) ]
 
DirectInput Device Properties:
Device Description  ASUS Base Station(T100)
Device Type  Unknown
Device Subtype  Unknown
Buttons/Keys  1
 
DirectInput Device Features:
Emulated Device  Yes
Alias Device  No
Polled Device  No
Polled Data Format  No
Attack Force Feedback  Not Supported
Deadband Force Feedback  Not Supported
Fade Force Feedback  Not Supported
Force Feedback  Not Supported
Saturation Force Feedback  Not Supported
+/- Force Feedback Coefficients  Not Supported
+/- Force Feedback Saturation  Not Supported


Windows Devices

 
[ Devices ]
 
Audio inputs and outputs:
Microphone (Intel SST Audio Device (WDM))  6.3.9600.16384
Speakers (Intel SST Audio Device (WDM))  6.3.9600.16384
 
Batteries:
Microsoft AC Adapter  6.3.9600.16384
Microsoft ACPI-Compliant Control Method Battery  6.3.9600.16384
 
Bluetooth:
Bluetooth Radio  6.3.9600.16384
Microsoft Bluetooth Enumerator  6.3.9600.16384
Microsoft Bluetooth LE Enumerator  6.3.9600.16384
 
Computer:
ACPI x86-based PC  6.3.9600.16384
Intel(R) Serial IO DMA Controller  6.3.9600.16384
Intel(R) Serial IO DMA Controller  6.3.9600.16384
 
Disk drives:
Hynix HCG8e  6.3.9600.16384
 
Display adapters:
Intel(R) HD Graphics  10.18.10.3286
 
Firmware:
Device Firmware  6.3.9600.16384
Device Firmware  6.3.9600.16384
System Firmware  6.3.9600.16384
 
Human Interface Devices:
GPIO Buttons Driver  6.3.9600.16384
HID-compliant consumer control device  6.3.9600.16384
HID-compliant consumer control device  6.3.9600.16384
HID-compliant system controller  6.3.9600.16384
HID-compliant system controller  6.3.9600.16384
HID-compliant touch screen  6.3.9600.16384
HID-compliant vendor-defined device  6.3.9600.16384
HID-compliant vendor-defined device  6.3.9600.16384
HID-compliant vendor-defined device  6.3.9600.16384
HID-compliant wireless radio controls  6.3.9600.16384
HID-compliant wireless radio controls  6.3.9600.16384
I2C HID Device  6.3.9600.16384
Sideband GPIO Buttons Injection Device  6.3.9600.16384
USB Input Device  6.3.9600.16384
USB Input Device  6.3.9600.16384
USB Input Device  6.3.9600.16384
 
Imaging devices:
Intel(R) Imaging Signal Processor 2400  603.9471.2006.22226
 
Keyboards:
HID Keyboard Device  6.3.9600.16384
HID Keyboard Device  6.3.9600.16384
 
Mice and other pointing devices:
ASUS Touchpad  3.0.0.13
 
Monitors:
Generic PnP Monitor  6.3.9600.16384
 
Network adapters:
Bluetooth Device (Personal Area Network)  6.3.9600.16384
Bluetooth Device (RFCOMM Protocol TDI)  6.3.9600.16384
Broadcom 802.11abgn Wireless SDIO Adapter  5.93.98.187
Microsoft ISATAP Adapter  6.3.9600.16384
Microsoft Kernel Debug Network Adapter  6.3.9600.16384
Microsoft Wi-Fi Direct Virtual Adapter  6.3.9600.16384
Teredo Tunneling Pseudo-Interface  6.3.9600.16384
 
Print queues:
Fax  6.3.9600.16384
Microsoft XPS Document Writer  6.3.9600.16384
Root Print Queue  6.3.9600.16384
 
Processors:
Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz  6.3.9600.16384
Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz  6.3.9600.16384
Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz  6.3.9600.16384
Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz  6.3.9600.16384
 
SD host adapters:
Intel SD Host Controller  6.3.9600.16384
Intel SD Host Controller  6.3.9600.16384
Intel SD Host Controller  6.3.9600.16384
 
Security devices:
Trusted Platform Module 2.0  6.3.9600.16384
 
Sensors:
Capella Micro CM3218x Ambient Light Sensor  1.0.4.0
InvenSense Sensor Collection  15.21.25.385
Simple Device Orientation Sensor  6.3.9600.16384
 
Software devices:
Lightweight Sensors Root Enumerator  6.3.9600.16384
Microsoft IPv4 IPv6 Transition Adapter Bus  6.3.9600.16384
Smart Card Device Enumeration Bus  6.3.9600.16384
 
Sound, video and game controllers:
Intel SST Audio Device (WDM)  603.9477.1948.22218
Realtek I2S Audio Codec  6.2.9400.4028
 
Storage controllers:
Microsoft Storage Spaces Controller  6.3.9600.16384
SD Storage Class Controller  6.3.9600.16384
 
Storage volume shadow copies:
Generic volume shadow copy  6.3.9600.16384
Generic volume shadow copy  6.3.9600.16384
 
Storage volumes:
Generic volume  6.3.9600.16384
Generic volume  6.3.9600.16384
Generic volume  6.3.9600.16384
Generic volume  6.3.9600.16384
Generic volume  6.3.9600.16384
 
System devices:
ACPI Lid  6.3.9600.16384
ACPI Processor Aggregator  6.3.9600.16384
ACPI Sleep Button  6.3.9600.16384
ACPI Thermal Zone  6.3.9600.16384
ASUS Wireless Radio Control  1.0.0.2
bcmfn2 Device  5.93.98.187
Broadcom Serial Bus Driver over UART Bus Enumerator  12.0.0.7600
Camera Sensor MT9M114  603.9471.2006.22226
Composite Bus Enumerator  6.3.9600.16384
High precision event timer  6.3.9600.16384
Intel(R) 82802 Firmware Hub Device  6.3.9600.16384
Intel(R) Atom(TM) Processor GPIO Controller  603.9477.2067.21807
Intel(R) Atom(TM) Processor GPIO Controller  603.9477.2067.21807
Intel(R) Atom(TM) Processor GPIO Controller  603.9477.2067.21807
Intel(R) Atom(TM) Processor GpioVirtual Controller  603.9456.2067.10791
Intel(R) Atom(TM) Processor I2C Controller  603.9477.2067.21806
Intel(R) Atom(TM) Processor I2C Controller  603.9477.2067.21806
Intel(R) Atom(TM) Processor I2C Controller  603.9477.2067.21806
Intel(R) Atom(TM) Processor I2C Controller  603.9477.2067.21806
Intel(R) Atom(TM) Processor I2C Controller  603.9477.2067.21806
Intel(R) Atom(TM) Processor I2C Controller  603.9477.2067.21806
Intel(R) Atom(TM) Processor I2C Controller  603.9477.2067.21806
Intel(R) Atom(TM) Processor SPI Controller  603.9477.2067.21808
Intel(R) Atom(TM) Processor UART Controller  603.9456.2067.17601
Intel(R) Dynamic Platform & Thermal Framework Display Participant Driver  7.1.0.144
Intel(R) Dynamic Platform & Thermal Framework Driver  7.1.0.144
Intel(R) Dynamic Platform & Thermal Framework Generic Participant Driver  7.1.0.144
Intel(R) Dynamic Platform & Thermal Framework Generic Participant Driver  7.1.0.144
Intel(R) Dynamic Platform & Thermal Framework Generic Participant Driver  7.1.0.144
Intel(R) Dynamic Platform & Thermal Framework Power Participant Driver  7.1.0.144
Intel(R) Dynamic Platform & Thermal Framework Processor Participant Driver  7.1.0.144
Intel(R) Power Engine Plug-in  6.3.9600.16384
Intel(R) Power Management IC Device  603.9456.2067.19226
Intel(R) Sideband Fabric Device  603.9448.2067.15591
Intel(R) Trusted Execution Engine Interface  1.0.0.1054
IWD Bus Enumerator  4.5.23.0
Microsoft ACPI-Compliant System  6.3.9600.16384
Microsoft Basic Display Driver  6.3.9600.16384
Microsoft Basic Render Driver  6.3.9600.16384
Microsoft System Management BIOS Driver  6.3.9600.16384
Microsoft UEFI-Compliant System  6.3.9600.16384
Microsoft Virtual Drive Enumerator  6.3.9600.16384
Microsoft Windows Management Interface for ACPI  6.3.9600.16384
Motherboard resources  6.3.9600.16384
Motherboard resources  6.3.9600.16384
Motherboard resources  6.3.9600.16384
NDIS Virtual Network Adapter Enumerator  6.3.9600.16384
PCI Express Root Complex  6.3.9600.16384
PCI standard host CPU bridge  6.3.9600.16384
PCI standard ISA bridge  6.3.9600.16384
Plug and Play Software Device Enumerator  6.3.9600.16384
Programmable interrupt controller  6.3.9600.16384
Remote Desktop Device Redirector Bus  6.3.9600.16384
System CMOS/real time clock  6.3.9600.16384
System timer  6.3.9600.16384
UMBus Root Bus Enumerator  6.3.9600.16384
Volume Manager  6.3.9600.16384
 
Universal Serial Bus controllers:
Intel(R) USB 3.0 eXtensible Host Controller - 0100 (Microsoft)  6.3.9600.16384
USB Composite Device  6.3.9600.16384
USB Root Hub (xHCI)  6.3.9600.16384
 
Unknown:
Unknown  
 
[ Audio inputs and outputs / Microphone (Intel SST Audio Device (WDM)) ]
 
Device Properties:
Driver Description  Microphone (Intel SST Audio Device (WDM))
Driver Date  2013.08.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  AudioEndpoint.inf
Hardware ID  MMDEVAPI\AudioEndpoints
 
[ Audio inputs and outputs / Speakers (Intel SST Audio Device (WDM)) ]
 
Device Properties:
Driver Description  Speakers (Intel SST Audio Device (WDM))
Driver Date  2013.08.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  AudioEndpoint.inf
Hardware ID  MMDEVAPI\AudioEndpoints
 
[ Batteries / Microsoft AC Adapter ]
 
Device Properties:
Driver Description  Microsoft AC Adapter
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  cmbatt.inf
Hardware ID  ACPI\VEN_ACPI&DEV_0003
 
[ Batteries / Microsoft ACPI-Compliant Control Method Battery ]
 
Device Properties:
Driver Description  Microsoft ACPI-Compliant Control Method Battery
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  cmbatt.inf
Hardware ID  ACPI\VEN_PNP&DEV_0C0A
 
[ Bluetooth / Bluetooth Radio ]
 
Device Properties:
Driver Description  Bluetooth Radio
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  bth.inf
Hardware ID  BCMBTBUS\BLUETOOTH
Location Information  Serial HCI Bus - Bluetooth Function
 
[ Bluetooth / Microsoft Bluetooth Enumerator ]
 
Device Properties:
Driver Description  Microsoft Bluetooth Enumerator
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  bth.inf
Hardware ID  BTH\MS_BTHBRB
 
[ Bluetooth / Microsoft Bluetooth LE Enumerator ]
 
Device Properties:
Driver Description  Microsoft Bluetooth LE Enumerator
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  bthleenum.inf
Hardware ID  BTH\MS_BTHLE
 
[ Computer / ACPI x86-based PC ]
 
Device Properties:
Driver Description  ACPI x86-based PC
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  hal.inf
Hardware ID  acpiapic
 
[ Computer / Intel(R) Serial IO DMA Controller ]
 
Device Properties:
Driver Description  Intel(R) Serial IO DMA Controller
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  halextintclpiodma.inf
Hardware ID  ACPI\VEN_INTL&DEV_9C60
 
[ Computer / Intel(R) Serial IO DMA Controller ]
 
Device Properties:
Driver Description  Intel(R) Serial IO DMA Controller
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  halextintclpiodma.inf
Hardware ID  ACPI\VEN_INTL&DEV_9C60
 
[ Disk drives / Hynix HCG8e ]
 
Device Properties:
Driver Description  Hynix HCG8e
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  disk.inf
Hardware ID  SD\GenDisk
Location Information  Bus Number 1, Target Id 2, LUN 0
 
[ Display adapters / Intel(R) HD Graphics ]
 
Device Properties:
Driver Description  Intel(R) HD Graphics
Driver Date  2013.08.28.
Driver Version  10.18.10.3286
Driver Provider  Intel Corporation
INF File  oem13.inf
Hardware ID  PCI\VEN_8086&DEV_0F31&SUBSYS_14ED1043&REV_09
Location Information  PCI bus 0, device 2, function 0
PCI Device  Intel Bay Trail-T SoC - Integrated Graphics Controller
 
Device Resources:
IRQ  65536
Memory  80000000-8FFFFFFF
Memory  90000000-903FFFFF
Port  1000-1007
 
Video Adapter Manufacturer:
Company Name  Intel Corporation
Product Information  http://www.intel.com/products/chipsets
Driver Download  http://support.intel.com/support/graphics
Driver Update  http://www.aida64.com/driver-updates
 
[ Firmware / Device Firmware ]
 
Device Properties:
Driver Description  Device Firmware
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  c_firmware.inf
Hardware ID  UEFI\RES_{28442815-3981-2336-1715-662259671897}&REV_1
 
[ Firmware / Device Firmware ]
 
Device Properties:
Driver Description  Device Firmware
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  c_firmware.inf
Hardware ID  UEFI\RES_{5a1c0d8b-8bb8-4a4f-bcc6-ac570d543294}&REV_1
 
[ Firmware / System Firmware ]
 
Device Properties:
Driver Description  System Firmware
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  c_firmware.inf
Hardware ID  UEFI\RES_{b122a262-3551-4f48-8892-55f6c0614290}&REV_1
 
[ Human Interface Devices / GPIO Buttons Driver ]
 
Device Properties:
Driver Description  GPIO Buttons Driver
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  msgpiowin32.inf
Hardware ID  ACPI\VEN_INT&DEV_CFD9
 
Device Resources:
IRQ  1029
IRQ  1030
IRQ  1031
IRQ  1032
IRQ  1033
 
[ Human Interface Devices / HID-compliant consumer control device ]
 
Device Properties:
Driver Description  HID-compliant consumer control device
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  hidserv.inf
Hardware ID  HID\VID_0B05&PID_17E0&REV_0238&MI_01&Col01
 
[ Human Interface Devices / HID-compliant consumer control device ]
 
Device Properties:
Driver Description  HID-compliant consumer control device
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  hidserv.inf
Hardware ID  HID\VEN_INT&DEV_CFD9&Col02
 
[ Human Interface Devices / HID-compliant system controller ]
 
Device Properties:
Driver Description  HID-compliant system controller
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  input.inf
Hardware ID  HID\VID_0B05&PID_17E0&REV_0238&MI_01&Col02
 
[ Human Interface Devices / HID-compliant system controller ]
 
Device Properties:
Driver Description  HID-compliant system controller
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  input.inf
Hardware ID  HID\VEN_INT&DEV_CFD9&Col03
 
[ Human Interface Devices / HID-compliant touch screen ]
 
Device Properties:
Driver Description  HID-compliant touch screen
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  input.inf
Hardware ID  HID\VEN_ATML&DEV_1000&Col01
 
[ Human Interface Devices / HID-compliant vendor-defined device ]
 
Device Properties:
Driver Description  HID-compliant vendor-defined device
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  input.inf
Hardware ID  HID\VID_0B05&PID_17E0&REV_0238&MI_01&Col03
 
[ Human Interface Devices / HID-compliant vendor-defined device ]
 
Device Properties:
Driver Description  HID-compliant vendor-defined device
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  input.inf
Hardware ID  HID\VID_0B05&PID_17E0&REV_0238&MI_02&Col02
 
[ Human Interface Devices / HID-compliant vendor-defined device ]
 
Device Properties:
Driver Description  HID-compliant vendor-defined device
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  input.inf
Hardware ID  HID\VEN_ATML&DEV_1000&Col02
 
[ Human Interface Devices / HID-compliant wireless radio controls ]
 
Device Properties:
Driver Description  HID-compliant wireless radio controls
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  input.inf
Hardware ID  HID\VEN_ATK&DEV_4001
 
[ Human Interface Devices / HID-compliant wireless radio controls ]
 
Device Properties:
Driver Description  HID-compliant wireless radio controls
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  input.inf
Hardware ID  HID\VID_0B05&PID_17E0&REV_0238&MI_01&Col04
 
[ Human Interface Devices / I2C HID Device ]
 
Device Properties:
Driver Description  I2C HID Device
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  hidi2c.inf
Hardware ID  ACPI\VEN_ATML&DEV_1000
 
Device Resources:
IRQ  69
 
[ Human Interface Devices / Sideband GPIO Buttons Injection Device ]
 
Device Properties:
Driver Description  Sideband GPIO Buttons Injection Device
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  msgpiowin32.inf
Hardware ID  {30ebfbf8-df5f-4d4d-9fc5-a26c7fd1df4a}\GPIO_Buttons
 
[ Human Interface Devices / USB Input Device ]
 
Device Properties:
Driver Description  USB Input Device
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  input.inf
Hardware ID  USB\VID_0B05&PID_17E0&REV_0238&MI_00
Location Information  0000.0014.0000.003.000.000.000.000.000
 
[ Human Interface Devices / USB Input Device ]
 
Device Properties:
Driver Description  USB Input Device
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  input.inf
Hardware ID  USB\VID_0B05&PID_17E0&REV_0238&MI_01
Location Information  0000.0014.0000.003.000.000.000.000.000
 
[ Human Interface Devices / USB Input Device ]
 
Device Properties:
Driver Description  USB Input Device
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  input.inf
Hardware ID  USB\VID_0B05&PID_17E0&REV_0238&MI_02
Location Information  0000.0014.0000.003.000.000.000.000.000
 
[ Imaging devices / Intel(R) Imaging Signal Processor 2400 ]
 
Device Properties:
Driver Description  Intel(R) Imaging Signal Processor 2400
Driver Date  2013.08.23.
Driver Version  603.9471.2006.22226
Driver Provider  Intel
INF File  oem17.inf
Hardware ID  VIDEO\VEN_8086&DEV_0F31&SUBSYS_14ED1043&REV_09&INT0F38
 
Device Resources:
Memory  90C00000-90FFFFFF
 
[ Keyboards / HID Keyboard Device ]
 
Device Properties:
Driver Description  HID Keyboard Device
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  keyboard.inf
Hardware ID  HID\VID_0B05&PID_17E0&REV_0238&MI_00
 
[ Keyboards / HID Keyboard Device ]
 
Device Properties:
Driver Description  HID Keyboard Device
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  keyboard.inf
Hardware ID  HID\VEN_INT&DEV_CFD9&Col01
 
[ Mice and other pointing devices / ASUS Touchpad ]
 
Device Properties:
Driver Description  ASUS Touchpad
Driver Date  2013.08.31.
Driver Version  3.0.0.13
Driver Provider  ASUS
INF File  oem24.inf
Hardware ID  HID\VID_0B05&PID_17E0&REV_0238&MI_02&Col01
 
[ Monitors / Generic PnP Monitor ]
 
Device Properties:
Driver Description  Generic PnP Monitor
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  monitor.inf
Hardware ID  MONITOR\CMN1001
 
[ Network adapters / Bluetooth Device (Personal Area Network) ]
 
Device Properties:
Driver Description  Bluetooth Device (Personal Area Network)
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  bthpan.inf
Hardware ID  BTH\MS_BTHPAN
 
[ Network adapters / Bluetooth Device (RFCOMM Protocol TDI) ]
 
Device Properties:
Driver Description  Bluetooth Device (RFCOMM Protocol TDI)
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  tdibth.inf
Hardware ID  BTH\MS_RFCOMM
 
[ Network adapters / Broadcom 802.11abgn Wireless SDIO Adapter ]
 
Device Properties:
Driver Description  Broadcom 802.11abgn Wireless SDIO Adapter
Driver Date  2013.10.02.
Driver Version  5.93.98.187
Driver Provider  Broadcom
INF File  oem26.inf
Hardware ID  SD\VID_02d0&PID_4324&FN_1
 
Device Resources:
IRQ  73
 
Network Adapter Manufacturer:
Company Name  Broadcom Corporation
Product Information  http://www.broadcom.com/products
Driver Download  http://www.broadcom.com/support/ethernet_nic
Driver Update  http://www.aida64.com/driver-updates
 
[ Network adapters / Microsoft ISATAP Adapter ]
 
Device Properties:
Driver Description  Microsoft ISATAP Adapter
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  nettun.inf
Hardware ID  *ISATAP
 
[ Network adapters / Microsoft Kernel Debug Network Adapter ]
 
Device Properties:
Driver Description  Microsoft Kernel Debug Network Adapter
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  kdnic.inf
Hardware ID  root\kdnic
 
[ Network adapters / Microsoft Wi-Fi Direct Virtual Adapter ]
 
Device Properties:
Driver Description  Microsoft Wi-Fi Direct Virtual Adapter
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  netvwifimp.inf
Hardware ID  {5d624f94-8850-40c3-a3fa-a4fd2080baf3}\vwifimp_wfd
Location Information  VWiFi Bus 0
 
[ Network adapters / Teredo Tunneling Pseudo-Interface ]
 
Device Properties:
Driver Description  Teredo Tunneling Pseudo-Interface
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  nettun.inf
Hardware ID  *TEREDO
 
[ Print queues / Fax ]
 
Device Properties:
Driver Description  Fax
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  PrintQueue.inf
Hardware ID  PRINTENUM\microsoftmicrosoft_s7d14
 
[ Print queues / Microsoft XPS Document Writer ]
 
Device Properties:
Driver Description  Microsoft XPS Document Writer
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  PrintQueue.inf
Hardware ID  PRINTENUM\{0f4130dd-19c7-7ab6-99a1-980f03b2ee4e}
 
[ Print queues / Root Print Queue ]
 
Device Properties:
Driver Description  Root Print Queue
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  PrintQueue.inf
Hardware ID  PRINTENUM\LocalPrintQueue
 
[ Processors / Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz ]
 
Device Properties:
Driver Description  Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz
Driver Date  2009.04.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  cpu.inf
Hardware ID  ACPI\GenuineIntel_-_x86_Family_6_Model_55
 
[ Processors / Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz ]
 
Device Properties:
Driver Description  Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz
Driver Date  2009.04.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  cpu.inf
Hardware ID  ACPI\GenuineIntel_-_x86_Family_6_Model_55
 
[ Processors / Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz ]
 
Device Properties:
Driver Description  Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz
Driver Date  2009.04.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  cpu.inf
Hardware ID  ACPI\GenuineIntel_-_x86_Family_6_Model_55
 
[ Processors / Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz ]
 
Device Properties:
Driver Description  Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz
Driver Date  2009.04.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  cpu.inf
Hardware ID  ACPI\GenuineIntel_-_x86_Family_6_Model_55
 
[ SD host adapters / Intel SD Host Controller ]
 
Device Properties:
Driver Description  Intel SD Host Controller
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  sdbus.inf
Hardware ID  ACPI\VEN_8086&DEV_0F14
 
Device Resources:
IRQ  44
Memory  90959000-90959FFF
 
[ SD host adapters / Intel SD Host Controller ]
 
Device Properties:
Driver Description  Intel SD Host Controller
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  sdbus.inf
Hardware ID  ACPI\VEN_INT&DEV_33BB&REV_0002
 
Device Resources:
IRQ  46
Memory  90905000-90905FFF
 
[ SD host adapters / Intel SD Host Controller ]
 
Device Properties:
Driver Description  Intel SD Host Controller
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  sdbus.inf
Hardware ID  ACPI\VEN_8086&DEV_0F14
 
Device Resources:
IRQ  1027
IRQ  47
Memory  9090B000-9090BFFF
 
[ Security devices / Trusted Platform Module 2.0 ]
 
Device Properties:
Driver Description  Trusted Platform Module 2.0
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  tpm.inf
Hardware ID  ACPI\VEN_MSFT&DEV_0101
 
Device Resources:
Memory  7FF00000-7FF00FFF
 
[ Sensors / Capella Micro CM3218x Ambient Light Sensor ]
 
Device Properties:
Driver Description  Capella Micro CM3218x Ambient Light Sensor
Driver Date  2013.06.06.
Driver Version  1.0.4.0
Driver Provider  Capella Microsystems
INF File  oem22.inf
Hardware ID  ACPI\VEN_CPLM&DEV_3218
 
Device Resources:
IRQ  51
 
[ Sensors / InvenSense Sensor Collection ]
 
Device Properties:
Driver Description  InvenSense Sensor Collection
Driver Date  2013.08.27.
Driver Version  15.21.25.385
Driver Provider  InvenSense
INF File  oem25.inf
Hardware ID  ACPI\VEN_INVN&DEV_6500
 
Device Resources:
IRQ  68
 
[ Sensors / Simple Device Orientation Sensor ]
 
Device Properties:
Driver Description  Simple Device Orientation Sensor
Driver Date  2009.04.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  sensorsservicedriver.inf
Hardware ID  Sensors\SensorsServiceDriver
 
[ Software devices / Lightweight Sensors Root Enumerator ]
 
Device Properties:
Driver Description  Lightweight Sensors Root Enumerator
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  c_swdevice.inf
 
[ Software devices / Microsoft IPv4 IPv6 Transition Adapter Bus ]
 
Device Properties:
Driver Description  Microsoft IPv4 IPv6 Transition Adapter Bus
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  c_swdevice.inf
 
[ Software devices / Smart Card Device Enumeration Bus ]
 
Device Properties:
Driver Description  Smart Card Device Enumeration Bus
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  c_swdevice.inf
Hardware ID  root\scdeviceenum
 
[ Sound, video and game controllers / Intel SST Audio Device (WDM) ]
 
Device Properties:
Driver Description  Intel SST Audio Device (WDM)
Driver Date  2013.08.22.
Driver Version  603.9477.1948.22218
Driver Provider  Intel
INF File  oem10.inf
Hardware ID  ACPI\VEN_8086&DEV_0F28&SUBSYS_80867270
 
Device Resources:
IRQ  1037
IRQ  24
IRQ  25
IRQ  26
IRQ  27
IRQ  28
IRQ  29
Memory  20000000-200FFFFF
Memory  90900000-90900FFF
Memory  90A00000-90BFFFFF
 
Device Manufacturer:
Company Name  Intel Corporation
Product Information  http://www.intel.com/products/chipsets
Driver Download  http://support.intel.com/support/chipsets
Driver Update  http://www.aida64.com/driver-updates
 
[ Sound, video and game controllers / Realtek I2S Audio Codec ]
 
Device Properties:
Driver Description  Realtek I2S Audio Codec
Driver Date  2013.08.30.
Driver Version  6.2.9400.4028
Driver Provider  REALTEK
INF File  oem16.inf
Hardware ID  ACPI\VEN_10EC&DEV_5640&SUBSYS_104314ED
 
Device Resources:
IRQ  1028
 
Device Manufacturer:
Company Name  Realtek Semiconductor Corp.
Product Information  http://www.realtek.com.tw/products/productsView.aspx?Langid=1&PNid=8&PFid=14&Level=3&Conn=2
Driver Download  http://www.realtek.com.tw/downloads
Driver Update  http://www.aida64.com/driver-updates
 
[ Storage controllers / Microsoft Storage Spaces Controller ]
 
Device Properties:
Driver Description  Microsoft Storage Spaces Controller
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  spaceport.inf
Hardware ID  Root\Spaceport
 
[ Storage controllers / SD Storage Class Controller ]
 
Device Properties:
Driver Description  SD Storage Class Controller
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  sdstor.inf
Hardware ID  SD\VID_90&OID_004a&PID_HCG8e&REV_8.2
 
[ Storage volume shadow copies / Generic volume shadow copy ]
 
Device Properties:
Driver Description  Generic volume shadow copy
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  volsnap.inf
Hardware ID  STORAGE\VolumeSnapshot
 
[ Storage volume shadow copies / Generic volume shadow copy ]
 
Device Properties:
Driver Description  Generic volume shadow copy
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  volsnap.inf
Hardware ID  STORAGE\VolumeSnapshot
 
[ Storage volumes / Generic volume ]
 
Device Properties:
Driver Description  Generic volume
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  volume.inf
Hardware ID  STORAGE\Volume
 
[ Storage volumes / Generic volume ]
 
Device Properties:
Driver Description  Generic volume
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  volume.inf
Hardware ID  STORAGE\Volume
 
[ Storage volumes / Generic volume ]
 
Device Properties:
Driver Description  Generic volume
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  volume.inf
Hardware ID  STORAGE\Volume
 
[ Storage volumes / Generic volume ]
 
Device Properties:
Driver Description  Generic volume
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  volume.inf
Hardware ID  STORAGE\Volume
 
[ Storage volumes / Generic volume ]
 
Device Properties:
Driver Description  Generic volume
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  volume.inf
Hardware ID  STORAGE\Volume
 
[ System devices / ACPI Lid ]
 
Device Properties:
Driver Description  ACPI Lid
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  machine.inf
Hardware ID  ACPI\VEN_PNP&DEV_0C0D
 
[ System devices / ACPI Processor Aggregator ]
 
Device Properties:
Driver Description  ACPI Processor Aggregator
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  acpipagr.inf
Hardware ID  ACPI\VEN_ACPI&DEV_000C
 
[ System devices / ACPI Sleep Button ]
 
Device Properties:
Driver Description  ACPI Sleep Button
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  machine.inf
Hardware ID  ACPI\VEN_PNP&DEV_0C0E
 
[ System devices / ACPI Thermal Zone ]
 
Device Properties:
Driver Description  ACPI Thermal Zone
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  machine.inf
Hardware ID  ACPI\ThermalZone
 
[ System devices / ASUS Wireless Radio Control ]
 
Device Properties:
Driver Description  ASUS Wireless Radio Control
Driver Date  2013.08.06.
Driver Version  1.0.0.2
Driver Provider  ASUS
INF File  oem23.inf
Hardware ID  ACPI\VEN_ATK&DEV_4001
 
[ System devices / bcmfn2 Device ]
 
Device Properties:
Driver Description  bcmfn2 Device
Driver Date  2013.10.02.
Driver Version  5.93.98.187
Driver Provider  Broadcom
INF File  oem27.inf
Hardware ID  SD\VID_02d0&PID_4324&FN_2
 
[ System devices / Broadcom Serial Bus Driver over UART Bus Enumerator ]
 
Device Properties:
Driver Description  Broadcom Serial Bus Driver over UART Bus Enumerator
Driver Date  2013.08.07.
Driver Version  12.0.0.7600
Driver Provider  Broadcom
INF File  oem21.inf
Hardware ID  ACPI\VEN_BCM&DEV_2E39
 
Device Resources:
IRQ  70
 
[ System devices / Camera Sensor MT9M114 ]
 
Device Properties:
Driver Description  Camera Sensor MT9M114
Driver Date  2013.08.23.
Driver Version  603.9471.2006.22226
Driver Provider  Intel Corporation
INF File  oem18.inf
Hardware ID  ACPI\VEN_INT&DEV_33F0&SUBSYS_INTL0000
 
[ System devices / Composite Bus Enumerator ]
 
Device Properties:
Driver Description  Composite Bus Enumerator
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  CompositeBus.inf
Hardware ID  ROOT\CompositeBus
 
[ System devices / High precision event timer ]
 
Device Properties:
Driver Description  High precision event timer
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  machine.inf
Hardware ID  ACPI\VEN_PNP&DEV_0103
 
[ System devices / Intel(R) 82802 Firmware Hub Device ]
 
Device Properties:
Driver Description  Intel(R) 82802 Firmware Hub Device
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  machine.inf
Hardware ID  ACPI\VEN_INT&DEV_0800
 
[ System devices / Intel(R) Atom(TM) Processor GPIO Controller ]
 
Device Properties:
Driver Description  Intel(R) Atom(TM) Processor GPIO Controller
Driver Date  2013.08.19.
Driver Version  603.9477.2067.21807
Driver Provider  Intel Corporation
INF File  oem4.inf
Hardware ID  ACPI\VEN_INT&DEV_33FC
 
Device Resources:
IRQ  49
Memory  FED0C000-FED0CFFF
 
[ System devices / Intel(R) Atom(TM) Processor GPIO Controller ]
 
Device Properties:
Driver Description  Intel(R) Atom(TM) Processor GPIO Controller
Driver Date  2013.08.19.
Driver Version  603.9477.2067.21807
Driver Provider  Intel Corporation
INF File  oem4.inf
Hardware ID  ACPI\VEN_INT&DEV_33FC
 
Device Resources:
IRQ  48
Memory  FED0D000-FED0DFFF
 
[ System devices / Intel(R) Atom(TM) Processor GPIO Controller ]
 
Device Properties:
Driver Description  Intel(R) Atom(TM) Processor GPIO Controller
Driver Date  2013.08.19.
Driver Version  603.9477.2067.21807
Driver Provider  Intel Corporation
INF File  oem4.inf
Hardware ID  ACPI\VEN_INT&DEV_33FC
 
Device Resources:
IRQ  50
Memory  FED0E000-FED0EFFF
 
[ System devices / Intel(R) Atom(TM) Processor GpioVirtual Controller ]
 
Device Properties:
Driver Description  Intel(R) Atom(TM) Processor GpioVirtual Controller
Driver Date  2013.03.14.
Driver Version  603.9456.2067.10791
Driver Provider  Intel Corporation
INF File  oem7.inf
Hardware ID  ACPI\VEN_INT&DEV_0002&REV_0004
 
Device Resources:
IRQ  09
 
[ System devices / Intel(R) Atom(TM) Processor I2C Controller ]
 
Device Properties:
Driver Description  Intel(R) Atom(TM) Processor I2C Controller
Driver Date  2013.08.19.
Driver Version  603.9477.2067.21806
Driver Provider  Intel Corporation
INF File  oem3.inf
Hardware ID  ACPI\VEN_8086&DEV_0F41&REV_0004
 
Device Resources:
DMA  00
DMA  01
IRQ  -1869283296
Memory  9091A000-9091AFFF
 
[ System devices / Intel(R) Atom(TM) Processor I2C Controller ]
 
Device Properties:
Driver Description  Intel(R) Atom(TM) Processor I2C Controller
Driver Date  2013.08.19.
Driver Version  603.9477.2067.21806
Driver Provider  Intel Corporation
INF File  oem3.inf
Hardware ID  ACPI\VEN_8086&DEV_0F41&REV_0004
 
Device Resources:
DMA  02
DMA  03
IRQ  -1869283295
Memory  90920000-90920FFF
 
[ System devices / Intel(R) Atom(TM) Processor I2C Controller ]
 
Device Properties:
Driver Description  Intel(R) Atom(TM) Processor I2C Controller
Driver Date  2013.08.19.
Driver Version  603.9477.2067.21806
Driver Provider  Intel Corporation
INF File  oem3.inf
Hardware ID  ACPI\VEN_8086&DEV_0F41&REV_0004
 
Device Resources:
DMA  04
DMA  05
IRQ  -1869283294
Memory  90926000-90926FFF
 
[ System devices / Intel(R) Atom(TM) Processor I2C Controller ]
 
Device Properties:
Driver Description  Intel(R) Atom(TM) Processor I2C Controller
Driver Date  2013.08.19.
Driver Version  603.9477.2067.21806
Driver Provider  Intel Corporation
INF File  oem3.inf
Hardware ID  ACPI\VEN_8086&DEV_0F41&REV_0004
 
Device Resources:
DMA  06
DMA  07
IRQ  -1869283293
Memory  9092C000-9092CFFF
 
[ System devices / Intel(R) Atom(TM) Processor I2C Controller ]
 
Device Properties:
Driver Description  Intel(R) Atom(TM) Processor I2C Controller
Driver Date  2013.08.19.
Driver Version  603.9477.2067.21806
Driver Provider  Intel Corporation
INF File  oem3.inf
Hardware ID  ACPI\VEN_8086&DEV_0F41&REV_0004
 
Device Resources:
DMA  00
DMA  01
IRQ  -1869283292
Memory  90932000-90932FFF
 
[ System devices / Intel(R) Atom(TM) Processor I2C Controller ]
 
Device Properties:
Driver Description  Intel(R) Atom(TM) Processor I2C Controller
Driver Date  2013.08.19.
Driver Version  603.9477.2067.21806
Driver Provider  Intel Corporation
INF File  oem3.inf
Hardware ID  ACPI\VEN_8086&DEV_0F41&REV_0004
 
Device Resources:
DMA  02
DMA  03
IRQ  -1869283291
Memory  90938000-90938FFF
 
[ System devices / Intel(R) Atom(TM) Processor I2C Controller ]
 
Device Properties:
Driver Description  Intel(R) Atom(TM) Processor I2C Controller
Driver Date  2013.08.19.
Driver Version  603.9477.2067.21806
Driver Provider  Intel Corporation
INF File  oem3.inf
Hardware ID  ACPI\VEN_8086&DEV_0F41&REV_0004
 
Device Resources:
DMA  04
DMA  05
IRQ  -1869283290
Memory  9093E000-9093EFFF
 
[ System devices / Intel(R) Atom(TM) Processor SPI Controller ]
 
Device Properties:
Driver Description  Intel(R) Atom(TM) Processor SPI Controller
Driver Date  2013.08.19.
Driver Version  603.9477.2067.21808
Driver Provider  Intel Corporation
INF File  oem6.inf
Hardware ID  ACPI\VEN_8086&DEV_0F0E&REV_0004
 
Device Resources:
DMA  00
DMA  01
IRQ  41
Memory  90953000-90953FFF
 
[ System devices / Intel(R) Atom(TM) Processor UART Controller ]
 
Device Properties:
Driver Description  Intel(R) Atom(TM) Processor UART Controller
Driver Date  2013.06.21.
Driver Version  603.9456.2067.17601
Driver Provider  Intel Corporation
INF File  oem5.inf
Hardware ID  ACPI\VEN_8086&DEV_0F0A&REV_0004
 
Device Resources:
DMA  02
DMA  03
IRQ  39
Memory  9094D000-9094DFFF
 
[ System devices / Intel(R) Dynamic Platform & Thermal Framework Display Participant Driver ]
 
Device Properties:
Driver Description  Intel(R) Dynamic Platform & Thermal Framework Display Participant Driver
Driver Date  2013.08.19.
Driver Version  7.1.0.144
Driver Provider  Intel
INF File  oem12.inf
Hardware ID  ACPI\VEN_INT&DEV_3406
 
[ System devices / Intel(R) Dynamic Platform & Thermal Framework Driver ]
 
Device Properties:
Driver Description  Intel(R) Dynamic Platform & Thermal Framework Driver
Driver Date  2013.08.19.
Driver Version  7.1.0.144
Driver Provider  Intel
INF File  oem12.inf
Hardware ID  ACPI\VEN_INT&DEV_3400
 
[ System devices / Intel(R) Dynamic Platform & Thermal Framework Generic Participant Driver ]
 
Device Properties:
Driver Description  Intel(R) Dynamic Platform & Thermal Framework Generic Participant Driver
Driver Date  2013.08.19.
Driver Version  7.1.0.144
Driver Provider  Intel
INF File  oem12.inf
Hardware ID  ACPI\VEN_INT&DEV_3403
 
Device Resources:
IRQ  1035
 
[ System devices / Intel(R) Dynamic Platform & Thermal Framework Generic Participant Driver ]
 
Device Properties:
Driver Description  Intel(R) Dynamic Platform & Thermal Framework Generic Participant Driver
Driver Date  2013.08.19.
Driver Version  7.1.0.144
Driver Provider  Intel
INF File  oem12.inf
Hardware ID  ACPI\VEN_INT&DEV_3403
 
Device Resources:
IRQ  1036
 
[ System devices / Intel(R) Dynamic Platform & Thermal Framework Generic Participant Driver ]
 
Device Properties:
Driver Description  Intel(R) Dynamic Platform & Thermal Framework Generic Participant Driver
Driver Date  2013.08.19.
Driver Version  7.1.0.144
Driver Provider  Intel
INF File  oem12.inf
Hardware ID  ACPI\VEN_INT&DEV_3403
 
Device Resources:
IRQ  1034
 
[ System devices / Intel(R) Dynamic Platform & Thermal Framework Power Participant Driver ]
 
Device Properties:
Driver Description  Intel(R) Dynamic Platform & Thermal Framework Power Participant Driver
Driver Date  2013.08.19.
Driver Version  7.1.0.144
Driver Provider  Intel
INF File  oem12.inf
Hardware ID  ACPI\VEN_INT&DEV_3407
 
[ System devices / Intel(R) Dynamic Platform & Thermal Framework Processor Participant Driver ]
 
Device Properties:
Driver Description  Intel(R) Dynamic Platform & Thermal Framework Processor Participant Driver
Driver Date  2013.08.19.
Driver Version  7.1.0.144
Driver Provider  Intel
INF File  oem12.inf
Hardware ID  ACPI\VEN_INT&DEV_3401
 
Device Resources:
IRQ  86
Memory  FED05000-FED057FF
 
[ System devices / Intel(R) Power Engine Plug-in ]
 
Device Properties:
Driver Description  Intel(R) Power Engine Plug-in
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  intelpep.inf
Hardware ID  ACPI\VEN_INT&DEV_3396
 
[ System devices / Intel(R) Power Management IC Device ]
 
Device Properties:
Driver Description  Intel(R) Power Management IC Device
Driver Date  2013.07.16.
Driver Version  603.9456.2067.19226
Driver Provider  Intel Corporation
INF File  oem9.inf
Hardware ID  ACPI\VEN_INT&DEV_33FD&REV_0002
 
Device Resources:
IRQ  67
IRQ  67
IRQ  67
 
[ System devices / Intel(R) Sideband Fabric Device ]
 
Device Properties:
Driver Description  Intel(R) Sideband Fabric Device
Driver Date  2013.05.29.
Driver Version  603.9448.2067.15591
Driver Provider  Intel Corporation
INF File  oem8.inf
Hardware ID  ACPI\VEN_INT&DEV_33BD&REV_0002
 
Device Resources:
Memory  E00000D0-E00000DB
 
[ System devices / Intel(R) Trusted Execution Engine Interface ]
 
Device Properties:
Driver Description  Intel(R) Trusted Execution Engine Interface
Driver Date  2013.08.04.
Driver Version  1.0.0.1054
Driver Provider  Intel
INF File  oem11.inf
Hardware ID  PCI\VEN_8086&DEV_0F18&SUBSYS_14ED1043&REV_09
Location Information  PCI bus 0, device 26, function 0
PCI Device  Intel Bay Trail SoC - Trusted Execution Engine
 
Device Resources:
IRQ  65536
Memory  90600000-906FFFFF
Memory  90700000-907FFFFF
 
[ System devices / IWD Bus Enumerator ]
 
Device Properties:
Driver Description  IWD Bus Enumerator
Driver Date  2013.07.25.
Driver Version  4.5.23.0
Driver Provider  Intel Corporation
INF File  oem15.inf
Hardware ID  root\iwdbus
 
[ System devices / Microsoft ACPI-Compliant System ]
 
Device Properties:
Driver Description  Microsoft ACPI-Compliant System
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  acpi.inf
Hardware ID  ACPI_HAL\PNP0C08
PnP Device  ACPI Driver/BIOS
 
Device Resources:
IRQ  100
IRQ  101
IRQ  102
IRQ  103
IRQ  104
IRQ  105
IRQ  106
IRQ  107
IRQ  108
IRQ  109
IRQ  110
IRQ  111
IRQ  112
IRQ  113
IRQ  114
IRQ  115
IRQ  116
IRQ  117
IRQ  118
IRQ  119
IRQ  120
IRQ  121
IRQ  122
IRQ  123
IRQ  124
IRQ  125
IRQ  126
IRQ  127
IRQ  128
IRQ  129
IRQ  130
IRQ  131
IRQ  132
IRQ  133
IRQ  134
IRQ  135
IRQ  136
IRQ  137
IRQ  138
IRQ  139
IRQ  140
IRQ  141
IRQ  142
IRQ  143
IRQ  144
IRQ  145
IRQ  146
IRQ  147
IRQ  148
IRQ  149
IRQ  150
IRQ  151
IRQ  152
IRQ  153
IRQ  154
IRQ  155
IRQ  156
IRQ  157
IRQ  158
IRQ  159
IRQ  160
IRQ  161
IRQ  162
IRQ  163
IRQ  164
IRQ  165
IRQ  166
IRQ  167
IRQ  168
IRQ  169
IRQ  170
IRQ  171
IRQ  172
IRQ  173
IRQ  174
IRQ  175
IRQ  176
IRQ  177
IRQ  178
IRQ  179
IRQ  180
IRQ  181
IRQ  182
IRQ  183
IRQ  184
IRQ  185
IRQ  186
IRQ  187
IRQ  188
IRQ  189
IRQ  190
IRQ  191
IRQ  256
IRQ  257
IRQ  258
IRQ  259
IRQ  260
IRQ  261
IRQ  262
IRQ  263
IRQ  264
IRQ  265
IRQ  266
IRQ  267
IRQ  268
IRQ  269
IRQ  270
IRQ  271
IRQ  272
IRQ  273
IRQ  274
IRQ  275
IRQ  276
IRQ  277
IRQ  278
IRQ  279
IRQ  280
IRQ  281
IRQ  282
IRQ  283
IRQ  284
IRQ  285
IRQ  286
IRQ  287
IRQ  288
IRQ  289
IRQ  290
IRQ  291
IRQ  292
IRQ  293
IRQ  294
IRQ  295
IRQ  296
IRQ  297
IRQ  298
IRQ  299
IRQ  300
IRQ  301
IRQ  302
IRQ  303
IRQ  304
IRQ  305
IRQ  306
IRQ  307
IRQ  308
IRQ  309
IRQ  310
IRQ  311
IRQ  312
IRQ  313
IRQ  314
IRQ  315
IRQ  316
IRQ  317
IRQ  318
IRQ  319
IRQ  320
IRQ  321
IRQ  322
IRQ  323
IRQ  324
IRQ  325
IRQ  326
IRQ  327
IRQ  328
IRQ  329
IRQ  330
IRQ  331
IRQ  332
IRQ  333
IRQ  334
IRQ  335
IRQ  336
IRQ  337
IRQ  338
IRQ  339
IRQ  340
IRQ  341
IRQ  342
IRQ  343
IRQ  344
IRQ  345
IRQ  346
IRQ  347
IRQ  348
IRQ  349
IRQ  350
IRQ  351
IRQ  352
IRQ  353
IRQ  354
IRQ  355
IRQ  356
IRQ  357
IRQ  358
IRQ  359
IRQ  360
IRQ  361
IRQ  362
IRQ  363
IRQ  364
IRQ  365
IRQ  366
IRQ  367
IRQ  368
IRQ  369
IRQ  370
IRQ  371
IRQ  372
IRQ  373
IRQ  374
IRQ  375
IRQ  376
IRQ  377
IRQ  378
IRQ  379
IRQ  380
IRQ  381
IRQ  382
IRQ  383
IRQ  384
IRQ  385
IRQ  386
IRQ  387
IRQ  388
IRQ  389
IRQ  390
IRQ  391
IRQ  392
IRQ  393
IRQ  394
IRQ  395
IRQ  396
IRQ  397
IRQ  398
IRQ  399
IRQ  400
IRQ  401
IRQ  402
IRQ  403
IRQ  404
IRQ  405
IRQ  406
IRQ  407
IRQ  408
IRQ  409
IRQ  410
IRQ  411
IRQ  412
IRQ  413
IRQ  414
IRQ  415
IRQ  416
IRQ  417
IRQ  418
IRQ  419
IRQ  420
IRQ  421
IRQ  422
IRQ  423
IRQ  424
IRQ  425
IRQ  426
IRQ  427
IRQ  428
IRQ  429
IRQ  430
IRQ  431
IRQ  432
IRQ  433
IRQ  434
IRQ  435
IRQ  436
IRQ  437
IRQ  438
IRQ  439
IRQ  440
IRQ  441
IRQ  442
IRQ  443
IRQ  444
IRQ  445
IRQ  446
IRQ  447
IRQ  448
IRQ  449
IRQ  450
IRQ  451
IRQ  452
IRQ  453
IRQ  454
IRQ  455
IRQ  456
IRQ  457
IRQ  458
IRQ  459
IRQ  460
IRQ  461
IRQ  462
IRQ  463
IRQ  464
IRQ  465
IRQ  466
IRQ  467
IRQ  468
IRQ  469
IRQ  470
IRQ  471
IRQ  472
IRQ  473
IRQ  474
IRQ  475
IRQ  476
IRQ  477
IRQ  478
IRQ  479
IRQ  480
IRQ  481
IRQ  482
IRQ  483
IRQ  484
IRQ  485
IRQ  486
IRQ  487
IRQ  488
IRQ  489
IRQ  490
IRQ  491
IRQ  492
IRQ  493
IRQ  494
IRQ  495
IRQ  496
IRQ  497
IRQ  498
IRQ  499
IRQ  500
IRQ  501
IRQ  502
IRQ  503
IRQ  504
IRQ  505
IRQ  506
IRQ  507
IRQ  508
IRQ  509
IRQ  510
IRQ  511
IRQ  81
IRQ  82
IRQ  83
IRQ  84
IRQ  85
IRQ  86
IRQ  87
IRQ  88
IRQ  89
IRQ  90
IRQ  91
IRQ  92
IRQ  93
IRQ  94
IRQ  95
IRQ  96
IRQ  97
IRQ  98
IRQ  99
 
[ System devices / Microsoft Basic Display Driver ]
 
Device Properties:
Driver Description  Microsoft Basic Display Driver
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  basicdisplay.inf
Hardware ID  ROOT\BasicDisplay
 
[ System devices / Microsoft Basic Render Driver ]
 
Device Properties:
Driver Description  Microsoft Basic Render Driver
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  basicrender.inf
Hardware ID  ROOT\BasicRender
 
[ System devices / Microsoft System Management BIOS Driver ]
 
Device Properties:
Driver Description  Microsoft System Management BIOS Driver
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  mssmbios.inf
Hardware ID  ROOT\mssmbios
 
[ System devices / Microsoft UEFI-Compliant System ]
 
Device Properties:
Driver Description  Microsoft UEFI-Compliant System
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  uefi.inf
Hardware ID  ACPI_HAL\UEFI
 
[ System devices / Microsoft Virtual Drive Enumerator ]
 
Device Properties:
Driver Description  Microsoft Virtual Drive Enumerator
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  vdrvroot.inf
Hardware ID  ROOT\vdrvroot
 
[ System devices / Microsoft Windows Management Interface for ACPI ]
 
Device Properties:
Driver Description  Microsoft Windows Management Interface for ACPI
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  wmiacpi.inf
Hardware ID  ACPI\VEN_PNP&DEV_0C14
 
[ System devices / Motherboard resources ]
 
Device Properties:
Driver Description  Motherboard resources
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  machine.inf
Hardware ID  ACPI\VEN_PNP&DEV_0C02
 
[ System devices / Motherboard resources ]
 
Device Properties:
Driver Description  Motherboard resources
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  machine.inf
Hardware ID  ACPI\VEN_PNP&DEV_0C02
 
[ System devices / Motherboard resources ]
 
Device Properties:
Driver Description  Motherboard resources
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  machine.inf
Hardware ID  ACPI\VEN_PNP&DEV_0C02
 
[ System devices / NDIS Virtual Network Adapter Enumerator ]
 
Device Properties:
Driver Description  NDIS Virtual Network Adapter Enumerator
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  ndisvirtualbus.inf
Hardware ID  ROOT\NdisVirtualBus
 
[ System devices / PCI Express Root Complex ]
 
Device Properties:
Driver Description  PCI Express Root Complex
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  machine.inf
Hardware ID  ACPI\VEN_PNP&DEV_0A08
 
Device Resources:
Memory  000A0000-000BFFFF
Memory  000C0000-000DFFFF
Memory  000E0000-000FFFFF
Memory  7AF00001-7EF00000
Memory  80000000-908FFFFE
Memory  90C00000-90FFFFFF
Memory  FED40000-FED40FFF
Port  0000-006F
Port  0078-0CF7
Port  0D00-FFFF
 
[ System devices / PCI standard host CPU bridge ]
 
Device Properties:
Driver Description  PCI standard host CPU bridge
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  machine.inf
Hardware ID  PCI\VEN_8086&DEV_0F00&SUBSYS_14ED1043&REV_09
Location Information  PCI bus 0, device 0, function 0
PCI Device  Intel Bay Trail-T SoC - Transaction Router
 
[ System devices / PCI standard ISA bridge ]
 
Device Properties:
Driver Description  PCI standard ISA bridge
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  machine.inf
Hardware ID  PCI\VEN_8086&DEV_0F1C&SUBSYS_14ED1043&REV_09
Location Information  PCI bus 0, device 31, function 0
PCI Device  Intel Bay Trail SoC - Platform Controller Unit - LPC Controller
 
[ System devices / Plug and Play Software Device Enumerator ]
 
Device Properties:
Driver Description  Plug and Play Software Device Enumerator
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  swenum.inf
Hardware ID  ROOT\SWENUM
 
[ System devices / Programmable interrupt controller ]
 
Device Properties:
Driver Description  Programmable interrupt controller
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  machine.inf
Hardware ID  ACPI\VEN_PNP&DEV_0000
 
[ System devices / Remote Desktop Device Redirector Bus ]
 
Device Properties:
Driver Description  Remote Desktop Device Redirector Bus
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  rdpbus.inf
Hardware ID  ROOT\RDPBUS
 
[ System devices / System CMOS/real time clock ]
 
Device Properties:
Driver Description  System CMOS/real time clock
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  machine.inf
Hardware ID  ACPI\VEN_PNP&DEV_0B00
 
Device Resources:
Port  0070-0077
 
[ System devices / System timer ]
 
Device Properties:
Driver Description  System timer
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  machine.inf
Hardware ID  ACPI\VEN_PNP&DEV_0100
 
[ System devices / UMBus Root Bus Enumerator ]
 
Device Properties:
Driver Description  UMBus Root Bus Enumerator
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  umbus.inf
Hardware ID  root\umbus
 
[ System devices / Volume Manager ]
 
Device Properties:
Driver Description  Volume Manager
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  volmgr.inf
Hardware ID  ROOT\VOLMGR
 
[ Universal Serial Bus controllers / Intel(R) USB 3.0 eXtensible Host Controller - 0100 (Microsoft) ]
 
Device Properties:
Driver Description  Intel(R) USB 3.0 eXtensible Host Controller - 0100 (Microsoft)
Driver Date  2013.08.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  usbxhci.inf
Hardware ID  PCI\VEN_8086&DEV_0F35&SUBSYS_14ED1043&REV_09
Location Information  PCI bus 0, device 20, function 0
PCI Device  Intel Bay Trail SoC - USB 3.0 xHCI Host Controller
 
Device Resources:
IRQ  524288
Memory  90800000-9080FFFF
 
Chipset Manufacturer:
Company Name  Intel Corporation
Product Information  http://www.intel.com/products/chipsets
Driver Download  http://support.intel.com/support/chipsets
BIOS Upgrades  http://www.aida64.com/bios-updates
Driver Update  http://www.aida64.com/driver-updates
 
[ Universal Serial Bus controllers / USB Composite Device ]
 
Device Properties:
Driver Description  USB Composite Device
Driver Date  2006.06.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  usb.inf
Hardware ID  USB\VID_0B05&PID_17E0&REV_0238
Location Information  Port_#0003.Hub_#0001
 
[ Universal Serial Bus controllers / USB Root Hub (xHCI) ]
 
Device Properties:
Driver Description  USB Root Hub (xHCI)
Driver Date  2013.08.21.
Driver Version  6.3.9600.16384
Driver Provider  Microsoft
INF File  usbhub3.inf
Hardware ID  USB\ROOT_HUB30&VID8086&PID0F35&REV0009
 
[ Unknown / Unknown ]
 
Device Properties:
Driver Description  Unknown


Physical Devices

 
PCI Devices:
Bus 0, Device 31, Function 0  Intel Bay Trail SoC - Platform Controller Unit - LPC Controller
Bus 0, Device 26, Function 0  Intel Bay Trail SoC - Trusted Execution Engine
Bus 0, Device 20, Function 0  Intel Bay Trail SoC - USB 3.0 xHCI Host Controller
Bus 0, Device 2, Function 0  Intel Bay Trail-T SoC - Integrated Graphics Controller
Bus 0, Device 0, Function 0  Intel Bay Trail-T SoC - Transaction Router
 
PnP Devices:
PNP0C08  ACPI Driver/BIOS
PNP0C14  ACPI Management Interface
ACPI000C  ACPI Processor Aggregator
THERMALZONE  ACPI Thermal Zone
PNP0A08  ACPI Three-wire Device Bus
ATK4001  Asus Wireless Radio Control
BCM2E39  Broadcom Serial Bus Driver over UART Bus Enumerator [NoDB]
INT33F0  Camera Sensor MT9M114 [NoDB]
CPLM3218  Capella Micro CM3218x Ambient Light Sensor
PNP0C0A  Control Method Battery
PNP0103  High Precision Event Timer
ATML1000  I2C HID Device
INT33FC  Intel Atom Processor GPIO Controller
INT33FC  Intel Atom Processor GPIO Controller
INT33FC  Intel Atom Processor GPIO Controller
INT0002  Intel BC Virtual GPIO controller
INT3406  Intel Dynamic Platform & Thermal Framework Display Participant
INT3403  Intel Dynamic Platform & Thermal Framework Generic Participant
INT3403  Intel Dynamic Platform & Thermal Framework Generic Participant
INT3403  Intel Dynamic Platform & Thermal Framework Generic Participant
INT3407  Intel Dynamic Platform & Thermal Framework Power Participant
INT3401  Intel Dynamic Platform & Thermal Framework Processor Participant
INT3400  Intel Dynamic Platform & Thermal Framework
INT0800  Intel Flash EEPROM
INTCFD9  Intel GPIO Controller
INT33BD  Intel MBI
INT3396  Intel Power Engine Plug-in
INT33FD  Intel Power Management IC Device
80860F14  Intel SD Host Controller
80860F14  Intel SD Host Controller
INT33BB  Intel SD Host Controller
80860F28  Intel SST Audio Device (WDM)
GENUINEINTEL_-_X86_FAMILY_6_MODEL_55_-_________INTEL(R)_ATOM(TM)_CPU__Z3740__@_1.33GHZ  Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz
GENUINEINTEL_-_X86_FAMILY_6_MODEL_55_-_________INTEL(R)_ATOM(TM)_CPU__Z3740__@_1.33GHZ  Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz
GENUINEINTEL_-_X86_FAMILY_6_MODEL_55_-_________INTEL(R)_ATOM(TM)_CPU__Z3740__@_1.33GHZ  Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz
GENUINEINTEL_-_X86_FAMILY_6_MODEL_55_-_________INTEL(R)_ATOM(TM)_CPU__Z3740__@_1.33GHZ  Intel(R) Atom(TM) CPU Z3740 @ 1.33GHz
80860F41  Intel(R) Atom(TM) Processor I2C Controller
80860F41  Intel(R) Atom(TM) Processor I2C Controller
80860F41  Intel(R) Atom(TM) Processor I2C Controller
80860F41  Intel(R) Atom(TM) Processor I2C Controller
80860F41  Intel(R) Atom(TM) Processor I2C Controller
80860F41  Intel(R) Atom(TM) Processor I2C Controller
80860F41  Intel(R) Atom(TM) Processor I2C Controller
80860F0E  Intel(R) Atom(TM) Processor SPI Controller
80860F0A  Intel(R) Atom(TM) Processor UART Controller
INTL9C60  Intel(R) Serial IO DMA Controller
INTL9C60  Intel(R) Serial IO DMA Controller
INVN6500  InvenSense Sensor Collection
PNP0C0D  Lid
ACPI0003  Microsoft AC Adapter
UEFI  Microsoft UEFI-Compliant System
PNP0000  Programmable Interrupt Controller
10EC5640  Realtek I2S Audio Codec
PNP0B00  Real-Time Clock
PNP0C0E  Sleep Button
PNP0100  System Timer
PNP0C02  Thermal Monitoring ACPI Device
PNP0C02  Thermal Monitoring ACPI Device
PNP0C02  Thermal Monitoring ACPI Device
MSFT0101  Trusted Platform Module 2.0
 
USB Devices:
0B05 17E0  USB Composite Device
0B05 17E0  USB Input Device
0B05 17E0  USB Input Device
0B05 17E0  USB Input Device


PCI Devices

 
[ Intel Bay Trail SoC - Platform Controller Unit - LPC Controller ]
 
Device Properties:
Device Description  Intel Bay Trail SoC - Platform Controller Unit - LPC Controller
Bus Type  PCI
Bus / Device / Function  0 / 31 / 0
Device ID  8086-0F1C
Subsystem ID  1043-14ED
Device Class  0601 (PCI/ISA Bridge)
Revision  09
Fast Back-to-Back Transactions  Not Supported
 
Device Features:
66 MHz Operation  Not Supported
Bus Mastering  Enabled
 
[ Intel Bay Trail SoC - Trusted Execution Engine ]
 
Device Properties:
Device Description  Intel Bay Trail SoC - Trusted Execution Engine
Bus Type  PCI
Bus / Device / Function  0 / 26 / 0
Device ID  8086-0F18
Subsystem ID  1043-14ED
Device Class  1080 (En/decryption Controller)
Revision  09
Fast Back-to-Back Transactions  Not Supported
 
Device Features:
66 MHz Operation  Not Supported
Bus Mastering  Disabled
 
[ Intel Bay Trail SoC - USB 3.0 xHCI Host Controller ]
 
Device Properties:
Device Description  Intel Bay Trail SoC - USB 3.0 xHCI Host Controller
Bus Type  PCI
Bus / Device / Function  0 / 20 / 0
Device ID  8086-0F35
Subsystem ID  1043-14ED
Device Class  0C03 (USB Controller)
Revision  09
Fast Back-to-Back Transactions  Supported, Disabled
 
Device Features:
66 MHz Operation  Not Supported
Bus Mastering  Enabled
 
[ Intel Bay Trail-T SoC - Integrated Graphics Controller ]
 
Device Properties:
Device Description  Intel Bay Trail-T SoC - Integrated Graphics Controller
Bus Type  PCI
Bus / Device / Function  0 / 2 / 0
Device ID  8086-0F31
Subsystem ID  1043-14ED
Device Class  0300 (VGA Display Controller)
Revision  09
Fast Back-to-Back Transactions  Not Supported
 
Device Features:
66 MHz Operation  Not Supported
Bus Mastering  Enabled
 
Video Adapter Manufacturer:
Company Name  Intel Corporation
Product Information  http://www.intel.com/products/chipsets
Driver Download  http://support.intel.com/support/graphics
Driver Update  http://www.aida64.com/driver-updates
 
[ Intel Bay Trail-T SoC - Transaction Router ]
 
Device Properties:
Device Description  Intel Bay Trail-T SoC - Transaction Router
Bus Type  PCI
Bus / Device / Function  0 / 0 / 0
Device ID  8086-0F00
Subsystem ID  1043-14ED
Device Class  0600 (Host/PCI Bridge)
Revision  09
Fast Back-to-Back Transactions  Not Supported
 
Device Features:
66 MHz Operation  Not Supported
Bus Mastering  Enabled


USB Devices

 
[ USB Composite Device (ASUS Base Station(T100)) ]
 
Device Properties:
Device Description  USB Composite Device
Device ID  0B05-17E0
Device Class  03 / 01 (Human Interface Device)
Device Protocol  01
Manufacturer  ASUSTek COMPUTER INC.
Product  ASUS Base Station(T100)
Supported USB Version  2.00
Current Speed  Full (USB 1.1)


Device Resources

 
Resource  Share  Device Description
DMA 00  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
DMA 00  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
DMA 00  Exclusive  Intel(R) Atom(TM) Processor SPI Controller
DMA 01  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
DMA 01  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
DMA 01  Exclusive  Intel(R) Atom(TM) Processor SPI Controller
DMA 02  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
DMA 02  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
DMA 02  Exclusive  Intel(R) Atom(TM) Processor UART Controller
DMA 03  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
DMA 03  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
DMA 03  Exclusive  Intel(R) Atom(TM) Processor UART Controller
DMA 04  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
DMA 04  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
DMA 05  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
DMA 05  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
DMA 06  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
DMA 07  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
IRQ 09  Exclusive  Intel(R) Atom(TM) Processor GpioVirtual Controller
IRQ 100  Exclusive  Microsoft ACPI-Compliant System
IRQ 101  Exclusive  Microsoft ACPI-Compliant System
IRQ 102  Exclusive  Microsoft ACPI-Compliant System
IRQ 1027  Shared  Intel SD Host Controller
IRQ 1028  Exclusive  Realtek I2S Audio Codec
IRQ 1029  Exclusive  GPIO Buttons Driver
IRQ 103  Exclusive  Microsoft ACPI-Compliant System
IRQ 1030  Exclusive  GPIO Buttons Driver
IRQ 1031  Exclusive  GPIO Buttons Driver
IRQ 1032  Exclusive  GPIO Buttons Driver
IRQ 1033  Exclusive  GPIO Buttons Driver
IRQ 1034  Exclusive  Intel(R) Dynamic Platform & Thermal Framework Generic Participant Driver
IRQ 1035  Exclusive  Intel(R) Dynamic Platform & Thermal Framework Generic Participant Driver
IRQ 1036  Exclusive  Intel(R) Dynamic Platform & Thermal Framework Generic Participant Driver
IRQ 1037  Exclusive  Intel SST Audio Device (WDM)
IRQ 104  Exclusive  Microsoft ACPI-Compliant System
IRQ 105  Exclusive  Microsoft ACPI-Compliant System
IRQ 106  Exclusive  Microsoft ACPI-Compliant System
IRQ 107  Exclusive  Microsoft ACPI-Compliant System
IRQ 108  Exclusive  Microsoft ACPI-Compliant System
IRQ 109  Exclusive  Microsoft ACPI-Compliant System
IRQ 110  Exclusive  Microsoft ACPI-Compliant System
IRQ 111  Exclusive  Microsoft ACPI-Compliant System
IRQ 112  Exclusive  Microsoft ACPI-Compliant System
IRQ 113  Exclusive  Microsoft ACPI-Compliant System
IRQ 114  Exclusive  Microsoft ACPI-Compliant System
IRQ 115  Exclusive  Microsoft ACPI-Compliant System
IRQ 116  Exclusive  Microsoft ACPI-Compliant System
IRQ 117  Exclusive  Microsoft ACPI-Compliant System
IRQ 118  Exclusive  Microsoft ACPI-Compliant System
IRQ 119  Exclusive  Microsoft ACPI-Compliant System
IRQ 120  Exclusive  Microsoft ACPI-Compliant System
IRQ 121  Exclusive  Microsoft ACPI-Compliant System
IRQ 122  Exclusive  Microsoft ACPI-Compliant System
IRQ 123  Exclusive  Microsoft ACPI-Compliant System
IRQ 124  Exclusive  Microsoft ACPI-Compliant System
IRQ 125  Exclusive  Microsoft ACPI-Compliant System
IRQ 126  Exclusive  Microsoft ACPI-Compliant System
IRQ 127  Exclusive  Microsoft ACPI-Compliant System
IRQ 128  Exclusive  Microsoft ACPI-Compliant System
IRQ 129  Exclusive  Microsoft ACPI-Compliant System
IRQ 130  Exclusive  Microsoft ACPI-Compliant System
IRQ 131  Exclusive  Microsoft ACPI-Compliant System
IRQ 132  Exclusive  Microsoft ACPI-Compliant System
IRQ 133  Exclusive  Microsoft ACPI-Compliant System
IRQ 134  Exclusive  Microsoft ACPI-Compliant System
IRQ 135  Exclusive  Microsoft ACPI-Compliant System
IRQ 136  Exclusive  Microsoft ACPI-Compliant System
IRQ 137  Exclusive  Microsoft ACPI-Compliant System
IRQ 138  Exclusive  Microsoft ACPI-Compliant System
IRQ 139  Exclusive  Microsoft ACPI-Compliant System
IRQ 140  Exclusive  Microsoft ACPI-Compliant System
IRQ 141  Exclusive  Microsoft ACPI-Compliant System
IRQ 142  Exclusive  Microsoft ACPI-Compliant System
IRQ 143  Exclusive  Microsoft ACPI-Compliant System
IRQ 144  Exclusive  Microsoft ACPI-Compliant System
IRQ 145  Exclusive  Microsoft ACPI-Compliant System
IRQ 146  Exclusive  Microsoft ACPI-Compliant System
IRQ 147  Exclusive  Microsoft ACPI-Compliant System
IRQ 148  Exclusive  Microsoft ACPI-Compliant System
IRQ 149  Exclusive  Microsoft ACPI-Compliant System
IRQ 150  Exclusive  Microsoft ACPI-Compliant System
IRQ 151  Exclusive  Microsoft ACPI-Compliant System
IRQ 152  Exclusive  Microsoft ACPI-Compliant System
IRQ 153  Exclusive  Microsoft ACPI-Compliant System
IRQ 154  Exclusive  Microsoft ACPI-Compliant System
IRQ 155  Exclusive  Microsoft ACPI-Compliant System
IRQ 156  Exclusive  Microsoft ACPI-Compliant System
IRQ 157  Exclusive  Microsoft ACPI-Compliant System
IRQ 158  Exclusive  Microsoft ACPI-Compliant System
IRQ 159  Exclusive  Microsoft ACPI-Compliant System
IRQ 160  Exclusive  Microsoft ACPI-Compliant System
IRQ 161  Exclusive  Microsoft ACPI-Compliant System
IRQ 162  Exclusive  Microsoft ACPI-Compliant System
IRQ 163  Exclusive  Microsoft ACPI-Compliant System
IRQ 164  Exclusive  Microsoft ACPI-Compliant System
IRQ 165  Exclusive  Microsoft ACPI-Compliant System
IRQ 166  Exclusive  Microsoft ACPI-Compliant System
IRQ 167  Exclusive  Microsoft ACPI-Compliant System
IRQ 168  Exclusive  Microsoft ACPI-Compliant System
IRQ 169  Exclusive  Microsoft ACPI-Compliant System
IRQ 170  Exclusive  Microsoft ACPI-Compliant System
IRQ 171  Exclusive  Microsoft ACPI-Compliant System
IRQ 172  Exclusive  Microsoft ACPI-Compliant System
IRQ 173  Exclusive  Microsoft ACPI-Compliant System
IRQ 174  Exclusive  Microsoft ACPI-Compliant System
IRQ 175  Exclusive  Microsoft ACPI-Compliant System
IRQ 176  Exclusive  Microsoft ACPI-Compliant System
IRQ 177  Exclusive  Microsoft ACPI-Compliant System
IRQ 178  Exclusive  Microsoft ACPI-Compliant System
IRQ 179  Exclusive  Microsoft ACPI-Compliant System
IRQ 180  Exclusive  Microsoft ACPI-Compliant System
IRQ 181  Exclusive  Microsoft ACPI-Compliant System
IRQ 182  Exclusive  Microsoft ACPI-Compliant System
IRQ 183  Exclusive  Microsoft ACPI-Compliant System
IRQ 184  Exclusive  Microsoft ACPI-Compliant System
IRQ 185  Exclusive  Microsoft ACPI-Compliant System
IRQ 186  Exclusive  Microsoft ACPI-Compliant System
IRQ -1869283290  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
IRQ -1869283291  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
IRQ -1869283292  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
IRQ -1869283293  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
IRQ -1869283294  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
IRQ -1869283295  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
IRQ -1869283296  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
IRQ 187  Exclusive  Microsoft ACPI-Compliant System
IRQ 188  Exclusive  Microsoft ACPI-Compliant System
IRQ 189  Exclusive  Microsoft ACPI-Compliant System
IRQ 190  Exclusive  Microsoft ACPI-Compliant System
IRQ 191  Exclusive  Microsoft ACPI-Compliant System
IRQ 24  Exclusive  Intel SST Audio Device (WDM)
IRQ 25  Exclusive  Intel SST Audio Device (WDM)
IRQ 256  Exclusive  Microsoft ACPI-Compliant System
IRQ 257  Exclusive  Microsoft ACPI-Compliant System
IRQ 258  Exclusive  Microsoft ACPI-Compliant System
IRQ 259  Exclusive  Microsoft ACPI-Compliant System
IRQ 26  Exclusive  Intel SST Audio Device (WDM)
IRQ 260  Exclusive  Microsoft ACPI-Compliant System
IRQ 261  Exclusive  Microsoft ACPI-Compliant System
IRQ 262  Exclusive  Microsoft ACPI-Compliant System
IRQ 263  Exclusive  Microsoft ACPI-Compliant System
IRQ 264  Exclusive  Microsoft ACPI-Compliant System
IRQ 265  Exclusive  Microsoft ACPI-Compliant System
IRQ 266  Exclusive  Microsoft ACPI-Compliant System
IRQ 267  Exclusive  Microsoft ACPI-Compliant System
IRQ 268  Exclusive  Microsoft ACPI-Compliant System
IRQ 269  Exclusive  Microsoft ACPI-Compliant System
IRQ 27  Exclusive  Intel SST Audio Device (WDM)
IRQ 270  Exclusive  Microsoft ACPI-Compliant System
IRQ 271  Exclusive  Microsoft ACPI-Compliant System
IRQ 272  Exclusive  Microsoft ACPI-Compliant System
IRQ 273  Exclusive  Microsoft ACPI-Compliant System
IRQ 274  Exclusive  Microsoft ACPI-Compliant System
IRQ 275  Exclusive  Microsoft ACPI-Compliant System
IRQ 276  Exclusive  Microsoft ACPI-Compliant System
IRQ 277  Exclusive  Microsoft ACPI-Compliant System
IRQ 278  Exclusive  Microsoft ACPI-Compliant System
IRQ 279  Exclusive  Microsoft ACPI-Compliant System
IRQ 28  Exclusive  Intel SST Audio Device (WDM)
IRQ 280  Exclusive  Microsoft ACPI-Compliant System
IRQ 281  Exclusive  Microsoft ACPI-Compliant System
IRQ 282  Exclusive  Microsoft ACPI-Compliant System
IRQ 283  Exclusive  Microsoft ACPI-Compliant System
IRQ 284  Exclusive  Microsoft ACPI-Compliant System
IRQ 285  Exclusive  Microsoft ACPI-Compliant System
IRQ 286  Exclusive  Microsoft ACPI-Compliant System
IRQ 287  Exclusive  Microsoft ACPI-Compliant System
IRQ 288  Exclusive  Microsoft ACPI-Compliant System
IRQ 289  Exclusive  Microsoft ACPI-Compliant System
IRQ 29  Exclusive  Intel SST Audio Device (WDM)
IRQ 290  Exclusive  Microsoft ACPI-Compliant System
IRQ 291  Exclusive  Microsoft ACPI-Compliant System
IRQ 292  Exclusive  Microsoft ACPI-Compliant System
IRQ 293  Exclusive  Microsoft ACPI-Compliant System
IRQ 294  Exclusive  Microsoft ACPI-Compliant System
IRQ 295  Exclusive  Microsoft ACPI-Compliant System
IRQ 296  Exclusive  Microsoft ACPI-Compliant System
IRQ 297  Exclusive  Microsoft ACPI-Compliant System
IRQ 298  Exclusive  Microsoft ACPI-Compliant System
IRQ 299  Exclusive  Microsoft ACPI-Compliant System
IRQ 300  Exclusive  Microsoft ACPI-Compliant System
IRQ 301  Exclusive  Microsoft ACPI-Compliant System
IRQ 302  Exclusive  Microsoft ACPI-Compliant System
IRQ 303  Exclusive  Microsoft ACPI-Compliant System
IRQ 304  Exclusive  Microsoft ACPI-Compliant System
IRQ 305  Exclusive  Microsoft ACPI-Compliant System
IRQ 306  Exclusive  Microsoft ACPI-Compliant System
IRQ 307  Exclusive  Microsoft ACPI-Compliant System
IRQ 308  Exclusive  Microsoft ACPI-Compliant System
IRQ 309  Exclusive  Microsoft ACPI-Compliant System
IRQ 310  Exclusive  Microsoft ACPI-Compliant System
IRQ 311  Exclusive  Microsoft ACPI-Compliant System
IRQ 312  Exclusive  Microsoft ACPI-Compliant System
IRQ 313  Exclusive  Microsoft ACPI-Compliant System
IRQ 314  Exclusive  Microsoft ACPI-Compliant System
IRQ 315  Exclusive  Microsoft ACPI-Compliant System
IRQ 316  Exclusive  Microsoft ACPI-Compliant System
IRQ 317  Exclusive  Microsoft ACPI-Compliant System
IRQ 318  Exclusive  Microsoft ACPI-Compliant System
IRQ 319  Exclusive  Microsoft ACPI-Compliant System
IRQ 320  Exclusive  Microsoft ACPI-Compliant System
IRQ 321  Exclusive  Microsoft ACPI-Compliant System
IRQ 322  Exclusive  Microsoft ACPI-Compliant System
IRQ 323  Exclusive  Microsoft ACPI-Compliant System
IRQ 324  Exclusive  Microsoft ACPI-Compliant System
IRQ 325  Exclusive  Microsoft ACPI-Compliant System
IRQ 326  Exclusive  Microsoft ACPI-Compliant System
IRQ 327  Exclusive  Microsoft ACPI-Compliant System
IRQ 328  Exclusive  Microsoft ACPI-Compliant System
IRQ 329  Exclusive  Microsoft ACPI-Compliant System
IRQ 330  Exclusive  Microsoft ACPI-Compliant System
IRQ 331  Exclusive  Microsoft ACPI-Compliant System
IRQ 332  Exclusive  Microsoft ACPI-Compliant System
IRQ 333  Exclusive  Microsoft ACPI-Compliant System
IRQ 334  Exclusive  Microsoft ACPI-Compliant System
IRQ 335  Exclusive  Microsoft ACPI-Compliant System
IRQ 336  Exclusive  Microsoft ACPI-Compliant System
IRQ 337  Exclusive  Microsoft ACPI-Compliant System
IRQ 338  Exclusive  Microsoft ACPI-Compliant System
IRQ 339  Exclusive  Microsoft ACPI-Compliant System
IRQ 340  Exclusive  Microsoft ACPI-Compliant System
IRQ 341  Exclusive  Microsoft ACPI-Compliant System
IRQ 342  Exclusive  Microsoft ACPI-Compliant System
IRQ 343  Exclusive  Microsoft ACPI-Compliant System
IRQ 344  Exclusive  Microsoft ACPI-Compliant System
IRQ 345  Exclusive  Microsoft ACPI-Compliant System
IRQ 346  Exclusive  Microsoft ACPI-Compliant System
IRQ 347  Exclusive  Microsoft ACPI-Compliant System
IRQ 348  Exclusive  Microsoft ACPI-Compliant System
IRQ 349  Exclusive  Microsoft ACPI-Compliant System
IRQ 350  Exclusive  Microsoft ACPI-Compliant System
IRQ 351  Exclusive  Microsoft ACPI-Compliant System
IRQ 352  Exclusive  Microsoft ACPI-Compliant System
IRQ 353  Exclusive  Microsoft ACPI-Compliant System
IRQ 354  Exclusive  Microsoft ACPI-Compliant System
IRQ 355  Exclusive  Microsoft ACPI-Compliant System
IRQ 356  Exclusive  Microsoft ACPI-Compliant System
IRQ 357  Exclusive  Microsoft ACPI-Compliant System
IRQ 358  Exclusive  Microsoft ACPI-Compliant System
IRQ 359  Exclusive  Microsoft ACPI-Compliant System
IRQ 360  Exclusive  Microsoft ACPI-Compliant System
IRQ 361  Exclusive  Microsoft ACPI-Compliant System
IRQ 362  Exclusive  Microsoft ACPI-Compliant System
IRQ 363  Exclusive  Microsoft ACPI-Compliant System
IRQ 364  Exclusive  Microsoft ACPI-Compliant System
IRQ 365  Exclusive  Microsoft ACPI-Compliant System
IRQ 366  Exclusive  Microsoft ACPI-Compliant System
IRQ 367  Exclusive  Microsoft ACPI-Compliant System
IRQ 368  Exclusive  Microsoft ACPI-Compliant System
IRQ 369  Exclusive  Microsoft ACPI-Compliant System
IRQ 370  Exclusive  Microsoft ACPI-Compliant System
IRQ 371  Exclusive  Microsoft ACPI-Compliant System
IRQ 372  Exclusive  Microsoft ACPI-Compliant System
IRQ 373  Exclusive  Microsoft ACPI-Compliant System
IRQ 374  Exclusive  Microsoft ACPI-Compliant System
IRQ 375  Exclusive  Microsoft ACPI-Compliant System
IRQ 376  Exclusive  Microsoft ACPI-Compliant System
IRQ 377  Exclusive  Microsoft ACPI-Compliant System
IRQ 378  Exclusive  Microsoft ACPI-Compliant System
IRQ 379  Exclusive  Microsoft ACPI-Compliant System
IRQ 380  Exclusive  Microsoft ACPI-Compliant System
IRQ 381  Exclusive  Microsoft ACPI-Compliant System
IRQ 382  Exclusive  Microsoft ACPI-Compliant System
IRQ 383  Exclusive  Microsoft ACPI-Compliant System
IRQ 384  Exclusive  Microsoft ACPI-Compliant System
IRQ 385  Exclusive  Microsoft ACPI-Compliant System
IRQ 386  Exclusive  Microsoft ACPI-Compliant System
IRQ 387  Exclusive  Microsoft ACPI-Compliant System
IRQ 388  Exclusive  Microsoft ACPI-Compliant System
IRQ 389  Exclusive  Microsoft ACPI-Compliant System
IRQ 39  Exclusive  Intel(R) Atom(TM) Processor UART Controller
IRQ 390  Exclusive  Microsoft ACPI-Compliant System
IRQ 391  Exclusive  Microsoft ACPI-Compliant System
IRQ 392  Exclusive  Microsoft ACPI-Compliant System
IRQ 393  Exclusive  Microsoft ACPI-Compliant System
IRQ 394  Exclusive  Microsoft ACPI-Compliant System
IRQ 395  Exclusive  Microsoft ACPI-Compliant System
IRQ 396  Exclusive  Microsoft ACPI-Compliant System
IRQ 397  Exclusive  Microsoft ACPI-Compliant System
IRQ 398  Exclusive  Microsoft ACPI-Compliant System
IRQ 399  Exclusive  Microsoft ACPI-Compliant System
IRQ 400  Exclusive  Microsoft ACPI-Compliant System
IRQ 401  Exclusive  Microsoft ACPI-Compliant System
IRQ 402  Exclusive  Microsoft ACPI-Compliant System
IRQ 403  Exclusive  Microsoft ACPI-Compliant System
IRQ 404  Exclusive  Microsoft ACPI-Compliant System
IRQ 405  Exclusive  Microsoft ACPI-Compliant System
IRQ 406  Exclusive  Microsoft ACPI-Compliant System
IRQ 407  Exclusive  Microsoft ACPI-Compliant System
IRQ 408  Exclusive  Microsoft ACPI-Compliant System
IRQ 409  Exclusive  Microsoft ACPI-Compliant System
IRQ 41  Exclusive  Intel(R) Atom(TM) Processor SPI Controller
IRQ 410  Exclusive  Microsoft ACPI-Compliant System
IRQ 411  Exclusive  Microsoft ACPI-Compliant System
IRQ 412  Exclusive  Microsoft ACPI-Compliant System
IRQ 413  Exclusive  Microsoft ACPI-Compliant System
IRQ 414  Exclusive  Microsoft ACPI-Compliant System
IRQ 415  Exclusive  Microsoft ACPI-Compliant System
IRQ 416  Exclusive  Microsoft ACPI-Compliant System
IRQ 417  Exclusive  Microsoft ACPI-Compliant System
IRQ 418  Exclusive  Microsoft ACPI-Compliant System
IRQ 419  Exclusive  Microsoft ACPI-Compliant System
IRQ 420  Exclusive  Microsoft ACPI-Compliant System
IRQ 421  Exclusive  Microsoft ACPI-Compliant System
IRQ 422  Exclusive  Microsoft ACPI-Compliant System
IRQ 423  Exclusive  Microsoft ACPI-Compliant System
IRQ 424  Exclusive  Microsoft ACPI-Compliant System
IRQ 425  Exclusive  Microsoft ACPI-Compliant System
IRQ 426  Exclusive  Microsoft ACPI-Compliant System
IRQ 427  Exclusive  Microsoft ACPI-Compliant System
IRQ 428  Exclusive  Microsoft ACPI-Compliant System
IRQ 429  Exclusive  Microsoft ACPI-Compliant System
IRQ 430  Exclusive  Microsoft ACPI-Compliant System
IRQ 431  Exclusive  Microsoft ACPI-Compliant System
IRQ 432  Exclusive  Microsoft ACPI-Compliant System
IRQ 433  Exclusive  Microsoft ACPI-Compliant System
IRQ 434  Exclusive  Microsoft ACPI-Compliant System
IRQ 435  Exclusive  Microsoft ACPI-Compliant System
IRQ 436  Exclusive  Microsoft ACPI-Compliant System
IRQ 437  Exclusive  Microsoft ACPI-Compliant System
IRQ 438  Exclusive  Microsoft ACPI-Compliant System
IRQ 439  Exclusive  Microsoft ACPI-Compliant System
IRQ 44  Exclusive  Intel SD Host Controller
IRQ 440  Exclusive  Microsoft ACPI-Compliant System
IRQ 441  Exclusive  Microsoft ACPI-Compliant System
IRQ 442  Exclusive  Microsoft ACPI-Compliant System
IRQ 443  Exclusive  Microsoft ACPI-Compliant System
IRQ 444  Exclusive  Microsoft ACPI-Compliant System
IRQ 445  Exclusive  Microsoft ACPI-Compliant System
IRQ 446  Exclusive  Microsoft ACPI-Compliant System
IRQ 447  Exclusive  Microsoft ACPI-Compliant System
IRQ 448  Exclusive  Microsoft ACPI-Compliant System
IRQ 449  Exclusive  Microsoft ACPI-Compliant System
IRQ 450  Exclusive  Microsoft ACPI-Compliant System
IRQ 451  Exclusive  Microsoft ACPI-Compliant System
IRQ 452  Exclusive  Microsoft ACPI-Compliant System
IRQ 453  Exclusive  Microsoft ACPI-Compliant System
IRQ 454  Exclusive  Microsoft ACPI-Compliant System
IRQ 455  Exclusive  Microsoft ACPI-Compliant System
IRQ 456  Exclusive  Microsoft ACPI-Compliant System
IRQ 457  Exclusive  Microsoft ACPI-Compliant System
IRQ 458  Exclusive  Microsoft ACPI-Compliant System
IRQ 459  Exclusive  Microsoft ACPI-Compliant System
IRQ 46  Exclusive  Intel SD Host Controller
IRQ 460  Exclusive  Microsoft ACPI-Compliant System
IRQ 461  Exclusive  Microsoft ACPI-Compliant System
IRQ 462  Exclusive  Microsoft ACPI-Compliant System
IRQ 463  Exclusive  Microsoft ACPI-Compliant System
IRQ 464  Exclusive  Microsoft ACPI-Compliant System
IRQ 465  Exclusive  Microsoft ACPI-Compliant System
IRQ 466  Exclusive  Microsoft ACPI-Compliant System
IRQ 467  Exclusive  Microsoft ACPI-Compliant System
IRQ 468  Exclusive  Microsoft ACPI-Compliant System
IRQ 469  Exclusive  Microsoft ACPI-Compliant System
IRQ 47  Exclusive  Intel SD Host Controller
IRQ 470  Exclusive  Microsoft ACPI-Compliant System
IRQ 471  Exclusive  Microsoft ACPI-Compliant System
IRQ 472  Exclusive  Microsoft ACPI-Compliant System
IRQ 473  Exclusive  Microsoft ACPI-Compliant System
IRQ 474  Exclusive  Microsoft ACPI-Compliant System
IRQ 475  Exclusive  Microsoft ACPI-Compliant System
IRQ 476  Exclusive  Microsoft ACPI-Compliant System
IRQ 477  Exclusive  Microsoft ACPI-Compliant System
IRQ 478  Exclusive  Microsoft ACPI-Compliant System
IRQ 479  Exclusive  Microsoft ACPI-Compliant System
IRQ 48  Shared  Intel(R) Atom(TM) Processor GPIO Controller
IRQ 480  Exclusive  Microsoft ACPI-Compliant System
IRQ 481  Exclusive  Microsoft ACPI-Compliant System
IRQ 482  Exclusive  Microsoft ACPI-Compliant System
IRQ 483  Exclusive  Microsoft ACPI-Compliant System
IRQ 484  Exclusive  Microsoft ACPI-Compliant System
IRQ 485  Exclusive  Microsoft ACPI-Compliant System
IRQ 486  Exclusive  Microsoft ACPI-Compliant System
IRQ 487  Exclusive  Microsoft ACPI-Compliant System
IRQ 488  Exclusive  Microsoft ACPI-Compliant System
IRQ 489  Exclusive  Microsoft ACPI-Compliant System
IRQ 49  Shared  Intel(R) Atom(TM) Processor GPIO Controller
IRQ 490  Exclusive  Microsoft ACPI-Compliant System
IRQ 491  Exclusive  Microsoft ACPI-Compliant System
IRQ 492  Exclusive  Microsoft ACPI-Compliant System
IRQ 493  Exclusive  Microsoft ACPI-Compliant System
IRQ 494  Exclusive  Microsoft ACPI-Compliant System
IRQ 495  Exclusive  Microsoft ACPI-Compliant System
IRQ 496  Exclusive  Microsoft ACPI-Compliant System
IRQ 497  Exclusive  Microsoft ACPI-Compliant System
IRQ 498  Exclusive  Microsoft ACPI-Compliant System
IRQ 499  Exclusive  Microsoft ACPI-Compliant System
IRQ 50  Shared  Intel(R) Atom(TM) Processor GPIO Controller
IRQ 500  Exclusive  Microsoft ACPI-Compliant System
IRQ 501  Exclusive  Microsoft ACPI-Compliant System
IRQ 502  Exclusive  Microsoft ACPI-Compliant System
IRQ 503  Exclusive  Microsoft ACPI-Compliant System
IRQ 504  Exclusive  Microsoft ACPI-Compliant System
IRQ 505  Exclusive  Microsoft ACPI-Compliant System
IRQ 506  Exclusive  Microsoft ACPI-Compliant System
IRQ 507  Exclusive  Microsoft ACPI-Compliant System
IRQ 508  Exclusive  Microsoft ACPI-Compliant System
IRQ 509  Exclusive  Microsoft ACPI-Compliant System
IRQ 51  Exclusive  Capella Micro CM3218x Ambient Light Sensor
IRQ 510  Exclusive  Microsoft ACPI-Compliant System
IRQ 511  Exclusive  Microsoft ACPI-Compliant System
IRQ 524288  Exclusive  Intel(R) USB 3.0 eXtensible Host Controller - 0100 (Microsoft)
IRQ 65536  Exclusive  Intel(R) HD Graphics
IRQ 65536  Exclusive  Intel(R) Trusted Execution Engine Interface
IRQ 67  Shared  Intel(R) Power Management IC Device
IRQ 67  Shared  Intel(R) Power Management IC Device
IRQ 67  Shared  Intel(R) Power Management IC Device
IRQ 68  Shared  InvenSense Sensor Collection
IRQ 69  Exclusive  I2C HID Device
IRQ 70  Exclusive  Broadcom Serial Bus Driver over UART Bus Enumerator
IRQ 73  Exclusive  Broadcom 802.11abgn Wireless SDIO Adapter
IRQ 81  Exclusive  Microsoft ACPI-Compliant System
IRQ 82  Exclusive  Microsoft ACPI-Compliant System
IRQ 83  Exclusive  Microsoft ACPI-Compliant System
IRQ 84  Exclusive  Microsoft ACPI-Compliant System
IRQ 85  Exclusive  Microsoft ACPI-Compliant System
IRQ 86  Exclusive  Intel(R) Dynamic Platform & Thermal Framework Processor Participant Driver
IRQ 86  Exclusive  Microsoft ACPI-Compliant System
IRQ 87  Exclusive  Microsoft ACPI-Compliant System
IRQ 88  Exclusive  Microsoft ACPI-Compliant System
IRQ 89  Exclusive  Microsoft ACPI-Compliant System
IRQ 90  Exclusive  Microsoft ACPI-Compliant System
IRQ 91  Exclusive  Microsoft ACPI-Compliant System
IRQ 92  Exclusive  Microsoft ACPI-Compliant System
IRQ 93  Exclusive  Microsoft ACPI-Compliant System
IRQ 94  Exclusive  Microsoft ACPI-Compliant System
IRQ 95  Exclusive  Microsoft ACPI-Compliant System
IRQ 96  Exclusive  Microsoft ACPI-Compliant System
IRQ 97  Exclusive  Microsoft ACPI-Compliant System
IRQ 98  Exclusive  Microsoft ACPI-Compliant System
IRQ 99  Exclusive  Microsoft ACPI-Compliant System
Memory 000A0000-000BFFFF  Shared  PCI Express Root Complex
Memory 000C0000-000DFFFF  Shared  PCI Express Root Complex
Memory 000E0000-000FFFFF  Shared  PCI Express Root Complex
Memory 20000000-200FFFFF  Exclusive  Intel SST Audio Device (WDM)
Memory 7AF00001-7EF00000  Shared  PCI Express Root Complex
Memory 7FF00000-7FF00FFF  Exclusive  Trusted Platform Module 2.0
Memory 80000000-8FFFFFFF  Exclusive  Intel(R) HD Graphics
Memory 80000000-908FFFFE  Shared  PCI Express Root Complex
Memory 90000000-903FFFFF  Exclusive  Intel(R) HD Graphics
Memory 90600000-906FFFFF  Exclusive  Intel(R) Trusted Execution Engine Interface
Memory 90700000-907FFFFF  Exclusive  Intel(R) Trusted Execution Engine Interface
Memory 90800000-9080FFFF  Exclusive  Intel(R) USB 3.0 eXtensible Host Controller - 0100 (Microsoft)
Memory 90900000-90900FFF  Exclusive  Intel SST Audio Device (WDM)
Memory 90905000-90905FFF  Exclusive  Intel SD Host Controller
Memory 9090B000-9090BFFF  Exclusive  Intel SD Host Controller
Memory 9091A000-9091AFFF  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
Memory 90920000-90920FFF  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
Memory 90926000-90926FFF  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
Memory 9092C000-9092CFFF  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
Memory 90932000-90932FFF  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
Memory 90938000-90938FFF  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
Memory 9093E000-9093EFFF  Exclusive  Intel(R) Atom(TM) Processor I2C Controller
Memory 9094D000-9094DFFF  Exclusive  Intel(R) Atom(TM) Processor UART Controller
Memory 90953000-90953FFF  Exclusive  Intel(R) Atom(TM) Processor SPI Controller
Memory 90959000-90959FFF  Exclusive  Intel SD Host Controller
Memory 90A00000-90BFFFFF  Exclusive  Intel SST Audio Device (WDM)
Memory 90C00000-90FFFFFF  Exclusive  Intel(R) Imaging Signal Processor 2400
Memory 90C00000-90FFFFFF  Shared  PCI Express Root Complex
Memory E00000D0-E00000DB  Exclusive  Intel(R) Sideband Fabric Device
Memory FED05000-FED057FF  Exclusive  Intel(R) Dynamic Platform & Thermal Framework Processor Participant Driver
Memory FED0C000-FED0CFFF  Exclusive  Intel(R) Atom(TM) Processor GPIO Controller
Memory FED0D000-FED0DFFF  Exclusive  Intel(R) Atom(TM) Processor GPIO Controller
Memory FED0E000-FED0EFFF  Exclusive  Intel(R) Atom(TM) Processor GPIO Controller
Memory FED40000-FED40FFF  Shared  PCI Express Root Complex
Port 0000-006F  Shared  PCI Express Root Complex
Port 0070-0077  Exclusive  System CMOS/real time clock
Port 0078-0CF7  Shared  PCI Express Root Complex
Port 0D00-FFFF  Shared  PCI Express Root Complex
Port 1000-1007  Exclusive  Intel(R) HD Graphics


Input

 
[ HID Keyboard Device ]
 
Keyboard Properties:
Keyboard Name  HID Keyboard Device
Keyboard Type  IBM enhanced (101- or 102-key) keyboard
Keyboard Layout  Hungarian
ANSI Code Page  1250 - Central European (Windows)
OEM Code Page  852 - Central European (DOS)
Repeat Delay  1
Repeat Rate  31
 
[ ASUS Touchpad ]
 
Mouse Properties:
Mouse Name  ASUS Touchpad
Mouse Buttons  2
Mouse Hand  Right
Pointer Speed  1
Double-Click Time  500 msec
X/Y Threshold  6 / 10
Wheel Scroll Lines  3
 
Mouse Features:
Active Window Tracking  Disabled
ClickLock  Disabled
Hide Pointer While Typing  Enabled
Mouse Wheel  Present
Move Pointer To Default Button  Disabled
Pointer Trails  Disabled
Sonar  Disabled


Printers

 
[ Fax ]
 
Printer Properties:
Printer Name  Fax
Default Printer  No
Share Point  Not shared
Printer Port  SHRFAX:
Printer Driver  Microsoft Shared Fax Driver (v4.00)
Device Name  Fax
Print Processor  winprint
Separator Page  None
Availability  2:00 - 2:00
Priority  1
Print Jobs Queued  0
Status  Unknown
 
Paper Properties:
Paper Size  Letter, 8.5 x 11 in
Orientation  Portrait
Print Quality  200 x 200 dpi Mono
 
[ Microsoft XPS Document Writer (Default) ]
 
Printer Properties:
Printer Name  Microsoft XPS Document Writer
Default Printer  Yes
Share Point  Not shared
Printer Port  PORTPROMPT:
Printer Driver  Microsoft XPS Document Writer v4 (v6.03)
Device Name  Microsoft XPS Document Writer
Print Processor  winprint
Separator Page  None
Availability  2:00 - 2:00
Priority  1
Print Jobs Queued  0
Status  Unknown
 
Paper Properties:
Paper Size  Letter, 8.5 x 11 in
Orientation  Portrait
Print Quality  600 x 600 dpi Color


Auto Start

 
Application Description  Start From  Application Command
ASUSPRP  Registry\Common\Run  C:\Program Files\ASUS\APRP\APRP.EXE
BrowserChoice  Registry\User\Run  C:\Windows\BrowserChoice\browserchoice.exe /run
DptfPolicyLpmServiceHelper  Registry\Common\Run  C:\Windows\system32\DptfPolicyLpmServiceHelper.exe
HotKeysCmds  Registry\Common\Run  C:\Windows\system32\hkcmd.exe
IgfxTray  Registry\Common\Run  C:\Windows\system32\igfxtray.exe
Persistence  Registry\Common\Run  C:\Windows\system32\igfxpers.exe
RtkNGUI  Registry\Common\Run  C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe /s
WebStorage  Registry\Common\Run  C:\Program Files\ASUS\WebStorage\2.0.3.226\ASUSWSLoader.exe


Scheduled

 
[ ASUS AC Reminder ]
 
Task Properties:
Task Name  ASUS AC Reminder
Status  Running
Application Name  C:\Program Files\ASUS\ASUS AC Reminder\ACReminderSrv.exe
Application Parameters  
Working Folder  
Comment  
Account Name  
Creator  ASUSTek Computer INC.
Last Run  2013.11.28. 18:56:56
Next Run  Unknown
 
Task Triggers:
At log on  At log on of any user
 
[ ASUS Live Update1 ]
 
Task Properties:
Task Name  ASUS Live Update1
Status  Enabled
Application Name  C:\Program Files\ASUS\ASUS Live Update\LiveUpdate.exe
Application Parameters  -critical
Working Folder  
Comment  
Account Name  
Creator  ASUSTek Computer Inc
Last Run  Unknown
Next Run  2013.11.29. 12:00:00
 
Task Triggers:
Daily  At 12:00:00 every day
 
[ ASUS Live Update2 ]
 
Task Properties:
Task Name  ASUS Live Update2
Status  Enabled
Application Name  C:\Program Files\ASUS\ASUS Live Update\LiveUpdate.exe
Application Parameters  -check
Working Folder  
Comment  
Account Name  
Creator  ASUSTek Computer Inc
Last Run  Unknown
Next Run  2013.12.05. 5:37:16
 
Task Triggers:
Daily  At 5:37:16 every 14 days
 
[ ASUS Patch for Touch Panel ]
 
Task Properties:
Task Name  ASUS Patch for Touch Panel
Status  Running
Application Name  C:\ProgramData\AsTouchPanel\AsPatchTouchPanel.exe
Application Parameters  
Working Folder  
Comment  
Account Name  
Creator  ASUSTek Computer INC.
Last Run  2013.11.28. 18:56:56
Next Run  Unknown
 
Task Triggers:
At log on  At log on of any user
 
[ Asus Reading Mode ]
 
Task Properties:
Task Name  Asus Reading Mode
Status  Running
Application Name  "C:\Program Files\ASUS\ASUS Reading Mode\ReadingModeWatchDogx86.exe"
Application Parameters  
Working Folder  
Comment  ASUS Reading Mode
Account Name  
Creator  ASUS
Last Run  2013.11.28. 18:56:56
Next Run  Unknown
 
Task Triggers:
At log on  At log on of any user
 
[ ASUS Smart Gesture Launcher ]
 
Task Properties:
Task Name  ASUS Smart Gesture Launcher
Status  Enabled
Application Name  C:\Program Files\ASUS\ASUS Smart Gesture\AsTPCenter\x86\AsusTPLauncher.exe
Application Parameters  
Working Folder  
Comment  ASUS Smart Gesture Launcher
Account Name  
Creator  ASUS
Last Run  2013.11.28. 18:56:56
Next Run  Unknown
 
Task Triggers:
At log on  At log on of any user
 
[ CreateChoiceProcessTask ]
 
Task Properties:
Task Name  CreateChoiceProcessTask
Status  Running
Application Name  C:\Windows\BrowserChoice\browserchoice.exe
Application Parameters  /launch
Working Folder  
Comment  
Account Name  T100\Transformer T100
Creator  BrowserChoice
Last Run  2013.11.28. 18:57:01
Next Run  Unknown
 
[ Optimize Start Menu Cache Files-S-1-5-21-510496655-4205887700-2175606355-1001 ]
 
Task Properties:
Task Name  Optimize Start Menu Cache Files-S-1-5-21-510496655-4205887700-2175606355-1001
Status  Disabled
Application Name  
Application Parameters  
Working Folder  
Comment  This idle task reorganizes the cache files used to display the start menu. It is enabled only when the cache files are not optimally organized.
Account Name  Transformer T100
Creator  Microsoft Corporation
Last Run  2013.11.28. 19:06:59
Next Run  Unknown
 
Task Triggers:
On idle  When computer is idle


Installed Programs

 
Program  Version  Inst. Size  GUID  Publisher  Inst. Date
AIDA64 [ TRIAL VERSION ]  4.00  Unknown  AIDA64 [ TRIAL VERSION ]  FinalWire Ltd.  2013-11-29
ASUS A [ TRIAL VERSION ]  1.0.1  Unknown  {B002B5 [ TRIAL VERSION ]  ASUS  2013-09-26
ASUS L [ TRIAL VERSION ]  3.2.6  Unknown  {FA540E [ TRIAL VERSION ]  ASUS  2013-09-26
ASUS R [ TRIAL VERSION ]  1.0.1  Unknown  {47CE1F [ TRIAL VERSION ]  ASUS  2013-09-26
ASUS S [ TRIAL VERSION ]  1.0.2  Unknown  {0FBEED [ TRIAL VERSION ]  ASUS  2013-09-26
ASUS S [ TRIAL VERSION ]  2.2.4  Unknown  {4D3286 [ TRIAL VERSION ]  ASUS  2013-09-26
ATK Pa [ TRIAL VERSION ]  1.0.0030  Unknown  {AB5C93 [ TRIAL VERSION ]  ASUS  2013-09-26
Intel(R) Processor Graphics  10.18.10.3286  Unknown  {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}  Intel Corporation  
Microsoft Office  15.0.4454.1510  Unknown  {90150000-0138-0409-0000-0000000FF1CE}  Microsoft Corporation  2013-09-05
Realtek I2S Audio [english]  6.2.9400.4028  Unknown  {89A448AA-3301-46AA-AFC3-34F2D7C670E8}  Realtek Semiconductor Corp.  2013-09-26
WebSto [ TRIAL VERSION ]  2.0.3.226  Unknown  WebStor [ TRIAL VERSION ]  ASUS Cloud Corporation  
Window [ TRIAL VERSION ]  08/31/2013 3.0.0.13  Unknown  9F0C2A3 [ TRIAL VERSION ]  ASUS  
WinFla [ TRIAL VERSION ]  2.42.0  Unknown  {8F2129 [ TRIAL VERSION ]  ASUS  2013-09-26


Licenses

 
Software  Product Key
Microsoft Internet Explorer 9.11.9600.16384  D6RD9- [ TRIAL VERSION ]
Microsoft Windows 8.1  2M8YJ- [ TRIAL VERSION ]


File Types

 
Extension  File Type Description  Content Type
386  Virtual Device Driver  
3G2  3GPP2 Audio/Video  video/3gpp2
3GP  3GPP Audio/Video  video/3gpp
3GP2  3GPP2 Audio/Video  video/3gpp2
3GPP  3GPP Audio/Video  video/3gpp
AAC  ADTS Audio  audio/vnd.dlna.adts
ACCDA  ACCDA File  
ACCDB  ACCDB File  
ACCDC  ACCDC File  
ACCDE  ACCDE File  
ACCDT  ACCDT File  
ACCDW  ACCDW File  
ACCOUNTPICTURE-MS  Account Picture File  application/windows-accountpicture
ADE  ADE File  
ADP  ADP File  
ADT  ADTS Audio  audio/vnd.dlna.adts
ADTS  ADTS Audio  audio/vnd.dlna.adts
AIF  AIFF Format Sound  audio/aiff
AIFC  AIFF Format Sound  audio/aiff
AIFF  AIFF Format Sound  audio/aiff
ANI  Animated Cursor  
APPCONTENT-MS  Application Content  application/windows-appcontent+xml
APPLICATION  Application Manifest  application/x-ms-application
APPREF-MS  Application Reference  
ASA  ASA File  
ASF  Windows Media Audio/Video file  video/x-ms-asf
ASP  ASP File  
ASX  Windows Media Audio/Video playlist  video/x-ms-asf
AU  AU Format Sound  audio/basic
AVI  Video Clip  video/avi
BAT  Windows Batch File  
BLG  Performance Monitor File  
BMP  Bitmap Image  image/bmp
CAB  Cabinet File  
CAMP  WCS Viewing Condition Profile  
CAT  Security Catalog  application/vnd.ms-pki.seccat
CDA  CD Audio Track  
CDMP  WCS Device Profile  
CDX  CDX File  
CDXML  CDXML File  
CER  Security Certificate  application/x-x509-ca-cert
CHK  Recovered File Fragments  
CHM  Compiled HTML Help file  
CMD  Windows Command Script  
COM  MS-DOS Application  
COMPOSITEFONT  Composite Font File  
CONTACT  Contact File  text/x-ms-contact
CPL  Control Panel Item  
CRL  Certificate Revocation List  application/pkix-crl
CRT  Security Certificate  application/x-x509-ca-cert
CUR  Cursor  
CSS  Cascading Style Sheet Document  text/css
DB  Data Base File  
DCTX  Open Extended Dictionary  
DCTXC  Open Extended Dictionary  
DDS  DDS Image  image/vnd.ms-dds
DER  Security Certificate  application/x-x509-ca-cert
DESKLINK  Desktop Shortcut  
DESKTHEMEPACK  Windows Desktop Theme Pack  
DIAGCAB  Diagnostic Cabinet  
DIAGCFG  Diagnostic Configuration  
DIAGPKG  Diagnostic Document  
DIB  Bitmap Image  image/bmp
DLL  Application Extension  application/x-msdownload
DOC  DOC File  
DOCM  DOCM File  
DOCX  OOXML Text Document  
DOT  DOT File  
DOTM  DOTM File  
DOTX  DOTX File  
DRV  Device Driver  
DSN  Microsoft OLE DB Provider for ODBC Drivers  
DWFX  XPS Document  model/vnd.dwfx+xps
EASMX  XPS Document  model/vnd.easmx+xps
EDRWX  XPS Document  model/vnd.edrwx+xps
EMF  EMF File  image/x-emf
EML  EML File  
EPRTX  XPS Document  model/vnd.eprtx+xps
EVT  EVT File  
EVTX  EVTX File  
EXE  Application  application/x-msdownload
FON  Font file  
GIF  GIF Image  image/gif
GMMP  WCS Gamut Mapping Profile  
GROUP  Contact Group File  text/x-ms-group
GRP  Microsoft Program Group  
HLP  Help File  
HOL  HOL File  
HTA  HTML Application  application/hta
HTM  HTML Document  text/html
HTML  HTML Document  text/html
ICC  ICC Profile  
ICL  Icon Library  
ICM  ICC Profile  
ICO  Icon  image/x-icon
IMESX  IME Search provider definition  
IMG  Disc Image File  
INF  Setup Information  
INI  Configuration Settings  
ISO  Disc Image File  
JFIF  JPEG Image  image/jpeg
JNT  Journal Document  
JOB  Task Scheduler Task Object  
JOD  Microsoft.Jet.OLEDB.4.0  
JPE  JPEG Image  image/jpeg
JPEG  JPEG Image  image/jpeg
JPG  JPEG Image  image/jpeg
JS  JavaScript File  
JSE  JScript Encoded File  
JTP  Journal Template  
JTX  XPS Document  application/x-jtx+xps
JXR  Windows Media Photo  image/vnd.ms-photo
LABEL  Property List  
LIBRARY-MS  Library Folder  application/windows-library+xml
LNK  Shortcut  
LOG  Text Document  
M1V  Movie Clip  video/mpeg
M2T  AVCHD Video  video/vnd.dlna.mpeg-tts
M2TS  AVCHD Video  video/vnd.dlna.mpeg-tts
M2V  Movie Clip  video/mpeg
M3U  M3U file  audio/x-mpegurl
M4A  MPEG-4 Audio  audio/mp4
M4V  MP4 Video  video/mp4
MAPIMAIL  Mail Service  
MDA  MDA File  
MDB  MDB File  
MDE  MDE File  
MDW  MDW File  
MFP  Macromedia Flash Paper  application/x-shockwave-flash
MHT  MHTML Document  message/rfc822
MHTML  MHTML Document  message/rfc822
MID  MIDI Sequence  audio/mid
MIDI  MIDI Sequence  audio/mid
MIG  Migration Store  
MLC  Language Pack File_  
MOD  Movie Clip  video/mpeg
MOV  QuickTime Movie  video/quicktime
MP2  MP3 Format Sound  audio/mpeg
MP2V  Movie Clip  video/mpeg
MP3  MP3 Format Sound  audio/mpeg
MP4  MP4 Video  video/mp4
MP4V  MP4 Video  video/mp4
MPA  Movie Clip  audio/mpeg
MPE  Movie Clip  video/mpeg
MPEG  Movie Clip  video/mpeg
MPG  Movie Clip  video/mpeg
MPV2  Movie Clip  video/mpeg
MSC  Microsoft Common Console Document  
MSG  MSG File  
MSI  Windows Installer Package  
MSP  Windows Installer Patch  
MSRCINCIDENT  Windows Remote Assistance Invitation  
MSSTYLES  Windows Visual Style File  
MSU  Microsoft Update Standalone Package  
MTS  AVCHD Video  video/vnd.dlna.mpeg-tts
MYDOCS  MyDocs Drop Target  
NFO  MSInfo Configuration File  
OCX  ActiveX control  
ODT  ODF Text Document  
ONE  ONE File  
ONEPKG  ONEPKG File  
ONETOC  ONETOC File  
ONETOC2  ONETOC2 File  
OSDX  OpenSearch Description File  application/opensearchdescription+xml
OTF  OpenType Font file  
OXPS  XPS Document  
P10  Certificate Request  application/pkcs10
P12  Personal Information Exchange  application/x-pkcs12
P7B  PKCS #7 Certificates  application/x-pkcs7-certificates
P7C  Digital ID File  application/pkcs7-mime
P7M  PKCS #7 MIME Message  application/pkcs7-mime
P7R  Certificate Request Response  application/x-pkcs7-certreqresp
P7S  PKCS #7 Signature  application/pkcs7-signature
PANO  PANO File  application/vnd.ms-pano
PARTIAL  Partial Download  
PBK  Dial-Up Phonebook  
PERFMONCFG  Performance Monitor Configuration  
PFM  Type 1 Font file  
PFX  Personal Information Exchange  application/x-pkcs12
PIF  Shortcut to MS-DOS Program  
PKO  Public Key Security Object  application/vnd.ms-pki.pko
PNF  Precompiled Setup Information  
PNG  PNG Image  image/png
POT  POT File  
POTM  POTM File  
POTX  POTX File  
PPS  PPS File  
PPSM  PPSM File  
PPSX  PPSX File  
PPT  PPT File  
PPTM  PPTM File  
PPTX  PPTX File  
PRF  PICS Rules File  application/pics-rules
PS1  PS1 File  
PS1XML  PS1XML File  
PSC1  PSC1 File  application/PowerShell
PSD1  PSD1 File  
PSM1  PSM1 File  
PSSC  PSSC File  
PUB  PUB File  
QDS  Directory Query  
RAT  Rating System File  application/rat-file
RDP  Remote Desktop Connection  
REG  Registration Entries  
RELS  XML Document  
RESMONCFG  Resource Monitor Configuration  
RLE  RLE File  
RLL  Application Extension  
RMI  MIDI Sequence  audio/mid
RTF  Rich Text Document  
SCF  File Explorer Command  
SCP  Text Document  
SCR  Screen saver  
SCT  Windows Script Component  text/scriptlet
SEARCHCONNECTOR-MS  Search Connector Folder  application/windows-search-connector+xml
SEARCH-MS  Saved Search  
SETTINGCONTENT-MS  Setting Content  
SFCACHE  ReadyBoost Cache File  
SND  AU Format Sound  audio/basic
SPC  PKCS #7 Certificates  application/x-pkcs7-certificates
SPL  Shockwave Flash Object  application/futuresplash
SST  Microsoft Serialized Certificate Store  application/vnd.ms-pki.certstore
SVG  SVG Document  image/svg+xml
SWF  Shockwave Flash Object  application/x-shockwave-flash
SYMLINK  .symlink  
SYS  System file  
THEME  Windows Theme File  
THEMEPACK  Windows Theme Pack  
TIF  TIF File  image/tiff
TIFF  TIFF File  image/tiff
TS  MPEG-2 TS Video  video/vnd.dlna.mpeg-tts
TTC  TrueType Collection Font file  
TTF  TrueType Font file  
TTS  MPEG-2 TS Video  video/vnd.dlna.mpeg-tts
TXT  Text Document  text/plain
UDL  Microsoft Data Link  
URL  URL File  
VBE  VBScript Encoded File  
VBS  VBScript Script File  
VCF  vCard File  text/x-vcard
VHD  Disc Image File  
VHDX  Disc Image File  
VXD  Virtual Device Driver  
WAB  Address Book File  
WAV  Wave Sound  audio/wav
WAX  Windows Media Audio shortcut  audio/x-ms-wax
WCX  Workspace Configuration File  
WDP  Windows Media Photo  image/vnd.ms-photo
WEBPNP  Web Point And Print File  
WEBSITE  Pinned Site Shortcut  application/x-mswebsite
WLL  WLL File  
WM  Windows Media Audio/Video file  video/x-ms-wm
WMA  Windows Media Audio file  audio/x-ms-wma
WMD  Windows Media Player Download Package  application/x-ms-wmd
WMDB  Windows Media Library  
WMF  WMF File  image/x-wmf
WMS  Windows Media Player Skin File  
WMV  Windows Media Audio/Video file  video/x-ms-wmv
WMX  Windows Media Audio/Video playlist  video/x-ms-wmx
WMZ  Windows Media Player Skin Package  application/x-ms-wmz
WPL  Windows Media playlist  application/vnd.ms-wpl
WSC  Windows Script Component  text/scriptlet
WSF  Windows Script File  
WSH  Windows Script Host Settings File  
WTX  Text Document  
WVX  Windows Media Audio/Video playlist  video/x-ms-wvx
XAML  Windows Markup File  application/xaml+xml
XBAP  XAML Browser Application  application/x-ms-xbap
XHT  XHTML Document  application/xhtml+xml
XHTML  XHTML Document  application/xhtml+xml
XLK  XLK File  
XLL  XLL File  
XLS  XLS File  
XLSB  XLSB File  
XLSM  XLSM File  
XLSX  XLSX File  
XLTM  XLTM File  
XLTX  XLTX File  
XML  XML Document  text/xml
XPS  XPS Document  application/vnd.ms-xpsdocument
XRM-MS  XrML Digital License  text/xml
XSL  XSL Stylesheet  text/xml
ZFSENDTOTARGET  Compressed (zipped) Folder SendTo Target  
ZIP  Compressed (zipped) Folder  application/x-zip-compressed


Windows Security

 
Operating System Properties:
OS Name  Microsoft Windows 8.1
OS Service Pack  [ TRIAL VERSION ]
Winlogon Shell  explorer.exe
User Account Control (UAC)  Enabled
System Restore  Enabled
 
Data Execution Prevention (DEP, NX, EDB):
Supported by Operating System  Yes
Supported by CPU  Yes
Active (To Protect Applications)  Yes
Active (To Protect Drivers)  Yes


Windows Update

 
Update Description  Update Type  Inst. Date
(Automatic Update)  Download:Automatic, Install:Scheduled  Every Day 0:00
Broadcom - WLAN - Broadcom 802.11abgn Wireless SDIO Adapter  Update  2013.11.21.
Cumulative Security Update for ActiveX Killbits for Windows 8.1 (KB2900986)  Update  2013.11.21.
Cumulative Security Update for Internet Explorer 11 for Windows 8.1 (KB2888505)  Update  2013.11.21.
Definition Update for Windows Defender - KB2267602 (Definition 1.163.155.0)  Update  2013.11.21.
Definition Update for Windows Defender - KB2267602 (Definition 1.163.747.0)  Update  2013.11.29.
Microsoft Browser Choice Screen Update for EEA Users of Windows 8.1 (KB976002)  Update  2013.11.21.
Security Update for Internet Explorer Flash Player for Windows 8.1 (KB2898108)  Update  2013.11.21.
Security Update for Internet Explorer Flash Player for Windows 8.1 (KB2898108)  Update  2013.11.29.
Security Update for Windows 8.1 (KB2862152)  Update  2013.11.21.
Security Update for Windows 8.1 (KB2868626)  Update  2013.11.21.
Security Update for Windows 8.1 (KB2876331)  Update  2013.11.21.
Update for Microsoft Camera Codec Pack for Windows 8.1 (KB2859675)  Update  2013.11.21.
Update for Windows 8.1 (KB2884846)  Update  2013.11.21.
Update for Windows 8.1 (KB2887595)  Update  2013.11.21.
Update for Windows 8.1 (KB2895586)  Update  2013.11.21.
Update for Windows 8.1 (KB2895586)  Update  2013.11.29.
Update for Windows 8.1 (KB2895592)  Update  2013.11.21.
Update for Windows 8.1 (KB2895614)  Update  2013.11.21.
Update for Windows 8.1 (KB2895614)  Update  2013.11.29.
Update for Windows 8.1 (KB2902892)  Update  2013.11.21.
Update for Windows 8.1 (KB2902892)  Update  2013.11.29.
Update for Windows 8.1 (KB2904594)  Update  2013.11.21.
Windows Malicious Software Removal Tool for Windows 8 and Windows 8.1 - November 2013 (KB890830)  Update  2013.11.21.


Anti-Virus

 
Software Description  Software Version  Virus Database Date  Known Viruses
Windows Defender  4.3.9600.16384(winblue_rtm.130821-1623)  2013.11.27.  ?


Firewall

 
Software Description  Software Version  Status
Windows Firewall  6.3.9600.16384  Enabled


Regional

 
Time Zone:
Current Time Zone  Central Europe Standard Time
Current Time Zone Description  (UTC+01:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague
Change To Standard Time  Last Sunday of October 3:00:00
Change To Daylight Saving Time  Last Sunday of March 2:00:00
 
Language:
Language Name (Native)  magyar
Language Name (English)  Hungarian
Language Name (ISO 639)  hu
 
Country/Region:
Country Name (Native)  Magyarország
Country Name (English)  Hungary
Country Name (ISO 3166)  HU
Country Code  36
 
Currency:
Currency Name (Native)  forint
Currency Name (English)  Hungarian Forint
Currency Symbol (Native)  Ft
Currency Symbol (ISO 4217)  HUF
Currency Format  123 456 789,00 Ft
Negative Currency Format  -123 456 789,00 Ft
 
Formatting:
Time Format  H:mm:ss
Short Date Format  yyyy.MM.dd.
Long Date Format  yyyy. MMMM d.
Number Format  123 456 789,00
Negative Number Format  -123 456 789,00
List Format  first; second; third
Native Digits  0123456789
 
Days of Week:
Native Name for Monday  hétfõ / H
Native Name for Tuesday  kedd / K
Native Name for Wednesday  szerda / Sze
Native Name for Thursday  csütörtök / Cs
Native Name for Friday  péntek / P
Native Name for Saturday  szombat / Szo
Native Name for Sunday  vasárnap / V
 
Months:
Native Name for January  január / jan.
Native Name for February  február / febr.
Native Name for March  március / márc.
Native Name for April  április / ápr.
Native Name for May  május / máj.
Native Name for June  június / jún.
Native Name for July  július / júl.
Native Name for August  augusztus / aug.
Native Name for September  szeptember / szept.
Native Name for October  október / okt.
Native Name for November  november / nov.
Native Name for December  december / dec.
 
Miscellaneous:
Calendar Type  Gregorian (localized)
Default Paper Size  A4
Measurement System  Metric
 
Display Languages:
LCID 0409h (Active)  English (United States)
LCID 0C0Ah  Spanish (Spain, International Sort)
LCID 040Ch  French (France)
LCID 0804h  Chinese (Simplified, China)
LCID 0C04h  Chinese (Traditional, Hong Kong SAR)


Environment

 
Variable  Value
__COMPAT_LAYER  DetectorsWin7
ALLUSERSPROFILE  C:\ProgramData
APPDATA  C:\Users\Transformer T100\AppData\Roaming
CommonProgramFiles  C:\Program Files\Common Files
COMPUTERNAME  T100
ComSpec  C:\Windows\system32\cmd.exe
FP_NO_HOST_CHECK  NO
HOMEDRIVE  C:
HOMEPATH  \Users\Transformer T100
LOCALAPPDATA  C:\Users\Transformer T100\AppData\Local
LOGONSERVER  \\T100
NUMBER_OF_PROCESSORS  4
OS  Windows_NT
Path  C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\
PATHEXT  .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PROCESSOR_ARCHITECTURE  x86
PROCESSOR_IDENTIFIER  x86 Family 6 Model 55 Stepping 3, GenuineIntel
PROCESSOR_LEVEL  6
PROCESSOR_REVISION  3703
ProgramData  C:\ProgramData
ProgramFiles  C:\Program Files
PSModulePath  C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
PUBLIC  C:\Users\Public
SystemDrive  C:
SystemRoot  C:\Windows
TEMP  C:\Users\TRANSF~1\AppData\Local\Temp
TMP  C:\Users\TRANSF~1\AppData\Local\Temp
USERDOMAIN_ROAMINGPROFILE  T100
USERDOMAIN  T100
USERNAME  Transformer T100
USERPROFILE  C:\Users\Transformer T100
windir  C:\Windows


Control Panel

 
Name  Comment
Action Center  Review recent messages and resolve problems with your computer.
Add features to Windows 8.1  A convenient and affordable way to add features to Windows
Administrative Tools  Configure administrative settings for your computer.
ASUS Smart Gesture  C:\Program Files\ASUS\ASUS Smart Gesture\AsTPCenter\x86\AsusTPConfigure.exe,-103
AutoPlay  Change default settings for CDs, DVDs, and devices so that you can automatically play music, view pictures, install software, and play games.
Color Management  Change advanced color management settings for displays, scanners, and printers.
Credential Manager  Manage your Windows credentials.
Date and Time  Set the date, time, and time zone for your computer.
Default Programs  Choose which programs you want Windows to use for activities like web browsing, editing photos, sending e-mail, and playing music.
Device Manager  View and update your hardware's settings and driver software.
Devices and Printers  View and manage devices, printers, and print jobs
Display  Change your display settings and make it easier to read what's on the desktop.
Ease of Access Center  Make your computer easier to use.
Family Safety  Change Family Safety settings.
File History  Keep a history of your files
Flash Player  Manage Flash Player Settings
Folder Options  Customize the display of files and folders.
Fonts  Add, change, and manage fonts on your computer.
HomeGroup  View HomeGroup settings, choose sharing options, and view or change the password.
Indexing Options  Change how Windows indexes to search faster
Intel(R) HD grafika  A számítógép grafikus hardverének beállítása.
Internet Options  Configure your Internet display and connection settings.
Keyboard  Customize your keyboard settings, such as the cursor blink rate and the character repeat rate.
Language  Customize your language preferences and international settings
Location Settings  Configure your sensor settings.
Mouse  Customize your mouse settings, such as the button configuration, double-click speed, mouse pointers, and motion speed.
Network and Sharing Center  Check network status, change network settings and set preferences for sharing files and printers.
Notification Area Icons  Select which icons and notifications appear in the notification area.
Pen and Touch  Configures pen options for a Tablet PC.
Personalization  Change the pictures, colors, and sounds for this computer.
Phone and Modem  Configure your telephone dialing rules and modem settings.
Power Options  Conserve energy or maximize performance by choosing how your computer manages power.
Programs and Features  Uninstall or change programs on your computer.
Realtek Audio Manager  Realtek Audio Control Panel
Recovery  Recovery
Region  Customize settings for the display of languages, numbers, times, and dates.
RemoteApp and Desktop Connections  Manage your RemoteApp and Desktop Connections
Sound  Configure your audio devices or change the sound scheme for your computer.
Speech Recognition  Configure how speech recognition works on your computer.
Storage Spaces  Help protect your files from drive failure.
Sync Center  Sync files between your computer and network folders
System  View information about your computer, and change settings for hardware, performance, and remote connections.
Tablet PC Settings  Configures tablet and screen settings for a Tablet PC.
Taskbar and Navigation  Customize the taskbar, such as the types of items to be displayed and how they should appear.
Troubleshooting  Troubleshoot and fix common computer problems.
User Accounts  Change user account settings and passwords for people who share this computer.
Windows Defender  Helps protect users from malware and other potentially unwanted software
Windows Firewall  Set firewall security options to help protect your computer from hackers and malicious software.
Windows Mobility Center  Adjust display brightness, volume, power options, and other commonly used mobile PC settings.
Windows Update  Check for software and driver updates, choose automatic updating settings, or view installed updates.
Work Folders  Access your work files anywhere, anytime.


Recycle Bin

 
Drive  Items Size  Items Count  Space %  Recycle Bin
C:  0  0  ?  ?


System Files

 
[ autoexec.bat ]
 
REM Dummy file for NTVDM
 
[ config.sys ]
 
FILES=40
 
[ autoexec.nt ]
 
@echo off
REM AUTOEXEC.BAT is not used to initialize the MS-DOS environment.
REM AUTOEXEC.NT is used to initialize the MS-DOS environment unless a
REM different startup file is specified in an application's PIF.
REM Install CD ROM extensions
lh %SystemRoot%\system32\mscdexnt.exe
REM Install network redirector (load before dosx.exe)
lh %SystemRoot%\system32\redir
REM Install DPMI support
lh %SystemRoot%\system32\dosx
REM The following line enables Sound Blaster 2.0 support on NTVDM.
REM The command for setting the BLASTER environment is as follows:
REM SET BLASTER=A220 I5 D1 P330
REM where:
REM A specifies the sound blaster's base I/O port
REM I specifies the interrupt request line
REM D specifies the 8-bit DMA channel
REM P specifies the MPU-401 base I/O port
REM T specifies the type of sound blaster card
REM 1 - Sound Blaster 1.5
REM 2 - Sound Blaster Pro I
REM 3 - Sound Blaster 2.0
REM 4 - Sound Blaster Pro II
REM 6 - SOund Blaster 16/AWE 32/32/64
REM
REM The default value is A220 I5 D1 T3 and P330. If any of the switches is
REM left unspecified, the default value will be used. (NOTE, since all the
REM ports are virtualized, the information provided here does not have to
REM match the real hardware setting.) NTVDM supports Sound Blaster 2.0 only.
REM The T switch must be set to 3, if specified.
SET BLASTER=A220 I5 D1 P330 T3
REM To disable the sound blaster 2.0 support on NTVDM, specify an invalid
REM SB base I/O port address. For example:
REM SET BLASTER=A0
 
[ config.nt ]
 
REM Windows MS-DOS Startup File
REM
REM CONFIG.SYS vs CONFIG.NT
REM CONFIG.SYS is not used to initialize the MS-DOS environment.
REM CONFIG.NT is used to initialize the MS-DOS environment unless a
REM different startup file is specified in an application's PIF.
REM
REM ECHOCONFIG
REM By default, no information is displayed when the MS-DOS environment
REM is initialized. To display CONFIG.NT/AUTOEXEC.NT information, add
REM the command echoconfig to CONFIG.NT or other startup file.
REM
REM NTCMDPROMPT
REM When you return to the command prompt from a TSR or while running an
REM MS-DOS-based application, Windows runs COMMAND.COM. This allows the
REM TSR to remain active. To run CMD.EXE, the Windows command prompt,
REM rather than COMMAND.COM, add the command ntcmdprompt to CONFIG.NT or
REM other startup file.
REM
REM DOSONLY
REM By default, you can start any type of application when running
REM COMMAND.COM. If you start an application other than an MS-DOS-based
REM application, any running TSR may be disrupted. To ensure that only
REM MS-DOS-based applications can be started, add the command dosonly to
REM CONFIG.NT or other startup file.
REM
REM EMM
REM You can use EMM command line to configure EMM(Expanded Memory Manager).
REM The syntax is:
REM
REM EMM = [A=AltRegSets] [B=BaseSegment] [RAM]
REM
REM AltRegSets
REM specifies the total Alternative Mapping Register Sets you
REM want the system to support. 1 <= AltRegSets <= 255. The
REM default value is 8.
REM BaseSegment
REM specifies the starting segment address in the Dos conventional
REM memory you want the system to allocate for EMM page frames.
REM The value must be given in Hexdecimal.
REM 0x1000 <= BaseSegment <= 0x4000. The value is rounded down to
REM 16KB boundary. The default value is 0x4000
REM RAM
REM specifies that the system should only allocate 64Kb address
REM space from the Upper Memory Block(UMB) area for EMM page frames
REM and leave the rests(if available) to be used by DOS to support
REM loadhigh and devicehigh commands. The system, by default, would
REM allocate all possible and available UMB for page frames.
REM
REM The EMM size is determined by pif file(either the one associated
REM with your application or _default.pif). If the size from PIF file
REM is zero, EMM will be disabled and the EMM line will be ignored.
REM
dos=high, umb
device=%SystemRoot%\system32\himem.sys
files=40
 
[ system.ini ]
 
; for 16-bit app support
[386Enh]
woafont=dosapp.fon
EGA80WOA.FON=EGA80WOA.FON
EGA40WOA.FON=EGA40WOA.FON
CGA80WOA.FON=CGA80WOA.FON
CGA40WOA.FON=CGA40WOA.FON
[drivers]
wave=mmdrv.dll
timer=timer.drv
[mci]
 
[ win.ini ]
 
; for 16-bit app support
[fonts]
[extensions]
[mci extensions]
[files]
[Mail]
MAPI=1
 
[ hosts ]
 
 
[ lmhosts.sam ]
 


System Folders

 
System Folder  Path
Administrative Tools  C:\Users\Transformer T100\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
AppData  C:\Users\Transformer T100\AppData\Roaming
Cache  C:\Users\Transformer T100\AppData\Local\Microsoft\Windows\INetCache
CD Burning  C:\Users\Transformer T100\AppData\Local\Microsoft\Windows\Burn\Burn
Common Administrative Tools  C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
Common AppData  C:\ProgramData
Common Desktop  C:\Users\Public\Desktop
Common Documents  C:\Users\Public\Documents
Common Favorites  C:\Users\Transformer T100\Favorites
Common Files  C:\Program Files\Common Files
Common Music  C:\Users\Public\Music
Common Pictures  C:\Users\Public\Pictures
Common Programs  C:\ProgramData\Microsoft\Windows\Start Menu\Programs
Common Start Menu  C:\ProgramData\Microsoft\Windows\Start Menu
Common Startup  C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Common Templates  C:\ProgramData\Microsoft\Windows\Templates
Common Video  C:\Users\Public\Videos
Cookies  C:\Users\Transformer T100\AppData\Local\Microsoft\Windows\INetCookies
Desktop  C:\Users\Transformer T100\Desktop
Device  C:\Windows\inf
Favorites  C:\Users\Transformer T100\Favorites
Fonts  C:\Windows\Fonts
History  C:\Users\Transformer T100\AppData\Local\Microsoft\Windows\History
Local AppData  C:\Users\Transformer T100\AppData\Local
My Documents  C:\Users\Transformer T100\Documents
My Music  C:\Users\Transformer T100\Music
My Pictures  C:\Users\Transformer T100\Pictures
My Video  C:\Users\Transformer T100\Videos
NetHood  C:\Users\Transformer T100\AppData\Roaming\Microsoft\Windows\Network Shortcuts
PrintHood  C:\Users\Transformer T100\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
Profile  C:\Users\Transformer T100
Program Files  C:\Program Files
Programs  C:\Users\Transformer T100\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
Recent  C:\Users\Transformer T100\AppData\Roaming\Microsoft\Windows\Recent
Resources  C:\Windows\resources
SendTo  C:\Users\Transformer T100\AppData\Roaming\Microsoft\Windows\SendTo
Start Menu  C:\Users\Transformer T100\AppData\Roaming\Microsoft\Windows\Start Menu
Startup  C:\Users\Transformer T100\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
System  C:\Windows\system32
Temp  C:\Users\TRANSF~1\AppData\Local\Temp\
Templates  C:\Users\Transformer T100\AppData\Roaming\Microsoft\Windows\Templates
Windows  C:\Windows


Event Logs

 
Log Name  Event Type  Category  Generated On  User  Source  Description
Application  Warning  3  2013-11-23 11:42:38    Windows Search Service  3036: Crawl could not be completed on content source <winrt://{S-1-5-21-510496655-4205887700-2175606355-1001}/>. Context: Application, SystemIndex Catalog Details: The parameter is incorrect. (HRESULT : 0x80070057) (0x80070057)
Application  Error  None  2013-11-23 12:37:41    Customer Experience Improvement Program  
Application  Warning  3  2013-11-28 17:02:48    Windows Search Service  3036: Crawl could not be completed on content source <winrt://{S-1-5-21-510496655-4205887700-2175606355-1001}/>. Context: Application, SystemIndex Catalog Details: The parameter is incorrect. (HRESULT : 0x80070057) (0x80070057)
Application  Warning  None  2013-11-28 17:35:45    Wlclntfy  6004: The winlogon notification subscriber <TrustedInstaller> failed a critical notification event.
Application  Warning  None  2013-11-28 17:35:54    VSS  8230: Volume Shadow Copy Service error: Failed resolving account NETWORK SERVICE with status 2226. Check connection to domain controller and VssAccessControl registry key. Operation: Initializing Writer Context: Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} Writer Name: WMI Writer Error-specific details: Error: NetLocalGroupGetMemebers(NETWORK SERVICE), 0x800708b2, This operation is only allowed on the primary domain controller of the domain.
Application  Warning  None  2013-11-28 17:35:59  SYSTEM  Microsoft-Windows-WMI  65: Windows Management Instrumentation (WMI) Service is starting to restore the WMI repository
Application  Error  None  2013-11-28 17:36:00  SYSTEM  Microsoft-Windows-WMI  24: Event provider $Core attempted to register query "select * from __InstanceOperationEvent" whose target class "__InstanceOperationEvent" in //./root/SECURITY namespace does not exist. The query will be ignored.
Application  Error  None  2013-11-28 17:36:00  SYSTEM  Microsoft-Windows-WMI  24: Event provider $Core attempted to register query "select * from __InstanceOperationEvent" whose target class "__InstanceOperationEvent" in //./root namespace does not exist. The query will be ignored.
Application  Error  None  2013-11-28 17:36:00  SYSTEM  Microsoft-Windows-WMI  24: Event provider $Core attempted to register query "select * from __InstanceOperationEvent" whose target class "__InstanceOperationEvent" in //./root/DEFAULT namespace does not exist. The query will be ignored.
Application  Error  None  2013-11-28 17:36:00  SYSTEM  Microsoft-Windows-WMI  24: Event provider $Core attempted to register query "select * from __ClassOperationEvent" whose target class "__ClassOperationEvent" in //./root/SECURITY namespace does not exist. The query will be ignored.
Application  Error  None  2013-11-28 17:36:00  SYSTEM  Microsoft-Windows-WMI  24: Event provider $Core attempted to register query "select * from __ClassOperationEvent" whose target class "__ClassOperationEvent" in //./root namespace does not exist. The query will be ignored.
Application  Error  None  2013-11-28 17:36:00  SYSTEM  Microsoft-Windows-WMI  24: Event provider $Core attempted to register query "select * from __ClassOperationEvent" whose target class "__ClassOperationEvent" in //./root/DEFAULT namespace does not exist. The query will be ignored.
Application  Error  None  2013-11-28 17:36:00  SYSTEM  Microsoft-Windows-WMI  24: Event provider $Core attempted to register query "select * from __NamespaceOperationEvent" whose target class "__NamespaceOperationEvent" in //./root/SECURITY namespace does not exist. The query will be ignored.
Application  Error  None  2013-11-28 17:36:00  SYSTEM  Microsoft-Windows-WMI  24: Event provider $Core attempted to register query "select * from __NamespaceOperationEvent" whose target class "__NamespaceOperationEvent" in //./root namespace does not exist. The query will be ignored.
Application  Error  None  2013-11-28 17:36:00  SYSTEM  Microsoft-Windows-WMI  24: Event provider $Core attempted to register query "select * from __NamespaceOperationEvent" whose target class "__NamespaceOperationEvent" in //./root/DEFAULT namespace does not exist. The query will be ignored.
Application  Error  None  2013-11-28 17:36:00  SYSTEM  Microsoft-Windows-WMI  24: Event provider $Core attempted to register query "select * from __SystemEvent" whose target class "__SystemEvent" in //./root namespace does not exist. The query will be ignored.
Application  Error  None  2013-11-28 17:36:00  SYSTEM  Microsoft-Windows-WMI  24: Event provider $Core attempted to register query "select * from __SystemEvent" whose target class "__SystemEvent" in //./root/SECURITY namespace does not exist. The query will be ignored.
Application  Error  None  2013-11-28 17:36:00  SYSTEM  Microsoft-Windows-WMI  24: Event provider $Core attempted to register query "select * from __SystemEvent" whose target class "__SystemEvent" in //./root/DEFAULT namespace does not exist. The query will be ignored.
Application  Error  None  2013-11-28 17:36:00  SYSTEM  Microsoft-Windows-WMI  24: Event provider $Core attempted to register query "select * from __TimerEvent" whose target class "__TimerEvent" in //./root namespace does not exist. The query will be ignored.
Application  Error  None  2013-11-28 17:36:00  SYSTEM  Microsoft-Windows-WMI  24: Event provider $Core attempted to register query "select * from __TimerEvent" whose target class "__TimerEvent" in //./root/DEFAULT namespace does not exist. The query will be ignored.
Application  Error  None  2013-11-28 17:36:00  SYSTEM  Microsoft-Windows-WMI  24: Event provider $Core attempted to register query "select * from __TimerEvent" whose target class "__TimerEvent" in //./root/SECURITY namespace does not exist. The query will be ignored.
Application  Error  None  2013-11-28 17:36:00  SYSTEM  Microsoft-Windows-WMI  10: Event filter with query "select * from __InstanceModificationEvent where targetinstance isa '__ArbitratorConfiguration'" could not be reactivated in namespace "//./root" because of error 0x80041033. Events cannot be delivered through this filter until the problem is corrected.
Application  Warning  None  2013-11-28 17:36:40  SYSTEM  Microsoft-Windows-WMI  63: A provider, LogFileEventConsumer, has been registered in the Windows Management Instrumentation namespace root\subscription to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:40  SYSTEM  Microsoft-Windows-WMI  63: A provider, LogFileEventConsumer, has been registered in the Windows Management Instrumentation namespace root\subscription to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:40  SYSTEM  Microsoft-Windows-WMI  63: A provider, CommandLineEventConsumer, has been registered in the Windows Management Instrumentation namespace root\subscription to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:40  SYSTEM  Microsoft-Windows-WMI  63: A provider, CommandLineEventConsumer, has been registered in the Windows Management Instrumentation namespace root\subscription to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:40  SYSTEM  Microsoft-Windows-WMI  63: A provider, ActiveScriptEventConsumer, has been registered in the Windows Management Instrumentation namespace root\subscription to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:40  SYSTEM  Microsoft-Windows-WMI  63: A provider, ActiveScriptEventConsumer, has been registered in the Windows Management Instrumentation namespace root\subscription to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:40  SYSTEM  Microsoft-Windows-WMI  63: A provider, ActiveScriptEventConsumer, has been registered in the Windows Management Instrumentation namespace root\default to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:40  SYSTEM  Microsoft-Windows-WMI  63: A provider, ActiveScriptEventConsumer, has been registered in the Windows Management Instrumentation namespace root\default to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:40  SYSTEM  Microsoft-Windows-WMI  63: A provider, LogFileEventConsumer, has been registered in the Windows Management Instrumentation namespace root\default to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:40  SYSTEM  Microsoft-Windows-WMI  63: A provider, LogFileEventConsumer, has been registered in the Windows Management Instrumentation namespace root\default to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:40  SYSTEM  Microsoft-Windows-WMI  63: A provider, CommandLineEventConsumer, has been registered in the Windows Management Instrumentation namespace root\default to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:40  SYSTEM  Microsoft-Windows-WMI  63: A provider, CommandLineEventConsumer, has been registered in the Windows Management Instrumentation namespace root\default to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:41  SYSTEM  Microsoft-Windows-WMI  63: A provider, HiPerfCooker_v1, has been registered in the Windows Management Instrumentation namespace Root\WMI to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:41  SYSTEM  Microsoft-Windows-WMI  63: A provider, HiPerfCooker_v1, has been registered in the Windows Management Instrumentation namespace Root\WMI to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:44  SYSTEM  Microsoft-Windows-WMI  63: A provider, RegistryEventProvider, has been registered in the Windows Management Instrumentation namespace Root\Default to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:44  SYSTEM  Microsoft-Windows-WMI  63: A provider, RegistryEventProvider, has been registered in the Windows Management Instrumentation namespace Root\Default to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:44  SYSTEM  Microsoft-Windows-WMI  63: A provider, RegistryEventProvider, has been registered in the Windows Management Instrumentation namespace Root\cimv2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:44  SYSTEM  Microsoft-Windows-WMI  63: A provider, RegistryEventProvider, has been registered in the Windows Management Instrumentation namespace Root\cimv2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:44  SYSTEM  Microsoft-Windows-WMI  63: A provider, MS_NT_EVENTLOG_EVENT_PROVIDER, has been registered in the Windows Management Instrumentation namespace Root\CIMV2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:44  SYSTEM  Microsoft-Windows-WMI  63: A provider, MS_NT_EVENTLOG_EVENT_PROVIDER, has been registered in the Windows Management Instrumentation namespace Root\CIMV2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:45  SYSTEM  Microsoft-Windows-WMI  63: A provider, WpcClamperProv, has been registered in the Windows Management Instrumentation namespace ROOT\CIMV2\Applications\WindowsParentalControls to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:45  SYSTEM  Microsoft-Windows-WMI  63: A provider, WpcClamperProv, has been registered in the Windows Management Instrumentation namespace ROOT\CIMV2\Applications\WindowsParentalControls to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:47  SYSTEM  Microsoft-Windows-WMI  63: A provider, PowerMeterProvider, has been registered in the Windows Management Instrumentation namespace root\cimv2\power to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:47  SYSTEM  Microsoft-Windows-WMI  63: A provider, PowerMeterProvider, has been registered in the Windows Management Instrumentation namespace root\cimv2\power to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:47  SYSTEM  Microsoft-Windows-WMI  63: A provider, PowerMeterProvider, has been registered in the Windows Management Instrumentation namespace root\cimv2\power to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:47  SYSTEM  Microsoft-Windows-WMI  63: A provider, ProfileAssociationProviderInterop, has been registered in the Windows Management Instrumentation namespace root\interop to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:47  SYSTEM  Microsoft-Windows-WMI  63: A provider, ProfileAssociationProviderInterop, has been registered in the Windows Management Instrumentation namespace root\interop to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:47  SYSTEM  Microsoft-Windows-WMI  63: A provider, ProfileAssociationProviderCimV2, has been registered in the Windows Management Instrumentation namespace root\cimv2\power to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:47  SYSTEM  Microsoft-Windows-WMI  63: A provider, ProfileAssociationProviderCimV2, has been registered in the Windows Management Instrumentation namespace root\cimv2\power to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:48  SYSTEM  Microsoft-Windows-WMI  63: A provider, WsmAgent, has been registered in the Windows Management Instrumentation namespace root\Microsoft\Windows\winrm to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:48  SYSTEM  Microsoft-Windows-WMI  63: A provider, WsmAgent, has been registered in the Windows Management Instrumentation namespace root\Microsoft\Windows\winrm to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:50  SYSTEM  Microsoft-Windows-WMI  63: A provider, Win32_UserStateConfigurationProvider, has been registered in the Windows Management Instrumentation namespace root\CIMV2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:50  SYSTEM  Microsoft-Windows-WMI  63: A provider, Win32_UserStateConfigurationProvider, has been registered in the Windows Management Instrumentation namespace root\CIMV2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:50  SYSTEM  Microsoft-Windows-WMI  63: A provider, Win32_FolderRedirectionConfiguration, has been registered in the Windows Management Instrumentation namespace root\CIMV2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:50  SYSTEM  Microsoft-Windows-WMI  63: A provider, Win32_FolderRedirectionConfiguration, has been registered in the Windows Management Instrumentation namespace root\CIMV2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:51  SYSTEM  Microsoft-Windows-WMI  63: A provider, MDMSettingsProv, has been registered in the Windows Management Instrumentation namespace root\cimv2\mdm to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:51  SYSTEM  Microsoft-Windows-WMI  63: A provider, MDMSettingsProv, has been registered in the Windows Management Instrumentation namespace root\cimv2\mdm to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:51  SYSTEM  Microsoft-Windows-WMI  63: A provider, MDMSettingsProv, has been registered in the Windows Management Instrumentation namespace root\cimv2\mdm to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:52  SYSTEM  Microsoft-Windows-WMI  63: A provider, dsccore, has been registered in the Windows Management Instrumentation namespace root\Microsoft\Windows\DesiredStateConfiguration to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:52  SYSTEM  Microsoft-Windows-WMI  63: A provider, dsccore, has been registered in the Windows Management Instrumentation namespace root\Microsoft\Windows\DesiredStateConfiguration to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:54  SYSTEM  Microsoft-Windows-WMI  63: A provider, UserProfileConfigurationProvider, has been registered in the Windows Management Instrumentation namespace ROOT\CIMV2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:54  SYSTEM  Microsoft-Windows-WMI  63: A provider, UserProfileConfigurationProvider, has been registered in the Windows Management Instrumentation namespace ROOT\CIMV2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:54  SYSTEM  Microsoft-Windows-WMI  63: A provider, UserProfileConfigurationProvider, has been registered in the Windows Management Instrumentation namespace ROOT\CIMV2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:55  SYSTEM  Microsoft-Windows-WMI  63: A provider, NetEventPacketCapture, has been registered in the Windows Management Instrumentation namespace root\standardcimv2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:55  SYSTEM  Microsoft-Windows-WMI  63: A provider, NetEventPacketCapture, has been registered in the Windows Management Instrumentation namespace root\standardcimv2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:55  SYSTEM  Microsoft-Windows-WMI  63: A provider, NetEventPacketCapture, has been registered in the Windows Management Instrumentation namespace root\standardcimv2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:56  SYSTEM  Microsoft-Windows-WMI  63: A provider, DSCCoreProviders, has been registered in the Windows Management Instrumentation namespace root\Microsoft\Windows\DesiredStateConfiguration to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:56  SYSTEM  Microsoft-Windows-WMI  63: A provider, DSCCoreProviders, has been registered in the Windows Management Instrumentation namespace root\Microsoft\Windows\DesiredStateConfiguration to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:56  SYSTEM  Microsoft-Windows-WMI  63: A provider, DSCCoreProviders, has been registered in the Windows Management Instrumentation namespace root\Microsoft\Windows\DesiredStateConfiguration to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:57  SYSTEM  Microsoft-Windows-WMI  63: A provider, WpcWebSyncProv, has been registered in the Windows Management Instrumentation namespace ROOT\CIMV2\Applications\WindowsParentalControls to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:57  SYSTEM  Microsoft-Windows-WMI  63: A provider, WpcWebSyncProv, has been registered in the Windows Management Instrumentation namespace ROOT\CIMV2\Applications\WindowsParentalControls to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:57  SYSTEM  Microsoft-Windows-WMI  63: A provider, WpcWebSyncProvSecured, has been registered in the Windows Management Instrumentation namespace root\CIMV2\Applications\WindowsParentalControls\Secured to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Warning  None  2013-11-28 17:36:57  SYSTEM  Microsoft-Windows-WMI  63: A provider, WpcWebSyncProvSecured, has been registered in the Windows Management Instrumentation namespace root\CIMV2\Applications\WindowsParentalControls\Secured to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\NETADAPTERCIMTRACE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\SMBWMIV2.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\APPBACKGROUNDTASK.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\ES-ES\PSMODULEDISCOVERYPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WDACWMIPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\SCHEDPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\MSFEEDS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\FILETRACE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\MSDTCWMI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WININIT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\SR.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WUDFX02000.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WFASCIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\PS_MMAGENT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\POWERWMIPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\NETEVENTPACKETCAPTURE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\FOLDERREDIRECTIONWMIPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\USERSTATEWMIPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\ES-ES\RESTARTMANAGER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\XWIZARDS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\DSCCORECONFPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\USERPROFILEWMIPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\USERPROFILECONFIGURATIONWMIPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\MSFEEDSBS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WINLOGON.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\QOSWMI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\QOSWMITRC.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\MDMSETTINGSPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\STORAGEWMI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\STORAGEWMI_PASSTHRU.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\RDPCORE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\CIMWIN32.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WMIPCIMA.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\SECRCW32.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\SUBSCRPT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\NCPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\SYSTEM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\INTEROP.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\SCRCONS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\SMTPCONS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WBEMCONS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WMI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WIN32_PRINTER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WFS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\CLI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\CLIEGALIASES.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\KRNLPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WMITIMEP.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\REGEVENT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\DSPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WMIPIPRT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WMIPJOBJ.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\NTEVT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\MSI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WMIPICMP.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WMIPDFS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WMIPDSKQ.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WMIPSESS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\RSOP.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WGXINSTALLEDGAME.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\MSTSCAX.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\MSTSC.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\IRMON.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\NETTTCIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\NETDACIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\NETNCCIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\VSS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\VDS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WSCENTER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\SERVICEMODEL.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\IPMIPRV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\ISCSIPRF.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\ISCSIDSC.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\ISCSIWMIV2.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WHQLPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\NETEVENTPACKETCAPTURE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WFASCIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\PS_MMAGENT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\POWERWMIPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\FOLDERREDIRECTIONWMIPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\USERSTATEWMIPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\FR-FR\RESTARTMANAGER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\XWIZARDS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\QOSWMI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\QOSWMITRC.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\MDMSETTINGSPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\DSCCORECONFPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\USERPROFILEWMIPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\USERPROFILECONFIGURATIONWMIPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\MSFEEDSBS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WINLOGON.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\STORAGEWMI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\STORAGEWMI_PASSTHRU.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\RDPCORE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\SMBWITNESSWMIV2PROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\HBAAPI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\CIMDMTF.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\POWERMETERPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\PROFILEASSOCIATIONPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\NLMCIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\L2GPSTORE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WUDFX02000.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\SR.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\VPNCLIENTPSPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\DSCCORE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\RACWMIPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\MISPACE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WCNCSVC.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\MSNETIMPLATFORM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\NETSWITCHTEAM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\NPIVWMI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\PROGRAM FILES\WINDOWS DEFENDER\FR-FR\PROTECTIONMANAGEMENT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\PCSVDEVICE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\SERVICEMODEL35.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\NETTCPIP.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\FILETRACE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\RDPENCOM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\APPBACKGROUNDTASK.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WUDFX.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WMPNETWK.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\PRINTMANAGEMENTPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\DNSCLIENTPSPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\MDMAPPPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\SPPWMI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\NETADAPTERCIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\NETADAPTERCIMTRACE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\SMBWMIV2.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\SCHEDPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\FR-FR\PSMODULEDISCOVERYPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WDACWMIPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\MSFEEDS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\MSDTCWMI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\FR-FR\WININIT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\CIMWIN32.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WMIPCIMA.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\SECRCW32.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\SUBSCRPT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\NCPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\SYSTEM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\INTEROP.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\SCRCONS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\SMTPCONS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WBEMCONS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WMI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WIN32_PRINTER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WFS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\CLI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\CLIEGALIASES.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\KRNLPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WMITIMEP.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\REGEVENT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\DSPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WMIPIPRT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WMIPJOBJ.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\NTEVT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\MSI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WMIPICMP.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WMIPDFS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WMIPDSKQ.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WMIPSESS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\RSOP.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WGXINSTALLEDGAME.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\MSTSCAX.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\MSTSC.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\IRMON.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\NETTTCIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\NETDACIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\NETNCCIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\VSS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\VDS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WSCENTER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\SERVICEMODEL.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\IPMIPRV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\ISCSIPRF.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\ISCSIDSC.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\ISCSIWMIV2.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WHQLPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WMPNETWK.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WUDFX.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\PRINTMANAGEMENTPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\DNSCLIENTPSPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\MDMAPPPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\SPPWMI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:25  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\NETADAPTERCIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\HBAAPI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\CIMDMTF.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\POWERMETERPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\PROFILEASSOCIATIONPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\NLMCIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\L2GPSTORE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\SMBWITNESSWMIV2PROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\VPNCLIENTPSPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\MISPACE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\WCNCSVC.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\NPIVWMI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\DSCCORE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\PROGRAM FILES\WINDOWS DEFENDER\ES-ES\PROTECTIONMANAGEMENT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\RACWMIPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\PCSVDEVICE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\MSNETIMPLATFORM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\NETSWITCHTEAM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\RDPENCOM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\SERVICEMODEL35.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:26  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ES-ES\NETTCPIP.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\CIMWIN32.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WMIPCIMA.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\SECRCW32.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\SUBSCRPT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\NCPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\SYSTEM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\INTEROP.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\SCRCONS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\SMTPCONS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WBEMCONS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WMI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WIN32_PRINTER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WFS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\CLI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\CLIEGALIASES.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\KRNLPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WMITIMEP.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\REGEVENT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\DSPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WMIPIPRT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WMIPJOBJ.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\NTEVT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\MSI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WMIPICMP.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WMIPDFS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WMIPDSKQ.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WMIPSESS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\RSOP.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WGXINSTALLEDGAME.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\MSTSCAX.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\MSTSC.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\IRMON.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\NETTTCIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\NETDACIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\NETNCCIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\VSS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\VDS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WSCENTER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\IPMIPRV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\ISCSIPRF.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\ISCSIDSC.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\ISCSIWMIV2.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WHQLPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\POWERWMIPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\NETEVENTPACKETCAPTURE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\ZH-HK\RESTARTMANAGER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\XWIZARDS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\FOLDERREDIRECTIONWMIPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\USERSTATEWMIPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WINLOGON.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\QOSWMI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\QOSWMITRC.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\MDMSETTINGSPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\DSCCORECONFPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\PS_MMAGENT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\USERPROFILEWMIPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\USERPROFILECONFIGURATIONWMIPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\MSFEEDSBS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\HBAAPI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\CIMDMTF.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\POWERMETERPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\PROFILEASSOCIATIONPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\STORAGEWMI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\STORAGEWMI_PASSTHRU.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\RDPCORE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\NLMCIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\L2GPSTORE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\SMBWITNESSWMIV2PROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WFASCIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\MISPACE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WCNCSVC.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\VPNCLIENTPSPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\DSCCORE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\PROGRAM FILES\WINDOWS DEFENDER\ZH-HK\PROTECTIONMANAGEMENT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\RACWMIPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\PCSVDEVICE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\MSNETIMPLATFORM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\NETSWITCHTEAM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\RDPENCOM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\NPIVWMI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\NETTCPIP.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\FILETRACE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WMPNETWK.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\APPBACKGROUNDTASK.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WUDFX.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\MDMAPPPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\SPPWMI.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\SMBWMIV2.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\PRINTMANAGEMENTPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\DNSCLIENTPSPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\ZH-HK\PSMODULEDISCOVERYPROVIDER.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WUDFX02000.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\NETADAPTERCIM.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\NETADAPTERCIMTRACE.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\SR.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\SCHEDPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\MSFEEDS.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WDACWMIPROV.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\WININIT.MFL while recovering .MOF file marked with autorecover.
Application  Error  None  2013-11-28 17:37:36  SYSTEM  Microsoft-Windows-WMI  4: Error 0x8004401e encountered when trying to load MOF C:\WINDOWS\SYSTEM32\WBEM\ZH-HK\MSDTCWMI.MFL while recovering .MOF file marked with autorecover.
Application  Warning  None  2013-11-28 17:39:04    Wlclntfy  6005: The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Application  Warning  None  2013-11-28 18:05:46    Wlclntfy  6006: The winlogon notification subscriber <TrustedInstaller> took 1662 second(s) to handle the notification event (CreateSession).
Application  Warning  None  2013-11-28 18:07:03    Wlclntfy  6005: The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Application  Warning  None  2013-11-28 18:08:22    Wlclntfy  6006: The winlogon notification subscriber <TrustedInstaller> took 138 second(s) to handle the notification event (CreateSession).
Application  Warning  None  2013-11-28 18:08:22    Wlclntfy  6004: The winlogon notification subscriber <TrustedInstaller> failed a critical notification event.
Application  Warning  None  2013-11-28 18:10:03    Wlclntfy  6005: The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Application  Warning  None  2013-11-28 18:26:29    Wlclntfy  6006: The winlogon notification subscriber <TrustedInstaller> took 1046 second(s) to handle the notification event (CreateSession).
Application  Warning  None  2013-11-28 18:26:29    Wlclntfy  6004: The winlogon notification subscriber <TrustedInstaller> failed a critical notification event.
Application  Warning  None  2013-11-28 18:34:03    Wlclntfy  6005: The winlogon notification subscriber <TrustedInstaller> is taking long time to handle the notification event (CreateSession).
Application  Warning  None  2013-11-28 18:50:29    Wlclntfy  6006: The winlogon notification subscriber <TrustedInstaller> took 1046 second(s) to handle the notification event (CreateSession).
Application  Warning  None  2013-11-28 18:50:29    Wlclntfy  6004: The winlogon notification subscriber <TrustedInstaller> failed a critical notification event.
Application  Error  None  2013-11-28 18:57:12    DptfPolicyLpmService  
Application  Error  None  2013-11-28 19:07:14    SideBySide  33: Activation context generation failed for "C:\Program Files\ASUS\ASUS Smart Gesture\win8\AsusTPDrv\x64\dpinst.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis.
Application  Error  None  2013-11-28 19:07:14    SideBySide  33: Activation context generation failed for "C:\Program Files\ASUS\ASUS Smart Gesture\win81\AsusTPDrv\x64\dpinst.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis.
Application  Error  None  2013-11-28 19:07:17    SideBySide  33: Activation context generation failed for "C:\Program Files\ASUS\ASUS Smart Gesture\win7\AsusTPDrv\x64\dpinst.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\dwm.exe' (pid 900) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\WUDFHost.exe' (pid 1256) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\wbem\WmiPrvSE.exe' (pid 2108) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\taskhostex.exe' (pid 2396) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\ASUS\ASUS Reading Mode\ReadingModeWatchDogx86.exe' (pid 2404) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\ProgramData\AsTouchPanel\AsPatchTouchPanel.exe' (pid 2412) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\ASUS\ASUS AC Reminder\ACReminderSrv.exe' (pid 2440) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\explorer.exe' (pid 2500) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe' (pid 2808) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\ASUS\ATK Package\ATK Media\DMedia.exe' (pid 2816) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe' (pid 3128) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\ASUS\ASUS Smart Gesture\AsTPCenter\x86\AsusTPLoader.exe' (pid 3428) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\BrowserChoice\browserchoice.exe' (pid 3464) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe' (pid 3472) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\ASUS\ASUS Smart Gesture\AsTPCenter\x86\AsusTPCenter.exe' (pid 3504) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\WWAHost.exe' (pid 3524) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\ASUS\ASUS Smart Gesture\AsTPCenter\x86\AsusTPHelper.exe' (pid 3900) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\igfxext.exe' (pid 2704) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\DptfPolicyLpmServiceHelper.exe' (pid 2524) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\igfxtray.exe' (pid 2772) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\igfxsrvc.exe' (pid 2740) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\hkcmd.exe' (pid 1024) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\igfxpers.exe' (pid 2276) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe' (pid 2228) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\Internet Explorer\iexplore.exe' (pid 3424) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\Internet Explorer\iexplore.exe' (pid 3720) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\WWAHost.exe' (pid 2328) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\RuntimeBroker.exe' (pid 2344) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\WinStore\WSHost.exe' (pid 1644) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\ASUS\WebStorage\2.0.3.226\AsusWSPanel.exe' (pid 2340) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\ASUS\ASUS Live Update\LiveUpdate.exe' (pid 724) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\taskhost.exe' (pid 3100) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:30  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\dllhost.exe' (pid 3104) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:31  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\Internet Explorer\ielowutil.exe' (pid 4164) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:31  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\wbem\WmiPrvSE.exe' (pid 2700) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:40  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\WWAHost.exe' (pid 3524) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:40  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\Internet Explorer\iexplore.exe' (pid 3720) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:31:40  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\WWAHost.exe' (pid 2328) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:32:12  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\WUDFHost.exe' (pid 1256) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:32:12  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\wbem\WmiPrvSE.exe' (pid 2108) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:32:12  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\explorer.exe' (pid 2500) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:32:12  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe' (pid 2808) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:32:12  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\ASUS\ATK Package\ATK Media\DMedia.exe' (pid 2816) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:32:12  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\ASUS\ASUS Smart Gesture\AsTPCenter\x86\AsusTPLoader.exe' (pid 3428) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:32:12  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\WWAHost.exe' (pid 3524) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:32:12  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe' (pid 2228) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:32:12  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\Internet Explorer\iexplore.exe' (pid 3424) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:32:12  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\Internet Explorer\iexplore.exe' (pid 3720) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:32:12  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\WWAHost.exe' (pid 2328) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:32:12  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\WinStore\WSHost.exe' (pid 1644) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:32:12  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\taskhost.exe' (pid 3100) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:32:12  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Windows\System32\dllhost.exe' (pid 3104) cannot be restarted - 1.
Application  Warning  None  2013-11-29 02:33:54  SYSTEM  Microsoft-Windows-RestartManager  10010: Application 'C:\Program Files\Internet Explorer\iexplore.exe' (pid 3424) cannot be restarted - 1.
Security  Audit Success  12544  2013-11-23 11:42:31    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x274 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-23 11:42:31    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-23 11:46:11    Microsoft-Windows-Security-Auditing  4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: Transformer T100 Account Domain: T100 Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x24c Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: 127.0.0.1 Port: 0 This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Security  Audit Success  12544  2013-11-23 11:46:11    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 7 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x1f97505 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x24c Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: T100 Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-23 11:46:11    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 7 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x1f9752b Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x24c Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: T100 Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12545  2013-11-23 11:46:11    Microsoft-Windows-Security-Auditing  4634: An account was logged off. Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x1f9752b Logon Type: 7 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
Security  Audit Success  12545  2013-11-23 11:46:11    Microsoft-Windows-Security-Auditing  4634: An account was logged off. Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x1f97505 Logon Type: 7 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
Security  Audit Success  12548  2013-11-23 11:46:11    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x1f97505 Privileges: SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-23 11:46:32    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x274 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-23 11:46:32    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x274 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-23 11:46:32    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-23 11:46:32    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-23 11:49:16    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x274 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-23 11:49:16    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-23 12:37:44    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x274 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-23 12:37:44    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-23 19:02:02    Microsoft-Windows-Security-Auditing  4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: Transformer T100 Account Domain: T100 Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x24c Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: 127.0.0.1 Port: 0 This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Security  Audit Success  12544  2013-11-23 19:02:02    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 7 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x1fdaf47 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x24c Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: T100 Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-23 19:02:02    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 7 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x1fdaf71 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x24c Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: T100 Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12545  2013-11-23 19:02:02    Microsoft-Windows-Security-Auditing  4634: An account was logged off. Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x1fdaf71 Logon Type: 7 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
Security  Audit Success  12545  2013-11-23 19:02:02    Microsoft-Windows-Security-Auditing  4634: An account was logged off. Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x1fdaf47 Logon Type: 7 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
Security  Audit Success  12548  2013-11-23 19:02:02    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x1fdaf47 Privileges: SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 17:02:20    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x274 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:02:20    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 17:04:15    Microsoft-Windows-Security-Auditing  4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: Transformer T100 Account Domain: T100 Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x24c Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: 127.0.0.1 Port: 0 This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Security  Audit Success  12544  2013-11-28 17:04:15    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 7 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x200db05 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x24c Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: T100 Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 17:04:15    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 7 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x200db2b Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x24c Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: T100 Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12545  2013-11-28 17:04:15    Microsoft-Windows-Security-Auditing  4634: An account was logged off. Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x200db2b Logon Type: 7 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
Security  Audit Success  12545  2013-11-28 17:04:15    Microsoft-Windows-Security-Auditing  4634: An account was logged off. Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x200db05 Logon Type: 7 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
Security  Audit Success  12548  2013-11-28 17:04:15    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x200db05 Privileges: SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 17:05:14    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x274 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:05:14    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 17:06:28    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x274 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12545  2013-11-28 17:06:28    Microsoft-Windows-Security-Auditing  4647: User initiated logoff: Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x207af This event is generated when a logoff is initiated. No further user-initiated activity can occur. This event can be interpreted as a logoff event.
Security  Audit Success  12548  2013-11-28 17:06:28    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 17:11:00    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x274 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 17:11:00    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x274 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:11:00    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 17:11:00    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 17:15:13    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x274 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:15:13    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 17:19:22    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x274 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:19:22    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 17:22:41    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x274 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:22:41    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 17:29:53    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x274 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:29:53    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12288  2013-11-28 17:33:19    Microsoft-Windows-Security-Auditing  4608: Windows is starting up. This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Security  Audit Success  12544  2013-11-28 17:33:19    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Type: 0 Impersonation Level: - New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x4 Process Name: Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: - Authentication Package: - Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  13568  2013-11-28 17:33:19    Microsoft-Windows-Security-Auditing  4902: The Per-user audit policy table was created. Number of Elements: 0 Policy ID: 0x9190
Security  Audit Success  12544  2013-11-28 17:33:20    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 17:33:20    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-20 Account Name: NETWORK SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e4 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 17:33:20    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:33:20    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 17:33:20    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-20 Account Name: NETWORK SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e4 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 17:33:20    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 17:33:21    Microsoft-Windows-Security-Auditing  4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: DWM-1 Account Domain: Window Manager Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x284 Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: - Port: - This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Security  Audit Success  12544  2013-11-28 17:33:21    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 2 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xf1cd Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x284 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 17:33:21    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 2 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xf1f2 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x284 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 17:33:21    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:33:21    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xf1cd Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 17:33:21    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xf1f2 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege
Security  Audit Success  12548  2013-11-28 17:33:21    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  13568  2013-11-28 17:33:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\winload.efi Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\ci.dll Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\lsasrv.dll Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\IKEEXT.DLL Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\winload.exe Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\winresume.exe Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\ntdll.dll Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\hal.dll Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\winresume.efi Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\ntoskrnl.exe Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\sspicli.dll Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\BFE.DLL Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\halmacpi.dll Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\spp\tokens\ppdlic\NetworkSecurity-ppdlic.xrm-ms Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\dxgmms1.sys Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\rdyboost.sys Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\ndis.sys Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\dxgkrnl.sys Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\mrxsmb20.sys Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\ks.sys Handle ID: 0x18 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\mrxsmb.sys Handle ID: 0x18 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\ksecdd.sys Handle ID: 0x18 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\tcpip.sys Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\pdc.sys Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\fvevol.sys Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\wfplwfs.sys Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\inf\wfplwfs.inf Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\inf\errata.inf Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Boot\PCAT\bootmgr Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Boot\EFI\bootmgr.efi Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Boot\EFI\bootmgfw.efi Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_a421d1bfaf856e2b.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_fr-fr_28373d63876f08c8.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_en-us_2650c83f8a48b821.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_es-es_2650c78b8a48b9a6.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_zh-hk_4e3889894e6d1583.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_zh-cn_4e388f3b4e6d0cf3.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_d7a65bb2f0e854e7.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_818c5a0e45020fba.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_ink_3c86e3db0b3b254c.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_journal_ada99bf7bc9c9733.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_journal_zh-hk_ff8b94f2baf35197.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_journal_zh-cn_ff8b95acbaf34fe7.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_defender_3e33901162166ae9.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_3296b36dbe4c7fa3.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_83386eac0379231b.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_c40c7a995ddd757b.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_bc1339ef8efa3c4c.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_04445b88cf0b8e8d.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_fr-fr_379139c69a39e1d4.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_en-us_35aac4a29d13912d.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_es-es_35aac3ee9d1392b2.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_zh-hk_5d9285ec6137ee8f.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_zh-cn_5d928b9e6137e5ff.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_mediaviewer_031bbf13c7a6f174.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_40104b85a18bfcb2.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_efi_0f890f82be247f42.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_pcat_0f8924c0debe64e4.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_vpnplugins_juniper_5202b8b12182e1c1.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_vpnplugins_f5_fdcbfdf645f834f9.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_vpnplugins_f5_f5vpnpluginappbg_978cbd3a7e028b77.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_vpnplugins_checkpoint_30967b7344988fbc.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_vpnplugins_sonicwall_508a4be0c07000ee.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_3f581daba4c8c835.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_1e6ccf0e6a91b570.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_a349059b05097caa.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_fff314eba11c101c.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_fr-fr_204f13e59b49b311.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_ff9b33f72ef29061.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_groupresour_f89377aef0e3070d.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_groupresour_ef6291c702239550.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_groupresour_ef628a4d02229fef.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_groupresour_ef6293ab02229242.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_groupresour_ef627ecf0237b69d.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_groupresour_ef627ec50237b6cd.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_scriptresou_9439642f1597caa3.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_scriptresou_5aff772efc12d48e.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_scriptresou_5919020afeec83e7.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_scriptresou_59190156feec856c.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_scriptresou_8100c354c310e149.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_scriptresou_8100c906c310d8b9.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_archivereso_76b8e47379b76aa0.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_archivereso_919a286d88402f27.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_archivereso_91be4d9787eef0f6.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_archivereso_91be2f4187ef1e59.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_archivereso_8ec97bf18e95b644.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_archivereso_8ec972078e95c574.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_registryres_edea8e2e2ccf59ab.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_registryres_6f00359868c32224.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:43    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_registryres_6efe330068cc290d.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_registryres_6efe354068cc2402.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_registryres_6f283f1a680ef6af.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_registryres_6f283fd4680ef4ff.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_processreso_e9b5c28bf1698a37.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_processreso_2c1bc8ce8cea0fc4.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_processreso_2c3fedf88c98d193.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_processreso_2c3fcfa28c98fef6.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_processreso_294b1c52933f96e1.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_processreso_294b1268933fa611.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_roleresourc_76a4a3ef5d2c01a4.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_roleresourc_0d6170cf3a6d1b85.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_roleresourc_0d5f6e373a76226e.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_roleresourc_0d5f70773a761d63.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_roleresourc_0d897a5139b8f010.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_roleresourc_0d897b0b39b8ee60.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_servicereso_fb85110125922f37.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_servicereso_e98c65c1017cea30.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_servicereso_e9b08aeb012babff.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_servicereso_e9b06c95012bd962.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_servicereso_e6bbb94507d2714d.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_servicereso_e6bbaf5b07d2807d.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_packagereso_7170c4cae89762bc.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_packagereso_94ebe822b39e7d67.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_packagereso_95100d4cb34d3f36.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_packagereso_950feef6b34d6c99.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_packagereso_921b3ba6b9f40484.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_packagereso_921b31bcb9f413b4.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_logresource_55a4f1e43ab800fa.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_logresource_a1d183e92635cb99.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_logresource_a1f5a91325e48d68.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_logresource_a1f58abd25e4bacb.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_logresource_9f00d76d2c8b52b6.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_logresource_9f00cd832c8b61e6.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_userresourc_6c89372784f42be7.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_userresourc_c8401d237c108960.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_userresourc_c83e1a8b7c199049.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_userresourc_c83e1ccb7c198b3e.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_userresourc_c86826a57b5c5deb.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_userresourc_c868275f7b5c5c3b.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_environment_f90a921d23087c69.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_environment_84d901a41af020fa.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_environment_84fd26ce1a9ee2c9.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_environment_84fd08781a9f102c.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_environment_820855282145a817.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_environment_82084b3e2145b747.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_en-us_204f0c6b9b48bdb0.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_es-es_204f15c99b48b003.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_zh-hk_204f00ed9b5dd45e.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_zh-cn_204f00e39b5dd48e.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_f1780fdbb7b569a2.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_8416c27bd490b8bd.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_zh-cn_cc275bf106f6763f.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_zh-hk_cc275bfb06f6760f.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-hk_6a84939e4900ccf6.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_boot_06654401df2fc50e.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migration_927a21df1acd7c18.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_fr-fr_448347788202c03b.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dism_066548addf2fbd4b.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_es-es_429cd1a084dc7119.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-cn_6a8499504900c466.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spp_tokens_ppdlic_0f09ba294211a24b.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_oobe_06655c95df2fa06f.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_common_8c297630658eaa3d.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_en-us_429cd25484dc6f94.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_0307ca33e1cd9708.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_0e66dffb08041cab.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_inbox.media.shared_styles_0b8acc230dca130a.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_windowsinternal_inbox_media_viewer_cfc88b9afeef4188.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_windowsinternal_inbox_media_viewer_edit_272c0da94a4002b4.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_windowsinternal_inbox_media_viewer_viewer_592c52ca633f93be.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_windowsinternal_inbox_media_viewer_camera_5bc8d30c5d8362b9.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_windowsinternal_inbox_media_viewer_pano_272c02994a40148c.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_6247a388787724b8.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_pris_a8c1f2a41196ba80.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_1e9f55b2d3f87dd3.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_apppatch_1143992cbbbebcab.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_09ec0b99a5045113.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\explorer.exe Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\FileManager\FileManagerApp.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\FileManager\Bing.Immersive.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\FileManager\App.xbf Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\FileManager\AppxBlockMap.xml Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\FileManager\AppxManifest.xml Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\FileManager\DataModel.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\FileManager\FileManager.exe Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\FileManager\Telemetry.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\FileManager\PhotosApp.exe Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\FileManager\AppxSignature.p7x Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\apppatch\AcGenral.dll Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\apppatch\drvmain.sdb Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\apppatch\sysmain.sdb Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\apppatch\msimain.sdb Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\apppatch\AcSpecfc.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:44    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Camera\PhotosynthControls.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Camera\Bing.Immersive.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Camera\StitcherRT.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Camera\AppxBlockMap.xml Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Camera\D3DCaptureTrackerComponent.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Camera\AppxManifest.xml Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Camera\CameraUtilities.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Camera\Camera.exe Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Camera\AppxSignature.p7x Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\SystemResources\Windows.UI.SkyDrive\Windows.UI.SkyDrive.pri Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\SystemResources\Windows.UI.SkyDrive\PRIS\Windows.UI.SkyDrive.fr-FR.pri Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\SystemResources\Windows.UI.SkyDrive\PRIS\Windows.UI.SkyDrive.zh-CN.pri Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\SystemResources\Windows.UI.SkyDrive\PRIS\Windows.UI.SkyDrive.zh-HK.pri Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\SystemResources\Windows.UI.SkyDrive\PRIS\Windows.UI.SkyDrive.es-ES.pri Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\SystemResources\Windows.UI.SkyDrive\PRIS\Windows.UI.SkyDrive.en-US.pri Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\SystemResources\Windows.UI.MediaViewer\WindowsInternal_Inbox_Media_Viewer\Pano\PanoViewerControl.xbf Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\SystemResources\Windows.UI.MediaViewer\WindowsInternal_Inbox_Media_Viewer\Pano\PanoCaptureStitchPage.xbf Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\SystemResources\Windows.UI.MediaViewer\WindowsInternal_Inbox_Media_Viewer\Camera\CameraCaptureControl.xbf Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\SystemResources\Windows.UI.MediaViewer\WindowsInternal_Inbox_Media_Viewer\Viewer\ViewerPage.xbf Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\SystemResources\Windows.UI.MediaViewer\WindowsInternal_Inbox_Media_Viewer\Edit\EditPage.xbf Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\SystemResources\Windows.UI.MediaViewer\WindowsInternal_Inbox_Media_Viewer\Edit\EditSlider.xbf Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\SystemResources\Windows.UI.MediaViewer\WindowsInternal_Inbox_Media_Viewer\Edit\EditPageStyles.xbf Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\SystemResources\Windows.UI.MediaViewer\WindowsInternal_Inbox_Media_Viewer\Edit\VideoTrimPage.xbf Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\SystemResources\Windows.UI.MediaViewer\Inbox.Media.Shared\Styles\StandardStyles.xbf Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\mfplat.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Utilman.exe Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SkyDrive.exe Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.Data.Pdf.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\DscCoreConfProv.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\mstscax.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\DeviceCenter.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\glcndFilter.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\livessp.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\UIAutomationCore.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wlidprov.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\mftranscode.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\msctf.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.Networking.Vpn.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wuauclt.exe Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\iuilp.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\AppXDeploymentServer.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\authui.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\msctfuimanager.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SettingSyncCore.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\dpapisrv.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SessEnv.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SRH.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WorkFoldersRes.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SettingsHandlers.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wcncsvc.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WinSCard.dll Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SyncEngine.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\bisrv.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\sysmain.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\msra.exe Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\rascustom.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\ieframe.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\dwmcore.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wlansvc.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wlidsvc.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\TetheringMgr.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\ole32.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\thumbcache.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\fdprint.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wer.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.Media.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\AppXDeploymentClient.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\mfsrcsnk.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wimgapi.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wininet.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\GeofenceMonitorService.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\MFMediaEngine.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\workfolderssvc.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\dcomp.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WorkfoldersControl.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\mfnetcore.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.Devices.HumanInterfaceDevice.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\dxgi.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.Globalization.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\fontsub.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\efswrt.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\sppsvc.exe Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\shell32.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.Networking.BackgroundTransfer.ContentPrefetchTask.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\actxprxy.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WMPhoto.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\pcasvc.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\iertutil.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\win32k.sys Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\mcbuilder.exe Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SkyDriveTelemetry.dll Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:45    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SettingSyncHost.exe Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\rdsdwmdr.dll Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\jscript9diag.dll Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\CryptoWinRT.dll Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Faultrep.dll Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\usercpl.dll Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\twinapi.dll Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\mfcore.dll Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.UI.Xaml.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SettingSync.dll Handle ID: 0x54 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\rdpencom.dll Handle ID: 0x54 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\combase.dll Handle ID: 0x54 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\miutils.dll Handle ID: 0x54 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WebcamUi.dll Handle ID: 0x54 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SensorsClassExtension.dll Handle ID: 0x54 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\AppxAllUserStore.dll Handle ID: 0x54 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\kernel32.dll Handle ID: 0x54 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\KernelBase.dll Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\twinui.dll Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WorkFolders.exe Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\msvproc.dll Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\vmrdvcore.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\tpmvsc.dll Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\jscript9.dll Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\dui70.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\d3d10level9.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\pcaui.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\dwmapi.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\twinui.appcore.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\windows.immersiveshell.serviceprovider.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SkyDriveShell.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.Web.Http.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\CredentialMigrationHandler.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\dhcpcore.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\ReAgent.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WerFault.exe Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wbiosrvc.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\BulkOperationHost.exe Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.UI.Search.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\sysmon.ocx Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\ubpm.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.Devices.Usb.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\printui.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\mfsvr.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WorkFoldersShell.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wlanmsm.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\MDEServer.exe Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\recimg.exe Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\kerberos.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wcmsvc.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.Media.Streaming.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\BthRadioMedia.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wuaueng.dll Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\mshtml.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\MrmCoreR.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\uDWM.dll Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.UI.Immersive.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\urlmon.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SearchFolder.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\DscCore.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\riched20.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WorkFoldersGPExt.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\AxInstSv.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\AppReadiness.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wimserv.exe Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\d3d11.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\en-US\SettingSyncCore.dll.mui Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\en-US\WorkFoldersRes.dll.mui Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\en-US\ieframe.dll.mui Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\en-US\mshtml.dll.mui Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\en-US\twinapi.dll.mui Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Speech\Common\sapi.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\oobe\msoobeplugins.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\oobe\msoobedui.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\oobe\FirstLogonAnim.html Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\spp\tokens\ppdlic\appid-ppdlic.xrm-ms Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\spp\tokens\ppdlic\authui-ppdlic.xrm-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\spp\tokens\ppdlic\explorer-ppdlic.xrm-ms Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\spp\tokens\ppdlic\TabletPCInputPanel-ppdlic.xrm-ms Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\spp\tokens\ppdlic\WinStoreUI-ppdlic.xrm-ms Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\spp\tokens\ppdlic\iuilp-ppdlic.xrm-ms Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\spp\tokens\ppdlic\Security-SPP-ppdlic.xrm-ms Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\zh-CN\SettingSyncCore.dll.mui Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\zh-CN\WorkFoldersRes.dll.mui Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\zh-CN\mshtml.dll.mui Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\zh-CN\ieframe.dll.mui Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\zh-CN\shell32.dll.mui Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\zh-CN\twinapi.dll.mui Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\es-ES\SettingSyncCore.dll.mui Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\es-ES\WorkFoldersRes.dll.mui Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\es-ES\mshtml.dll.mui Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\es-ES\ieframe.dll.mui Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\es-ES\twinapi.dll.mui Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Dism\AppxProvider.dll Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\fr-FR\SettingSyncCore.dll.mui Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\fr-FR\WorkFoldersRes.dll.mui Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\fr-FR\mshtml.dll.mui Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\fr-FR\ieframe.dll.mui Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\fr-FR\twinapi.dll.mui Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\migration\dafmigplugin.dll Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Boot\winload.exe Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Boot\winload.efi Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\zh-HK\SettingSyncCore.dll.mui Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\zh-HK\WorkFoldersRes.dll.mui Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\zh-HK\mshtml.dll.mui Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\zh-HK\ieframe.dll.mui Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\zh-HK\twinapi.dll.mui Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\VerifierExt.sys Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\agilevpn.sys Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\nwifi.sys Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\srv2.sys Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\ipnat.sys Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\srvnet.sys Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\appid.sys Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\spool\drivers\w32x86\3\zh-HK\jnwdui.dll.mui Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\spool\drivers\w32x86\3\zh-CN\jnwdui.dll.mui Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\PSDesiredStateConfiguration.psm1 Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\zh-CN\PSDesiredStateConfiguration.Resource.psd1 Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\zh-HK\PSDesiredStateConfiguration.Resource.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\es-ES\PSDesiredStateConfiguration.Resource.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\en-US\PSDesiredStateConfiguration.Resource.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_EnvironmentResource\MSFT_EnvironmentResource.psm1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_EnvironmentResource\zh-CN\MSFT_EnvironmentResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_EnvironmentResource\zh-HK\MSFT_EnvironmentResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_EnvironmentResource\es-ES\MSFT_EnvironmentResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_EnvironmentResource\en-US\MSFT_EnvironmentResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_EnvironmentResource\fr-FR\MSFT_EnvironmentResource.strings.psd1 Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_UserResource\MSFT_UserResource.psm1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_UserResource\zh-CN\MSFT_UserResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_UserResource\zh-HK\MSFT_UserResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_UserResource\es-ES\MSFT_UserResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_UserResource\en-US\MSFT_UserResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_UserResource\fr-FR\MSFT_UserResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_PackageResource\MSFT_PackageResource.psm1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_PackageResource\zh-CN\PackageProvider.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_PackageResource\zh-HK\PackageProvider.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_PackageResource\es-ES\PackageProvider.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_PackageResource\en-US\PackageProvider.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_PackageResource\fr-FR\PackageProvider.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ServiceResource\MSFT_ServiceResource.psm1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ServiceResource\zh-CN\MSFT_ServiceResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ServiceResource\zh-HK\MSFT_ServiceResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ServiceResource\es-ES\MSFT_ServiceResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ServiceResource\en-US\MSFT_ServiceResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ServiceResource\fr-FR\MSFT_ServiceResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_RoleResource\MSFT_RoleResource.psm1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_RoleResource\zh-CN\MSFT_RoleResourceStrings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_RoleResource\zh-HK\MSFT_RoleResourceStrings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_RoleResource\es-ES\MSFT_RoleResourceStrings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_RoleResource\en-US\MSFT_RoleResourceStrings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_RoleResource\fr-FR\MSFT_RoleResourceStrings.psd1 Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ProcessResource\MSFT_ProcessResource.psm1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ProcessResource\zh-CN\MSFT_ProcessResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ProcessResource\zh-HK\MSFT_ProcessResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ProcessResource\es-ES\MSFT_ProcessResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ProcessResource\en-US\MSFT_ProcessResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ProcessResource\fr-FR\MSFT_ProcessResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_RegistryResource\MSFT_RegistryResource.psm1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_RegistryResource\zh-CN\MSFT_RegistryResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_RegistryResource\zh-HK\MSFT_RegistryResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:47    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_RegistryResource\es-ES\MSFT_RegistryResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_RegistryResource\en-US\MSFT_RegistryResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_RegistryResource\fr-FR\MSFT_RegistryResource.strings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ArchiveResource\MSFT_ArchiveResource.psm1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ArchiveResource\zh-CN\ArchiveProvider.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ArchiveResource\zh-HK\ArchiveProvider.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ArchiveResource\es-ES\ArchiveProvider.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ArchiveResource\en-US\ArchiveProvider.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ArchiveResource\fr-FR\ArchiveProvider.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ScriptResource\MSFT_ScriptResource.psm1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ScriptResource\zh-CN\MSFT_ScriptResourceStrings.psd1 Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ScriptResource\zh-HK\MSFT_ScriptResourceStrings.psd1 Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ScriptResource\es-ES\MSFT_ScriptResourceStrings.psd1 Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ScriptResource\en-US\MSFT_ScriptResourceStrings.psd1 Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_ScriptResource\fr-FR\MSFT_ScriptResourceStrings.psd1 Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_GroupResource\MSFT_GroupResource.psm1 Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_GroupResource\zh-CN\MSFT_GroupResource.strings.psd1 Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_GroupResource\zh-HK\MSFT_GroupResource.strings.psd1 Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_GroupResource\es-ES\MSFT_GroupResource.strings.psd1 Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_GroupResource\en-US\MSFT_GroupResource.strings.psd1 Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\DSCResources\MSFT_GroupResource\fr-FR\MSFT_GroupResource.strings.psd1 Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\PSDesiredStateConfiguration\fr-FR\PSDesiredStateConfiguration.Resource.psd1 Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\ImmersiveControlPanel\SystemSettings.exe Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\inf\apps.inf Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\sonicwall\msvcp120_app.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\sonicwall\MobileConnectVpnPluginAppBg.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\sonicwall\vcamp120_app.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\sonicwall\vcomp120_app.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\sonicwall\MobileConnectVpnPluginApp.exe Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\sonicwall\msvcr120_app.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\sonicwall\vccorlib120_app.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\checkpoint\CheckPointVpnPluginAppBg.winmd Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\checkpoint\resources.pri Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\checkpoint\CheckPointVpnPluginApp.exe Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\f5\msvcp120_app.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\f5\vcamp120_app.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\f5\vcomp120_app.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\f5\F5VpnPluginApp.exe Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\f5\msvcr120_app.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\f5\vccorlib120_app.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\f5\F5VpnPluginAppBg.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\f5\F5VpnPluginAppBg\CustomXMLSchema.xsd Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\juniper\msvcp120_app.dll Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\juniper\vcamp120_app.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\juniper\vcomp120_app.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\juniper\resources.pri Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\juniper\msvcr120_app.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\juniper\vccorlib120_app.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\juniper\JunosPulseVpn.exe Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\vpnplugins\juniper\JunosPulseVpnBg.dll Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\MediaViewer\WindowsInternal.Inbox.Shared.dll Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\MediaViewer\WindowsInternal.Inbox.Media.Viewer.dll Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\MediaViewer\LockScreenCamera.dll Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\MediaViewer\WindowsInternal.Inbox.Media.Viewer.winmd Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\MediaViewer\WindowsInternal.Inbox.Media.Shared.dll Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinStore\WinStoreUI.dll Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinStore\WinStore.js Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinStore\zh-CN\WinStoreUI.dll.mui Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinStore\zh-HK\WinStoreUI.dll.mui Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinStore\es-ES\WinStoreUI.dll.mui Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinStore\en-US\WinStoreUI.dll.mui Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinStore\fr-FR\WinStoreUI.dll.mui Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.IO.Compression.dll Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscordbi.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscordacwks.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Microsoft.NET\Framework\v4.0.30319\SOS.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.dll Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WindowsBase.dll Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationCore.dll Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WindowsFormsIntegration.dll Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.dll Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Program Files\Windows Defender\MpClient.dll Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Program Files\Windows Journal\zh-CN\jnwdui.dll.mui Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Program Files\Windows Journal\zh-HK\jnwdui.dll.mui Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Program Files\Common Files\microsoft shared\ink\tipskins.dll Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Program Files\Internet Explorer\MemoryAnalyzer.dll Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Program Files\Internet Explorer\F12.dll Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Program Files\Internet Explorer\F12Resources.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Program Files\Internet Explorer\ieproxy.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Program Files\Internet Explorer\IEShims.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Program Files\Internet Explorer\F12Tools.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Program Files\Internet Explorer\zh-CN\F12.dll.mui Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Program Files\Internet Explorer\zh-HK\F12.dll.mui Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Program Files\Internet Explorer\es-ES\F12.dll.mui Handle ID: 0x34 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Program Files\Internet Explorer\en-US\F12.dll.mui Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Program Files\Internet Explorer\fr-FR\F12.dll.mui Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SkyDrive.exe Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SyncEngine.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SettingSyncHost.exe Handle ID: 0x30 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SettingSyncCore.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SkyDriveTelemetry.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\MrmCoreR.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\MrmIndexer.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\iphlpsvc.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\ntoskrnl.exe Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\rdyboost.sys Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\dxgmms1.sys Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\dxgkrnl.sys Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\tcpip.sys Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\inf\errata.inf Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_a421d1bfaf856e2b.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_04445b88cf0b8e8d.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_fr-fr_379139c69a39e1d4.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_en-us_35aac4a29d13912d.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_es-es_35aac3ee9d1392b2.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_zh-hk_5d9285ec6137ee8f.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_zh-cn_5d928b9e6137e5ff.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_3296b36dbe4c7fa3.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_83386eac0379231b.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_c40c7a995ddd757b.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_bc1339ef8efa3c4c.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_3f581daba4c8c835.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_policydefinitions_89130cdfc4d9c27c.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_inputmethod_shared_6eb54fb4ad19ef1c.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migwiz_2650d8d30fee1fe9.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-hk_6a84939e4900ccf6.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_fr-fr_448347788202c03b.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_es-es_429cd1a084dc7119.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-cn_6a8499504900c466.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spp_tokens_ppdlic_0f09ba294211a24b.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_en-us_429cd25484dc6f94.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_apppatch_1143992cbbbebcab.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\explorer.exe Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\apppatch\AcGenral.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\apppatch\drvmain.sdb Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\apppatch\sysmain.sdb Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\apppatch\msimain.sdb Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\apppatch\AcSpecfc.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\dnsapi.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\TSWorkspace.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\dnsrslvr.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\mstscax.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\d2d1.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\UIAutomationCore.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\kd_02_8086.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\mfasfsrcsnk.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wuauclt.exe Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\ncryptsslp.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wucltux.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\AppXDeploymentServer.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WSService.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\iuilp.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\authui.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\samsrv.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wintrust.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\dafBth.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\AppXDeploymentExtensions.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SettingsHandlers.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\eapp3hst.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:52    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SyncEngine.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\tsmf.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\ieframe.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\dwmcore.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\msched.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\ie4uinit.exe Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\TSWbPrxy.exe Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wldp.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\AudioSes.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.Media.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.ApplicationModel.Store.TestingFramework.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wininet.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\workfolderssvc.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\ApnDatabase.xml Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WorkfoldersControl.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\dxgi.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\shell32.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\iertutil.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\win32k.sys Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WSShared.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\ieetwcollector.exe Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\comdlg32.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\ploptin.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Display.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.UI.Xaml.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\pcsvDevice.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\eappcfg.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\miutils.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\AppxAllUserStore.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\kernel32.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\profsvc.dll Handle ID: 0x44 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\psmsrv.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\eappgnui.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\twinui.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\winmde.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\ipnathlp.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\d3d9.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\apphelp.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\inetcpl.cpl Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\jscript9.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\d3d10level9.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WWAHost.exe Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.Web.Http.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\shsetup.dll Handle ID: 0x38 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\rdpclip.exe Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WiFiDisplay.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\dafWfdProvider.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WorkFoldersShell.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\mfsvr.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wuaueng.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\mshtml.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\MrmCoreR.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\eapphost.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\WUSettingsProvider.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\urlmon.dll Handle ID: 0x2c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\ftp.exe Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\wmpmde.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\AppReadiness.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\d3d11.dll Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\en-US\WorkFoldersRes.dll.mui Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\en-US\twinui.dll.mui Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\spp\tokens\ppdlic\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\spp\tokens\ppdlic\authui-ppdlic.xrm-ms Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\spp\tokens\ppdlic\explorer-ppdlic.xrm-ms Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\spp\tokens\ppdlic\WSLicensingService-ppdlic.xrm-ms Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\spp\tokens\ppdlic\WinStoreUI-ppdlic.xrm-ms Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\spp\tokens\ppdlic\iuilp-ppdlic.xrm-ms Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\zh-CN\WorkFoldersRes.dll.mui Handle ID: 0x50 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\zh-CN\twinui.dll.mui Handle ID: 0x3c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\es-ES\WorkFoldersRes.dll.mui Handle ID: 0x3c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\es-ES\twinui.dll.mui Handle ID: 0x4c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\fr-FR\WorkFoldersRes.dll.mui Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\fr-FR\twinui.dll.mui Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\zh-HK\WorkFoldersRes.dll.mui Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\zh-HK\twinui.dll.mui Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\srv.sys Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\migwiz\migstore.dll Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\InputMethod\SHARED\ChxProxyDS.DLL Handle ID: 0x3c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\PolicyDefinitions\WinStoreUI.admx Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\inf\apps.inf Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WindowsBase.dll Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WindowsFormsIntegration.dll Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationCore.dll Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.dll Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinStore\WinStoreUI.dll Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinStore\zh-CN\WinStoreUI.dll.mui Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinStore\zh-HK\WinStoreUI.dll.mui Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinStore\es-ES\WinStoreUI.dll.mui Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinStore\en-US\WinStoreUI.dll.mui Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinStore\fr-FR\WinStoreUI.dll.mui Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:53    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Program Files\Internet Explorer\F12.dll Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:54    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:54    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:54    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_3296b36dbe4c7fa3.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:54    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_83386eac0379231b.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:54    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_c40c7a995ddd757b.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:54    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_nativeimages_7f83bd6ed8241f3a.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:54    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Microsoft.NET\Framework\v4.0.30319\NativeImages\mscorlib.ni.dll Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\actxprxy.dll Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\twinui.dll Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\twinui.appcore.dll Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_3f581daba4c8c835.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.UI.Xaml.dll Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\shell32.dll Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\twinui.dll Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\inf\apps.inf Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_1e9f55b2d3f87dd3.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Camera\PhotosynthControls.dll Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Camera\StitcherRT.dll Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Camera\D3DCaptureTrackerComponent.dll Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Camera\CameraUtilities.dll Handle ID: 0x3c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\mfplat.dll Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_fr-fr_448347788202c03b.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_en-us_429cd25484dc6f94.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_es-es_429cd1a084dc7119.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-hk_6a84939e4900ccf6.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-cn_6a8499504900c466.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\crypt32.dll Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\zh-CN\crypt32.dll.mui Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\zh-HK\crypt32.dll.mui Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\es-ES\crypt32.dll.mui Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\en-US\crypt32.dll.mui Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\fr-FR\crypt32.dll.mui Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_mail_e07902f329fe05e9.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_a421d1bfaf856e2b.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_pris_3635310c72721a09.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_media_player_da4e5f6eb3198de9.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_6101456faac5015c.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_accessories_156d2b9b22040474.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_photo_viewer_6eb173d8debcda9a.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_journal_ada99bf7bc9c9733.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_d7a65bb2f0e854e7.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_818c5a0e45020fba.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_ink_3c86e3db0b3b254c.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_ink_es-es_8a1612561a0cdf91.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_msinfo_817ad0c7c1c8e490.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_b13078daf1286f60.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ado_149a784bc852a2c0.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_msadc_48cda3763ecb3874.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ole_db_48d1b11cd4e5cabe.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_f89c5a39d351281a.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_a4ba21b6f468ca9e.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_61efdd9e2d0263ca.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.0_44577d982216c291.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.5_44577da22216c264.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_defender_3e33901162166ae9.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_04445b88cf0b8e8d.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_pris_688b1d7050c30cf5.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_servicing_fc2045b9046cc796.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_branding_1728f5d8b15e5263.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_branding_basebrd_9ee9a176c9fadab4.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_3296b36dbe4c7fa3.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_83386eac0379231b.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_5588a81f3fdc44c6.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_wpf_b56a2354fbfa0c31.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_windows_communication_foundation_e07323de19ff1b52.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.5_5588a8293fdc4499.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_e9368840261e60ee.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_c40c7a995ddd757b.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_bc1339ef8efa3c4c.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_app_localresources_84df96316f150d4c.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_providers_app_localresources_7d34f2c02aed6be4.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_appconfig_app_localresources_aef413ce2370b549.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:55    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_app_localresources_4620d9e6e73b47b8.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_wizard_app_localresources_6e58d02b006cefe5.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_permissions_app_localresources_ac56057a6371bc94.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_users_app_localresources_1f849782c95d71ca.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_roles_app_localresources_8626c43b9128448f.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_app_globalresources_adb5dd0528d9b46e.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_40104b85a18bfcb2.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_resources_0adab7ac98c3dc03.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_e6d66275c6e4d14a.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_scheduled_35e98acca7dbf9c7.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_scheduled_maintenance_6bb1b174b39bb442.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_d78913b7f0741b59.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_usbcore_14d5b24ecc418e9a.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_networking_29c6b61ce45e9171.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_printer_22190c3ab8798fd9.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iebrowseweb_e2468f1fdde27cf7.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_devicecenter_0e1655bf357f4c22.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_power_9d457dc1c7c54838.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_homegroup_1909584eb21c73e3.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_search_9d4b5385ff8f1ef3.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerplaydvd_3aa04961f831b79d.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iesecurity_25644a5ef81c9ef5.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsupdate_0862ad88ff233b9d.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_performance_d48bf95b5c828123.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerconfiguration_537e287f67955d9f.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_device_9d2d754600160183.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayermedialibrary_64611465e9119df8.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_audio_9d2751b7c84ca0f1.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_aero_8b2c42561936b3f0.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_pcw_2115168e47eaddb7.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_ime_3f581be9a4c8cabd.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_3f581daba4c8c835.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_bits_0ef6f148bde367d9.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_data_0864fda87da3c851.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_d061836896f4f29d.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_oracle_07838adde9419766.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugthrsvc_9c5b081f28f83f11.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_smsvchost_4.0.0.0_13299f3c208ca635.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_0ef70686e1d9b30c.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_usbhub_299dea1039e75d30.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_tapisrv_20c65cafb424239c.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_termservice_f0fb244350031192.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_sqlserver_7cfd5f3e72497ce1.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_rdyboost_95e76b07334dd353.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_bridge_4.0.0.0_4d0c545c25fa998f.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_remoteaccess_110554180baafc8b.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugatherer_9f1f9c5b6cd50d98.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_esent_0ef70656e1d1b1ac.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_4.0.0.0_ea306c746014451b.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_windows_workflow_foundation_4.0.0.0_60d60271dbee3c46.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.netframework_266880c2626e99c6.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_wsearchidxpi_a2c41dc1731a4204.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_pnrpsvc_3932681b8fb41c9d.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_1e6ccf0e6a91b570.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_pris_a05890fcf353f1d8.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_desktoptileresources_b2a801db1c49551f.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_desktoptileresources_pris_fb9b991ef28508b5.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_policydefinitions_89130cdfc4d9c27c.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:56    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migwiz_2650d8d30fee1fe9.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_oobe_06655c95df2fa06f.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_sysprep_f7b45b8dfed1b768.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_boot_06654401df2fc50e.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migration_927a21df1acd7c18.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_e92024d8b2d5d3b6.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_schema_869341856a9aa0c1.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_schema_msft_filedirectoryconfiguration_8324e8f8bda9c0f5.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_baseregistration_f33ccae687b65dda.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_registration_fdfcf6ae03636dbf.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_registration_msft_filedirectoryconfiguration_e425053d94db5fd3.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_umdf_a531b5dc588477d3.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wcn_06656d8dd047aafe.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dism_066548addf2fbd4b.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_driverstore_a531a9c6b3dfcf87.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_a349059b05097caa.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_tls_36c96f1eb9feecc5.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_windowssearch_f5f5bf848a6aa07b.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_secureboot_9d07353d2b857be7.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_fff314eba11c101c.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_ff9b33f72ef29061.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_groupresour_f89377aef0e3070d.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_scriptresou_9439642f1597caa3.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_archivereso_76b8e47379b76aa0.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_registryres_edea8e2e2ccf59ab.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_processreso_e9b5c28bf1698a37.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_roleresourc_76a4a3ef5d2c01a4.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_servicereso_fb85110125922f37.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_packagereso_7170c4cae89762bc.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_logresource_55a4f1e43ab800fa.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_userresourc_6c89372784f42be7.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_environment_f90a921d23087c69.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_downloadmanager_dscfiledownlo_53cd0afeb4dff086.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_kds_36c95feeb9ff0384.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_appx_6a827ca1d13e479b.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitstransfer_935cce3b0456eb87.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitlocker_a73047ff15e7584f.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_trustedplatformmodule_1b07dab5874a01a0.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_msdtc_6a8283fc51a8e0dd.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_netsecurity_1f2dcf39815a9f67.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_dism_6a826ed5d13e5ce3.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_vpnclient_b543ca3d0a342edf.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_pki_36c96ea0b9feec70.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wbem_06656d9fdf2f8577.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_f1780fdbb7b569a2.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_8416c27bd490b8bd.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_es-es_429cd1a084dc7119.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_com_066545e3d047e7c7.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_systemresetplatform_14fecc2716acccef.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dsc_06654725d047e68c.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_common_8c297630658eaa3d.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_engines_sr_f5f77fb9283237d8.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_speechux_bf4b53e8d47da913.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_1e9f55b2d3f87dd3.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_pris_7badf1db07b249e7.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_reports_a2604845b2b380ca.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_rules_0bde462ce96f215e.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_0307ca33e1cd9708.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsapp_041d35a886a9ab39.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsapp_pris_5b98fa23432d61fd.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_0e66dffb08041cab.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_pris_b9b6d478276f23e5.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingshandlers_5b3af40f40f8bda7.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingshandlers_pris_71ec33a38f3576eb.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsadminflowui_704aadb27d9f6f27.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsadminflowui_pris_73f1705cccdeb65b.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_6247a388787724b8.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_pris_a8c1f2a41196ba80.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.search_ed9cc5a2b23bcffb.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.search_pris_6935df56eeeca635.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_fbee56ab048ab239.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_themes_4d0d4910e83c2273.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_themes_aero_3fd78bf4cb5fa2c4.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_apppatch_1143992cbbbebcab.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_09ec0b99a5045113.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_pris_f05e2f58ec689435.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_es-es_f05e3512c1c3dafc.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_3b206622a946e834.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_common_76cd6f1aaba6e83b.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_8a294d630e90192b.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_tts_4e06b8e5aea05fb6.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_dc4f6f92ba7f6fd4.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_indexstore_c4411e76b4b68bb5.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_contentstore_8ab00c4ac38e5298.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_fe5c6d762edd2110.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_b4e458a72482d5c6.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_common_coverpages_642a277e0ccb775c.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_virtualinbox_343012079dc9af5d.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_07deb856-fc6e-4fb9-8add-d8f2cf8722c9__0ce7c057892d5774.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:57    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_e35be42d-f742-4d96-a50a-1775fb1a7a42__96ac8d0751fb5c2c.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:58    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\msctf.dll Handle ID: 0x24 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:33:58    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Windows.Media.Streaming.dll Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_mail_e07902f329fe05e9.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_a421d1bfaf856e2b.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_pris_3635310c72721a09.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_media_player_da4e5f6eb3198de9.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_journal_ada99bf7bc9c9733.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_6101456faac5015c.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_accessories_156d2b9b22040474.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_f89c5a39d351281a.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_a4ba21b6f468ca9e.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_61efdd9e2d0263ca.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.0_44577d982216c291.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.5_44577da22216c264.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_photo_viewer_6eb173d8debcda9a.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_d7a65bb2f0e854e7.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_818c5a0e45020fba.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_ink_3c86e3db0b3b254c.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_ink_fr-fr_8bfc882e17332eb3.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_msinfo_817ad0c7c1c8e490.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_b13078daf1286f60.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ado_149a784bc852a2c0.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_msadc_48cda3763ecb3874.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ole_db_48d1b11cd4e5cabe.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_defender_3e33901162166ae9.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_04445b88cf0b8e8d.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_pris_688b1d7050c30cf5.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_servicing_fc2045b9046cc796.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_branding_1728f5d8b15e5263.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_branding_basebrd_9ee9a176c9fadab4.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_3296b36dbe4c7fa3.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_83386eac0379231b.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_5588a81f3fdc44c6.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_wpf_b56a2354fbfa0c31.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_windows_communication_foundation_e07323de19ff1b52.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.5_5588a8293fdc4499.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:14    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_e9368840261e60ee.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_c40c7a995ddd757b.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_bc1339ef8efa3c4c.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_app_localresources_84df96316f150d4c.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_providers_app_localresources_7d34f2c02aed6be4.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_appconfig_app_localresources_aef413ce2370b549.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_app_localresources_4620d9e6e73b47b8.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_wizard_app_localresources_6e58d02b006cefe5.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_permissions_app_localresources_ac56057a6371bc94.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_users_app_localresources_1f849782c95d71ca.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_roles_app_localresources_8626c43b9128448f.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_app_globalresources_adb5dd0528d9b46e.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_40104b85a18bfcb2.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_resources_0adab7ac98c3dc03.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_ime_3f581be9a4c8cabd.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_e6d66275c6e4d14a.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_scheduled_35e98acca7dbf9c7.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_scheduled_maintenance_6bb1b174b39bb442.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_d78913b7f0741b59.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_usbcore_14d5b24ecc418e9a.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_networking_29c6b61ce45e9171.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iebrowseweb_e2468f1fdde27cf7.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_printer_22190c3ab8798fd9.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_homegroup_1909584eb21c73e3.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_devicecenter_0e1655bf357f4c22.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_power_9d457dc1c7c54838.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_search_9d4b5385ff8f1ef3.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerplaydvd_3aa04961f831b79d.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iesecurity_25644a5ef81c9ef5.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsupdate_0862ad88ff233b9d.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_performance_d48bf95b5c828123.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_audio_9d2751b7c84ca0f1.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_aero_8b2c42561936b3f0.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_pcw_2115168e47eaddb7.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerconfiguration_537e287f67955d9f.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_device_9d2d754600160183.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayermedialibrary_64611465e9119df8.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_3f581daba4c8c835.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_bits_0ef6f148bde367d9.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_d061836896f4f29d.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_data_0864fda87da3c851.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugthrsvc_9c5b081f28f83f11.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_oracle_07838adde9419766.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_smsvchost_4.0.0.0_13299f3c208ca635.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_tapisrv_20c65cafb424239c.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_0ef70686e1d9b30c.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_usbhub_299dea1039e75d30.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_rdyboost_95e76b07334dd353.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_termservice_f0fb244350031192.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_sqlserver_7cfd5f3e72497ce1.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_remoteaccess_110554180baafc8b.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugatherer_9f1f9c5b6cd50d98.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_bridge_4.0.0.0_4d0c545c25fa998f.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_wsearchidxpi_a2c41dc1731a4204.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_pnrpsvc_3932681b8fb41c9d.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_esent_0ef70656e1d1b1ac.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_4.0.0.0_ea306c746014451b.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.netframework_266880c2626e99c6.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_windows_workflow_foundation_4.0.0.0_60d60271dbee3c46.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_desktoptileresources_b2a801db1c49551f.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_desktoptileresources_pris_fb9b991ef28508b5.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_policydefinitions_89130cdfc4d9c27c.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_1e6ccf0e6a91b570.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_pris_a05890fcf353f1d8.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_oobe_06655c95df2fa06f.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migwiz_2650d8d30fee1fe9.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_fr-fr_448347788202c03b.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_boot_06654401df2fc50e.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_sysprep_f7b45b8dfed1b768.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migration_927a21df1acd7c18.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_e92024d8b2d5d3b6.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_schema_869341856a9aa0c1.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_schema_msft_filedirectoryconfiguration_8324e8f8bda9c0f5.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_baseregistration_f33ccae687b65dda.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_registration_fdfcf6ae03636dbf.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_registration_msft_filedirectoryconfiguration_e425053d94db5fd3.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms Handle ID: 0x40 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_umdf_a531b5dc588477d3.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wcn_06656d8dd047aafe.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dism_066548addf2fbd4b.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_driverstore_a531a9c6b3dfcf87.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_f1780fdbb7b569a2.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_8416c27bd490b8bd.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wbem_06656d9fdf2f8577.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_a349059b05097caa.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_tls_36c96f1eb9feecc5.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_windowssearch_f5f5bf848a6aa07b.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_secureboot_9d07353d2b857be7.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_fff314eba11c101c.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_ff9b33f72ef29061.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_groupresour_f89377aef0e3070d.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_scriptresou_9439642f1597caa3.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_archivereso_76b8e47379b76aa0.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_registryres_edea8e2e2ccf59ab.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_processreso_e9b5c28bf1698a37.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_roleresourc_76a4a3ef5d2c01a4.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_servicereso_fb85110125922f37.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_packagereso_7170c4cae89762bc.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_logresource_55a4f1e43ab800fa.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_userresourc_6c89372784f42be7.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_environment_f90a921d23087c69.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_downloadmanager_dscfiledownlo_53cd0afeb4dff086.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_kds_36c95feeb9ff0384.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_appx_6a827ca1d13e479b.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitstransfer_935cce3b0456eb87.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitlocker_a73047ff15e7584f.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_netsecurity_1f2dcf39815a9f67.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_trustedplatformmodule_1b07dab5874a01a0.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:15    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_msdtc_6a8283fc51a8e0dd.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_dism_6a826ed5d13e5ce3.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_vpnclient_b543ca3d0a342edf.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_pki_36c96ea0b9feec70.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_systemresetplatform_14fecc2716acccef.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dsc_06654725d047e68c.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_common_8c297630658eaa3d.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_engines_sr_f5f77fb9283237d8.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_speechux_bf4b53e8d47da913.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_com_066545e3d047e7c7.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_1e9f55b2d3f87dd3.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_pris_7badf1db07b249e7.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_reports_a2604845b2b380ca.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_rules_0bde462ce96f215e.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_0307ca33e1cd9708.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsapp_041d35a886a9ab39.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsapp_pris_5b98fa23432d61fd.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingshandlers_5b3af40f40f8bda7.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingshandlers_pris_71ec33a38f3576eb.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_0e66dffb08041cab.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_pris_b9b6d478276f23e5.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsadminflowui_704aadb27d9f6f27.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsadminflowui_pris_73f1705cccdeb65b.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.search_ed9cc5a2b23bcffb.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.search_pris_6935df56eeeca635.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_6247a388787724b8.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_pris_a8c1f2a41196ba80.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_09ec0b99a5045113.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_fr-fr_f05e332ec1c4de0a.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_pris_f05e2f58ec689435.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_fbee56ab048ab239.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_themes_4d0d4910e83c2273.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_themes_aero_3fd78bf4cb5fa2c4.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_apppatch_1143992cbbbebcab.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_3b206622a946e834.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_common_76cd6f1aaba6e83b.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_8a294d630e90192b.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_tts_4e06b8e5aea05fb6.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_dc4f6f92ba7f6fd4.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_indexstore_c4411e76b4b68bb5.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_contentstore_8ab00c4ac38e5298.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_fe5c6d762edd2110.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_b4e458a72482d5c6.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_common_coverpages_642a277e0ccb775c.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_virtualinbox_343012079dc9af5d.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_07deb856-fc6e-4fb9-8add-d8f2cf8722c9__0ce7c057892d5774.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_e35be42d-f742-4d96-a50a-1775fb1a7a42__96ac8d0751fb5c2c.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_mail_e07902f329fe05e9.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_a421d1bfaf856e2b.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_pris_3635310c72721a09.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_media_player_da4e5f6eb3198de9.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_journal_ada99bf7bc9c9733.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_6101456faac5015c.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_tabletextservice_9475b2de2d92bc74.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_accessories_156d2b9b22040474.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_photo_viewer_6eb173d8debcda9a.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_f89c5a39d351281a.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_a4ba21b6f468ca9e.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_61efdd9e2d0263ca.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.0_44577d982216c291.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.5_44577da22216c264.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_d7a65bb2f0e854e7.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_818c5a0e45020fba.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_ink_3c86e3db0b3b254c.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_ink_zh-hk_b1fdd453de313b6e.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_msinfo_817ad0c7c1c8e490.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_b13078daf1286f60.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_msadc_48cda3763ecb3874.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ado_149a784bc852a2c0.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ole_db_48d1b11cd4e5cabe.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_defender_3e33901162166ae9.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_04445b88cf0b8e8d.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_pris_688b1d7050c30cf5.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_servicing_fc2045b9046cc796.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_branding_1728f5d8b15e5263.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_branding_basebrd_9ee9a176c9fadab4.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_3296b36dbe4c7fa3.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_83386eac0379231b.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_5588a81f3fdc44c6.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_wpf_b56a2354fbfa0c31.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_windows_communication_foundation_e07323de19ff1b52.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.5_5588a8293fdc4499.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_e9368840261e60ee.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_c40c7a995ddd757b.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_bc1339ef8efa3c4c.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_app_localresources_84df96316f150d4c.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_providers_app_localresources_7d34f2c02aed6be4.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_appconfig_app_localresources_aef413ce2370b549.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_app_localresources_4620d9e6e73b47b8.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_wizard_app_localresources_6e58d02b006cefe5.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_permissions_app_localresources_ac56057a6371bc94.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_users_app_localresources_1f849782c95d71ca.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_roles_app_localresources_8626c43b9128448f.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_app_globalresources_adb5dd0528d9b46e.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_40104b85a18bfcb2.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_resources_0adab7ac98c3dc03.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_ime_3f581be9a4c8cabd.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_e6d66275c6e4d14a.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_scheduled_35e98acca7dbf9c7.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_scheduled_maintenance_6bb1b174b39bb442.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_d78913b7f0741b59.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_usbcore_14d5b24ecc418e9a.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_networking_29c6b61ce45e9171.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iebrowseweb_e2468f1fdde27cf7.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_printer_22190c3ab8798fd9.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_homegroup_1909584eb21c73e3.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_devicecenter_0e1655bf357f4c22.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_power_9d457dc1c7c54838.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_search_9d4b5385ff8f1ef3.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerplaydvd_3aa04961f831b79d.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iesecurity_25644a5ef81c9ef5.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsupdate_0862ad88ff233b9d.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_performance_d48bf95b5c828123.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_audio_9d2751b7c84ca0f1.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_aero_8b2c42561936b3f0.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_pcw_2115168e47eaddb7.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerconfiguration_537e287f67955d9f.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:31    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayermedialibrary_64611465e9119df8.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_device_9d2d754600160183.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_3f581daba4c8c835.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_data_0864fda87da3c851.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_d061836896f4f29d.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_bits_0ef6f148bde367d9.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugthrsvc_9c5b081f28f83f11.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_oracle_07838adde9419766.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_smsvchost_4.0.0.0_13299f3c208ca635.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_tapisrv_20c65cafb424239c.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_0ef70686e1d9b30c.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_usbhub_299dea1039e75d30.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_sqlserver_7cfd5f3e72497ce1.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_rdyboost_95e76b07334dd353.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_termservice_f0fb244350031192.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_remoteaccess_110554180baafc8b.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugatherer_9f1f9c5b6cd50d98.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_bridge_4.0.0.0_4d0c545c25fa998f.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_wsearchidxpi_a2c41dc1731a4204.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_pnrpsvc_3932681b8fb41c9d.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_4.0.0.0_ea306c746014451b.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_windows_workflow_foundation_4.0.0.0_60d60271dbee3c46.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.netframework_266880c2626e99c6.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_esent_0ef70656e1d1b1ac.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_1e6ccf0e6a91b570.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_pris_a05890fcf353f1d8.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_desktoptileresources_b2a801db1c49551f.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_desktoptileresources_pris_fb9b991ef28508b5.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_policydefinitions_89130cdfc4d9c27c.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migwiz_2650d8d30fee1fe9.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_oobe_06655c95df2fa06f.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_boot_06654401df2fc50e.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_sysprep_f7b45b8dfed1b768.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-tw_6a84aa664900aad6.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migration_927a21df1acd7c18.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_e92024d8b2d5d3b6.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_schema_869341856a9aa0c1.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_schema_msft_filedirectoryconfiguration_8324e8f8bda9c0f5.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_baseregistration_f33ccae687b65dda.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_registration_fdfcf6ae03636dbf.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_registration_msft_filedirectoryconfiguration_e425053d94db5fd3.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_umdf_a531b5dc588477d3.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wcn_06656d8dd047aafe.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dism_066548addf2fbd4b.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_driverstore_a531a9c6b3dfcf87.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_f1780fdbb7b569a2.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_8416c27bd490b8bd.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_a349059b05097caa.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_tls_36c96f1eb9feecc5.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_windowssearch_f5f5bf848a6aa07b.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_secureboot_9d07353d2b857be7.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_fff314eba11c101c.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_ff9b33f72ef29061.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_groupresour_f89377aef0e3070d.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_scriptresou_9439642f1597caa3.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_archivereso_76b8e47379b76aa0.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_registryres_edea8e2e2ccf59ab.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_processreso_e9b5c28bf1698a37.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_roleresourc_76a4a3ef5d2c01a4.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_servicereso_fb85110125922f37.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_packagereso_7170c4cae89762bc.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_logresource_55a4f1e43ab800fa.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_userresourc_6c89372784f42be7.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_environment_f90a921d23087c69.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_downloadmanager_dscfiledownlo_53cd0afeb4dff086.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_kds_36c95feeb9ff0384.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_appx_6a827ca1d13e479b.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitlocker_a73047ff15e7584f.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitstransfer_935cce3b0456eb87.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_trustedplatformmodule_1b07dab5874a01a0.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_msdtc_6a8283fc51a8e0dd.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_netsecurity_1f2dcf39815a9f67.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_dism_6a826ed5d13e5ce3.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_vpnclient_b543ca3d0a342edf.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_pki_36c96ea0b9feec70.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wbem_06656d9fdf2f8577.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_systemresetplatform_14fecc2716acccef.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dsc_06654725d047e68c.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_com_066545e3d047e7c7.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_common_8c297630658eaa3d.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_engines_sr_f5f77fb9283237d8.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_speechux_bf4b53e8d47da913.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-hk_6a84939e4900ccf6.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_1e9f55b2d3f87dd3.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_pris_7badf1db07b249e7.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_reports_a2604845b2b380ca.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_rules_0bde462ce96f215e.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_0307ca33e1cd9708.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsapp_041d35a886a9ab39.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsapp_pris_5b98fa23432d61fd.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingshandlers_5b3af40f40f8bda7.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingshandlers_pris_71ec33a38f3576eb.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_0e66dffb08041cab.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_pris_b9b6d478276f23e5.cdf-ms Handle ID: 0x7c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsadminflowui_704aadb27d9f6f27.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsadminflowui_pris_73f1705cccdeb65b.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.search_ed9cc5a2b23bcffb.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.search_pris_6935df56eeeca635.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_6247a388787724b8.cdf-ms Handle ID: 0x8c Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_pris_a8c1f2a41196ba80.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_09ec0b99a5045113.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_pris_f05e2f58ec689435.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_zh-hk_f05e2036c1d8ff57.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_fbee56ab048ab239.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_themes_4d0d4910e83c2273.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_themes_aero_3fd78bf4cb5fa2c4.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_apppatch_1143992cbbbebcab.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:32    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_dc4f6f92ba7f6fd4.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_indexstore_c4411e76b4b68bb5.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_contentstore_8ab00c4ac38e5298.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_3b206622a946e834.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_common_76cd6f1aaba6e83b.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_8a294d630e90192b.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_tts_4e06b8e5aea05fb6.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_fe5c6d762edd2110.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_b4e458a72482d5c6.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_common_coverpages_642a277e0ccb775c.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_virtualinbox_343012079dc9af5d.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_07deb856-fc6e-4fb9-8add-d8f2cf8722c9__0ce7c057892d5774.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_e35be42d-f742-4d96-a50a-1775fb1a7a42__96ac8d0751fb5c2c.cdf-ms Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\BFE.DLL Handle ID: 0xdc Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\IKEEXT.DLL Handle ID: 0xdc Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\wfplwfs.sys Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\spp\tokens\ppdlic\NetworkSecurity-ppdlic.xrm-ms Handle ID: 0xdc Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\inf\wfplwfs.inf Handle ID: 0xd0 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0xd0 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x78 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_3f581daba4c8c835.cdf-ms Handle ID: 0x78 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x78 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spp_tokens_ppdlic_0f09ba294211a24b.cdf-ms Handle ID: 0x78 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms Handle ID: 0xe0 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0xc8 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0xc8 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0xc8 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\gdi32.dll Handle ID: 0xc8 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\dxgmms1.sys Handle ID: 0xc8 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Drivers\dxgkrnl.sys Handle ID: 0x80 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0xc8 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0xc8 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0xc8 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms Handle ID: 0xc8 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\dwmcore.dll Handle ID: 0xc8 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SettingsHandlers.dll Handle ID: 0xc8 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\dxgi.dll Handle ID: 0xc8 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Display.dll Handle ID: 0xc8 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\win32k.sys Handle ID: 0xc8 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-28 17:34:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\d3d11.dll Handle ID: 0xc8 Process Information: Process ID: 0x458 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  101  2013-11-28 17:35:45    Microsoft-Windows-Eventlog  1101: Audit events have been dropped by the transport. 0
Security  Audit Success  12544  2013-11-28 17:35:45    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 17:35:45    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:35:45    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 17:35:45    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12292  2013-11-28 17:35:49    Microsoft-Windows-Security-Auditing  5033: The Windows Firewall Driver started successfully.
Security  Audit Success  12544  2013-11-28 17:35:49    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:35:49    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 17:35:50    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:35:50    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 17:35:54    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Type: 3 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-7 Account Name: ANONYMOUS LOGON Account Domain: NT AUTHORITY Logon ID: 0x6d60c Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x0 Process Name: - Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: NtLmSsp Authentication Package: NTLM Transited Services: - Package Name (NTLM only): NTLM V1 Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  103  2013-11-28 17:35:55    Microsoft-Windows-Eventlog  1100: The event logging service has shut down.
Security  Audit Success  12288  2013-11-28 17:36:32    Microsoft-Windows-Security-Auditing  4608: Windows is starting up. This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Security  Audit Success  12544  2013-11-28 17:36:32    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Type: 0 Impersonation Level: - New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x4 Process Name: Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: - Authentication Package: - Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 17:36:32    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x294 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 17:36:32    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-20 Account Name: NETWORK SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e4 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x294 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:36:32    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 17:36:32    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-20 Account Name: NETWORK SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e4 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
Security  Audit Success  13568  2013-11-28 17:36:32    Microsoft-Windows-Security-Auditing  4902: The Per-user audit policy table was created. Number of Elements: 0 Policy ID: 0x9512
Security  Audit Success  12544  2013-11-28 17:36:33    Microsoft-Windows-Security-Auditing  4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: DWM-1 Account Domain: Window Manager Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x26c Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: - Port: - This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Security  Audit Success  12544  2013-11-28 17:36:33    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 2 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xf5fc Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x26c Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 17:36:33    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 2 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xf619 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x26c Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 17:36:33    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x294 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 17:36:33    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x294 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 17:36:33    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x294 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 17:36:33    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x294 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:36:33    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xf5fc Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 17:36:33    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xf619 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege
Security  Audit Success  12548  2013-11-28 17:36:33    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 17:36:33    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 17:36:33    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 17:36:33    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12292  2013-11-28 17:36:36    Microsoft-Windows-Security-Auditing  5033: The Windows Firewall Driver started successfully.
Security  Audit Success  12544  2013-11-28 17:36:36    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x294 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:36:36    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12292  2013-11-28 17:36:37    Microsoft-Windows-Security-Auditing  5024: The Windows Firewall service started successfully.
Security  Audit Success  12544  2013-11-28 17:36:37    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x294 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 17:36:37    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Type: 3 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-7 Account Name: ANONYMOUS LOGON Account Domain: NT AUTHORITY Logon ID: 0x1a303 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x0 Process Name: - Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: NtLmSsp Authentication Package: NTLM Transited Services: - Package Name (NTLM only): NTLM V1 Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:36:37    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 17:37:41    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x294 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:37:41    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 17:38:42    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x294 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 17:38:42    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  13568  2013-11-28 18:06:07    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:07    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:07    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:07    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_3f581daba4c8c835.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spp_tokens_ppdlic_0f09ba294211a24b.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_mail_e07902f329fe05e9.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_mail_zh-hk_4eece70683cfc441.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_a421d1bfaf856e2b.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_pris_3635310c72721a09.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_zh-hk_4e3889894e6d1583.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_media_player_da4e5f6eb3198de9.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_media_player_zh-hk_94ff8c163fdb2e7b.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_journal_ada99bf7bc9c9733.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_journal_zh-hk_ff8b94f2baf35197.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_6101456faac5015c.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_tabletextservice_9475b2de2d92bc74.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_tabletextservice_zh-hk_0e70b9f84a7dc2f2.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_accessories_156d2b9b22040474.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_accessories_zh-hk_4a05aaecc8edc89e.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_photo_viewer_6eb173d8debcda9a.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_photo_viewer_zh-hk_bb1887f68d57578a.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_f89c5a39d351281a.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_a4ba21b6f468ca9e.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_61efdd9e2d0263ca.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.0_44577d982216c291.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.0_zh-cht_732c8e4d5c172933.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.5_44577da22216c264.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.5_zh-cht_733690c35bea1e20.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_d7a65bb2f0e854e7.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_818c5a0e45020fba.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_ink_3c86e3db0b3b254c.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_ink_zh-hk_b1fdd453de313b6e.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_msinfo_817ad0c7c1c8e490.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_msinfo_zh-hk_983185f6bba7d2b6.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_b13078daf1286f60.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_msadc_48cda3763ecb3874.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_msadc_zh-hk_80a2c4996a8fb52e.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ado_149a784bc852a2c0.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ado_zh-hk_9c3c74b4c078db64.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ole_db_48d1b11cd4e5cabe.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ole_db_zh-hk_5d025ecc038715be.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_zh-hk_48e783643e56558e.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_defender_3e33901162166ae9.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_defender_zh-hk_a607efd30bb51643.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_04445b88cf0b8e8d.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_pris_688b1d7050c30cf5.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_zh-hk_5d9285ec6137ee8f.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_servicing_fc2045b9046cc796.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_servicing_zh-hk_5f9eccd2735eee76.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_branding_1728f5d8b15e5263.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_branding_basebrd_9ee9a176c9fadab4.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_branding_basebrd_zh-hk_79a82467076c50b2.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_3296b36dbe4c7fa3.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_83386eac0379231b.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_5588a81f3fdc44c6.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_wpf_b56a2354fbfa0c31.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_wpf_zh-cht_a48160d888293201.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_wpf_zh-tw_49f1037553ee19b7.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_windows_communication_foundation_e07323de19ff1b52.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_windows_communication_foundation_zh-tw_fc3cba02619ed180.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_windows_communication_foundation_zh-cht_1b3a923bd6282868.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.5_5588a8293fdc4499.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.5_1028_b573e1fe73d26174.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.5_zh-cht_3f78403d8c5aab8f.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_e9368840261e60ee.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_1028_7994e8760abd58a3.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_gac_zh-cht_1f100d0995fa2ca5.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_zh-cht_9a3b1609bfa75284.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_mui_0404_fbbb4574c63bd0d7.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_c40c7a995ddd757b.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_1028_46978c13d7506756.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_zh-tw_63553d5155faa481.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_bc1339ef8efa3c4c.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_zh-tw_dc89dba795adcbbe.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_zh-hant_89302213fd03e710.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_app_localresources_84df96316f150d4c.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_providers_app_localresources_7d34f2c02aed6be4.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_appconfig_app_localresources_aef413ce2370b549.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_app_localresources_4620d9e6e73b47b8.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_wizard_app_localresources_6e58d02b006cefe5.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_permissions_app_localresources_ac56057a6371bc94.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_users_app_localresources_1f849782c95d71ca.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_roles_app_localresources_8626c43b9128448f.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_app_globalresources_adb5dd0528d9b46e.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_sql_zh-hant_21283f67a55f3e9f.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_zh-hant_54e293f4b2ff78bf.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_40104b85a18bfcb2.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_resources_0adab7ac98c3dc03.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_resources_zh-hk_33be01a245911ab3.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_ime_3f581be9a4c8cabd.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_ime_zh-hk_0d34860ae46f6e37.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_e6d66275c6e4d14a.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_scheduled_35e98acca7dbf9c7.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:08    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_scheduled_maintenance_6bb1b174b39bb442.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_scheduled_maintenance_zh-hk_190bae855e44559c.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_d78913b7f0741b59.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_usbcore_14d5b24ecc418e9a.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_usbcore_zh-hk_0cad7e3d1f21e130.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_networking_29c6b61ce45e9171.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_networking_zh-hk_9ac3928029f05911.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iebrowseweb_e2468f1fdde27cf7.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iebrowseweb_zh-hk_ecfaa5791b581c51.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_printer_22190c3ab8798fd9.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_printer_zh-hk_21441157f6fb93b3.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_homegroup_1909584eb21c73e3.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_homegroup_zh-hk_cb721ad79a1714ed.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_devicecenter_0e1655bf357f4c22.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_devicecenter_zh-hk_63ad568634fe2682.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_power_9d457dc1c7c54838.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_power_zh-hk_9a014b20391c1a66.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_search_9d4b5385ff8f1ef3.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_search_zh-hk_082f69798beb7e57.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerplaydvd_3aa04961f831b79d.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerplaydvd_zh-hk_3fbedab18f1ac779.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iesecurity_25644a5ef81c9ef5.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iesecurity_zh-hk_ba4418a23f683e61.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsupdate_0862ad88ff233b9d.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsupdate_zh-hk_95a7804e28a0a155.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_performance_d48bf95b5c828123.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_performance_zh-hk_0e43329cc4f3edd9.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_audio_9d2751b7c84ca0f1.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_audio_zh-hk_c79a1a21247ad36f.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_aero_8b2c42561936b3f0.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_aero_zh-hk_1a667f4720b953d2.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_pcw_2115168e47eaddb7.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_pcw_zh-hk_30d3fb3678b90fdd.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerconfiguration_537e287f67955d9f.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerconfiguration_zh-hk_b581c4a157ec086f.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayermedialibrary_64611465e9119df8.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayermedialibrary_zh-hk_8d139e52e743fc80.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_device_9d2d754600160183.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_device_zh-hk_3aa3505ef4e35efb.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_3f581daba4c8c835.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_data_0864fda87da3c851.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_data_0404_9334e8c1f02772e9.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_d061836896f4f29d.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_0404_417ab29a909264dd.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_bits_0ef6f148bde367d9.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_bits_0c04_a03dbcd163e839c4.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_windows_workflow_foundation_3.0.0.0_0404_c87be953a75f6cf3.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_servicemodeloperation_3.0.0.0_0404_9b92c33ad51f654b.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_smsvchost_3.0.0.0_0404_2d6d98135cb60bf8.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugthrsvc_9c5b081f28f83f11.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugthrsvc_0c04_8451c054df70c466.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_oracle_07838adde9419766.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_oracle_0404_1ac87c28f00b1f68.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_smsvchost_4.0.0.0_13299f3c208ca635.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_smsvchost_4.0.0.0_0404_1bb369ef8498f3c9.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_tapisrv_20c65cafb424239c.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_tapisrv_0c04_2e99ba041b85fbff.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_0ef70686e1d9b30c.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_0c04_5b1b89734f36bc1f.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_usbhub_299dea1039e75d30.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_usbhub_0c04_1bec332b3c8baa4b.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_sqlserver_7cfd5f3e72497ce1.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_sqlserver_0404_22ef188981b08c73.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_rdyboost_95e76b07334dd353.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_rdyboost_0c04_50c617717330cf24.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_termservice_f0fb244350031192.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_termservice_0c04_f96d80ff6bc73989.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_remoteaccess_110554180baafc8b.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_remoteaccess_0c04_86bc957ee65d6350.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugatherer_9f1f9c5b6cd50d98.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugatherer_0c04_046b59c1f9ca3305.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_bridge_4.0.0.0_4d0c545c25fa998f.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_bridge_4.0.0.0_0404_4cb1a6e2183b9d4d.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_bridge_3.0.0.0_0404_5d6037fd7f35c3a6.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_servicemodelservice_3.0.0.0_0404_2fd4df9498bb9be1.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_wsearchidxpi_a2c41dc1731a4204.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_wsearchidxpi_0c04_2e6e3c70af9fd027.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_pnrpsvc_3932681b8fb41c9d.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_pnrpsvc_0c04_43735f21fe2e8200.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_4.0.0.0_ea306c746014451b.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_4.0.0.0_0404_fb64b03a4648bc63.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_windows_workflow_foundation_4.0.0.0_60d60271dbee3c46.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_windows_workflow_foundation_4.0.0.0_0404_c87be953a7dd7c74.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.netframework_266880c2626e99c6.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.netframework_0404_fd6b67034927276c.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_esent_0ef70656e1d1b1ac.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_esent_0c04_5aeb7da34bde657f.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_servicemodelendpoint_3.0.0.0_0404_1441b5536e0ddf4f.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_1e6ccf0e6a91b570.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_pris_a05890fcf353f1d8.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_zh-hk_80cdd4487a4c0a76.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_desktoptileresources_b2a801db1c49551f.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_desktoptileresources_pris_fb9b991ef28508b5.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_policydefinitions_89130cdfc4d9c27c.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_policydefinitions_zh-hk_382789f3944799fc.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_winrm_0c04_a9926349fab42aba.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migwiz_2650d8d30fee1fe9.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migwiz_zh-hk_b32d84f452e8f721.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_oobe_06655c95df2fa06f.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_oobe_zh-hk_e15b0fa7f6d1fae3.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_slmgr_0c04_c09c72d00002fa10.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_boot_06654401df2fc50e.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_boot_zh-hk_ba527472311fd44e.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_sysprep_f7b45b8dfed1b768.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_sysprep_zh-hk_15683b7a6b76d1fc.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-tw_6a84aa664900aad6.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migration_927a21df1acd7c18.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migration_zh-hk_81871cae894ade44.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_e92024d8b2d5d3b6.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_schema_869341856a9aa0c1.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_schema_msft_filedirectoryconfiguration_8324e8f8bda9c0f5.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_schema_msft_filedirectoryconfiguration_zh-hk_61b57b1743406d7b.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_baseregistration_f33ccae687b65dda.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_baseregistration_zh-hk_3a6155165575d222.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_registration_fdfcf6ae03636dbf.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_registration_msft_filedirectoryconfiguration_e425053d94db5fd3.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_registration_msft_filedirectoryconfiguration_zh-hk_f35d49edb3788cc1.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_xpsviewer_zh-tw_46a0216fb6655d99.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_umdf_a531b5dc588477d3.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_umdf_zh-hk_b5c5cdb585c2fe81.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_zh-hk_73a0d54622ddc931.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_mui_0404_ecc96e0e9498d629.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wcn_06656d8dd047aafe.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wcn_zh-hk_1c105936cba9f89e.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dism_066548addf2fbd4b.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dism_zh-hk_035a690a73af0e21.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_driverstore_a531a9c6b3dfcf87.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_driverstore_zh-hk_1e9c6c389e3900d3.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_printing_admin_scripts_zh-hk_f24294c37393cfc0.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_f1780fdbb7b569a2.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_8416c27bd490b8bd.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_mui_0c04_b123df58e96d4b03.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_zh-hk_cc275bfb06f6760f.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:09    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_zh-hk_028e5dcbcad565cb.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_a349059b05097caa.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_tls_36c96f1eb9feecc5.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_tls_zh-hk_ad27cd45156108a5.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_windowssearch_f5f5bf848a6aa07b.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_windowssearch_zh-hk_4ec9dc0a60e59bef.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_secureboot_9d07353d2b857be7.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_secureboot_zh-hk_98dde131bf1dbded.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_fff314eba11c101c.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_ff9b33f72ef29061.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_groupresour_f89377aef0e3070d.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_groupresour_ef627ecf0237b69d.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_scriptresou_9439642f1597caa3.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_scriptresou_8100c354c310e149.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_archivereso_76b8e47379b76aa0.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_archivereso_8ec97bf18e95b644.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_registryres_edea8e2e2ccf59ab.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_registryres_6f283f1a680ef6af.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_processreso_e9b5c28bf1698a37.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_processreso_294b1c52933f96e1.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_roleresourc_76a4a3ef5d2c01a4.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_roleresourc_0d897a5139b8f010.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_servicereso_fb85110125922f37.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_servicereso_e6bbb94507d2714d.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_packagereso_7170c4cae89762bc.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_packagereso_921b3ba6b9f40484.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_logresource_55a4f1e43ab800fa.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_logresource_9f00d76d2c8b52b6.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_userresourc_6c89372784f42be7.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_userresourc_c86826a57b5c5deb.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_environment_f90a921d23087c69.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_environment_820855282145a817.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_downloadmanager_dscfiledownlo_53cd0afeb4dff086.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_downloadmanager_dscfiledownlo_8c3e000c914e7f7c.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_zh-hk_204f00ed9b5dd45e.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_kds_36c95feeb9ff0384.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_kds_zh-hk_9df4107527c01854.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_appx_6a827ca1d13e479b.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_appx_zh-hk_0ba044cd7e1a2335.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitlocker_a73047ff15e7584f.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitlocker_zh-hk_8728eab4cdd6ef79.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitstransfer_935cce3b0456eb87.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitstransfer_zh-hk_b755146c9cfade3f.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_trustedplatformmodule_1b07dab5874a01a0.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_trustedplatformmodule_zh-hk_e52c56182d9c8600.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_msdtc_6a8283fc51a8e0dd.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_msdtc_zh-hk_80142f4f1b47f3db.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_netsecurity_1f2dcf39815a9f67.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_netsecurity_zh-hk_7867facf6b95d451.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_dism_6a826ed5d13e5ce3.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_dism_zh-hk_7fe41c8f51c1b251.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_vpnclient_b543ca3d0a342edf.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_vpnclient_zh-hk_11f5b0d377ff355b.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_pki_36c96ea0b9feec70.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_pki_zh-hk_aca9ae431317b6b2.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wbem_06656d9fdf2f8577.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wbem_zh-hk_4260e018b867fdd1.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_systemresetplatform_14fecc2716acccef.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_systemresetplatform_zh-hk_726da8de3e282bb1.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dsc_06654725d047e68c.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dsc_zh-hk_56ae8b1575af2886.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_com_066545e3d047e7c7.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_com_zh-hk_6801448cdb0ae8fd.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_common_8c297630658eaa3d.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_common_zh-hk_fdcee4505fd29623.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_engines_sr_f5f77fb9283237d8.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_engines_sr_zh-hk_5031a81c07c93706.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_speechux_bf4b53e8d47da913.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_speechux_zh-tw_acdfb33e1d5e3f39.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_speechux_zh-hk_acdf9c761d5e6159.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-hk_6a84939e4900ccf6.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-hk_licenses_oem_core_08654752b8b13a5a.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-hk_licenses_default_core_ef91e866e7b4c5e1.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-hk_licenses_volume_core_957016b01eea0c49.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_1e9f55b2d3f87dd3.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_pris_7badf1db07b249e7.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_reports_a2604845b2b380ca.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_reports_zh-hk_04eb75a49a8df662.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_rules_0bde462ce96f215e.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_rules_zh-hk_89ddd61c578cfbf0.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_0307ca33e1cd9708.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsapp_041d35a886a9ab39.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsapp_pris_5b98fa23432d61fd.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingshandlers_5b3af40f40f8bda7.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingshandlers_pris_71ec33a38f3576eb.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_0e66dffb08041cab.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_pris_b9b6d478276f23e5.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsadminflowui_704aadb27d9f6f27.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsadminflowui_pris_73f1705cccdeb65b.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.search_ed9cc5a2b23bcffb.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.search_pris_6935df56eeeca635.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_6247a388787724b8.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_pris_a8c1f2a41196ba80.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_09ec0b99a5045113.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_pris_f05e2f58ec689435.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_zh-hk_f05e2036c1d8ff57.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_fbee56ab048ab239.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_themes_4d0d4910e83c2273.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_themes_aero_3fd78bf4cb5fa2c4.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_themes_aero_zh-hk_a821b4d926eada48.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_zh-hk_401042eba1e61c7a.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_apppatch_1143992cbbbebcab.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_apppatch_zh-hk_317589bc3c3f491b.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_dc4f6f92ba7f6fd4.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_indexstore_c4411e76b4b68bb5.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_indexstore_zh-hk_77ae8e518b2b0d6f.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_contentstore_8ab00c4ac38e5298.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_contentstore_zh-hk_58eae9487dab5fd4.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_mui_0c04_c7941e78fabeab0b.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_zh-hk_cc1e1e34c69a3c11.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_3b206622a946e834.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_common_76cd6f1aaba6e83b.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_common_zh-hk_0ef6fab94336f271.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_8a294d630e90192b.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_tts_4e06b8e5aea05fb6.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_tts_zh-tw_5bfddddd55acbff8.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_tts_zh-hk_5bfddf7555acbc98.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_sr_zh-tw_2f0d0f29d3d803be.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_lexicon_zh-tw_bd9bdfcdf59bb22d.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_fe5c6d762edd2110.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_b4e458a72482d5c6.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_common_coverpages_642a277e0ccb775c.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_common_coverpages_zh-hk_ebd1643f8aa18b52.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_virtualinbox_343012079dc9af5d.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_virtualinbox_zh-hk_c4461e06bd0d3ce7.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_07deb856-fc6e-4fb9-8add-d8f2cf8722c9__0ce7c057892d5774.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_07deb856-fc6e-4fb9-8add-d8f2cf8722c9_zh-hk_66e92e5145182f72.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:10    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_e35be42d-f742-4d96-a50a-1775fb1a7a42__96ac8d0751fb5c2c.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:11    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_e35be42d-f742-4d96-a50a-1775fb1a7a42_zh-hk_98bc0ccb03db4eac.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:11    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Speech\Engines\Lexicon\zh-TW Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:11    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Speech\Engines\SR\zh-TW Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:13    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Speech\SpeechUX\zh-HK Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:13    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Speech\SpeechUX\zh-TW Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:13    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SystemResetPlatform\zh-HK Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\ImmersiveControlPanel\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\inf\TAPISRV\0C04 Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Device\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\WindowsMediaPlayerMediaLibrary\zh-HK Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\WindowsMediaPlayerConfiguration\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\PCW\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\AERO\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Audio\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Performance\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\WindowsUpdate\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\IESecurity\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\WindowsMediaPlayerPlayDVD\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Search\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Power\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\DeviceCenter\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\HomeGroup\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Printer\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\IEBrowseWeb\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Networking\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\UsbCore\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:16    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\scheduled\Maintenance\zh-HK Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_mail_e07902f329fe05e9.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_mail_fr-fr_4eecf9fe83bba2f4.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_a421d1bfaf856e2b.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_fr-fr_28373d63876f08c8.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_pris_3635310c72721a09.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_media_player_da4e5f6eb3198de9.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_media_player_fr-fr_94ff9f0e3fc70d2e.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_journal_ada99bf7bc9c9733.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_journal_fr-fr_ff638b70bba77d0c.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_6101456faac5015c.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_accessories_156d2b9b22040474.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_accessories_fr-fr_4cd65768c2984181.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_f89c5a39d351281a.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_a4ba21b6f468ca9e.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_61efdd9e2d0263ca.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.0_44577d982216c291.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.0_fr_4221032969c490e5.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.5_44577da22216c264.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.5_fr_4221033369c490b8.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_photo_viewer_6eb173d8debcda9a.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_photo_viewer_fr-fr_bb189aee8d43363d.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_d7a65bb2f0e854e7.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_818c5a0e45020fba.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_ink_3c86e3db0b3b254c.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_ink_fr-fr_8bfc882e17332eb3.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_msinfo_817ad0c7c1c8e490.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_msinfo_fr-fr_983198eebb93b169.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_b13078daf1286f60.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_fr-fr_48bf79e23f0a8103.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ado_149a784bc852a2c0.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ado_fr-fr_9c146b32c12d06d9.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_msadc_48cda3763ecb3874.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_msadc_fr-fr_5aa17873a391a873.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ole_db_48d1b11cd4e5cabe.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ole_db_fr-fr_5fd30b47fd318ea1.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_defender_3e33901162166ae9.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_defender_fr-fr_a60802cb0ba0f4f6.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_04445b88cf0b8e8d.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_fr-fr_379139c69a39e1d4.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_pris_688b1d7050c30cf5.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_servicing_fc2045b9046cc796.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_servicing_fr-fr_626f794e6d096759.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_branding_1728f5d8b15e5263.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_branding_basebrd_9ee9a176c9fadab4.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_branding_basebrd_fr-fr_53a6d841406e43f7.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_fr-fr_401055e3a1d1fb2d.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_3296b36dbe4c7fa3.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_83386eac0379231b.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_5588a81f3fdc44c6.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_wpf_b56a2354fbfa0c31.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_wpf_fr-fr_23efa0878cf02f1c.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_wpf_fr_389a8cc7979d7497.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_windows_communication_foundation_e07323de19ff1b52.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_windows_communication_foundation_fr-fr_ff0d51665b4968c3.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_windows_communication_foundation_fr_60247259477539a0.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.5_5588a8293fdc4499.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:20    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.5_1036_b573e20073d26169.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.5_fr_3cd0207a9aaeb789.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_e9368840261e60ee.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_gac_fr_9a1532ebc04b4433.cdf-ms Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_1036_7994eaa40abd5528.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_mui_040c_fbbb4358c63bd596.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_fr_9d42e4553d1bb694.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_c40c7a995ddd757b.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_fr-fr_632d356756aecc96.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_1036_46978e41d75063db.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_bc1339ef8efa3c4c.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_fr-fr_dc61d3bd9661f3d3.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_fr_634f6a0b9d7640a2.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_sql_fr_634773779d9b38a7.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_app_localresources_84df96316f150d4c.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_providers_app_localresources_7d34f2c02aed6be4.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_appconfig_app_localresources_aef413ce2370b549.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_app_localresources_4620d9e6e73b47b8.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_wizard_app_localresources_6e58d02b006cefe5.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_permissions_app_localresources_ac56057a6371bc94.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_users_app_localresources_1f849782c95d71ca.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_roles_app_localresources_8626c43b9128448f.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_app_globalresources_adb5dd0528d9b46e.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_fr_7810d4be74fdd39b.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_40104b85a18bfcb2.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_resources_0adab7ac98c3dc03.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_resources_fr-fr_3395f82046454628.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_ime_3f581be9a4c8cabd.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_ime_fr-fr_0d349902e45b4cea.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_e6d66275c6e4d14a.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_scheduled_35e98acca7dbf9c7.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_scheduled_maintenance_6bb1b174b39bb442.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_scheduled_maintenance_fr-fr_1bdc5b0157eece7f.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_d78913b7f0741b59.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_usbcore_14d5b24ecc418e9a.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_usbcore_fr-fr_0c8574bb1fd60ca5.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_networking_29c6b61ce45e9171.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_networking_fr-fr_9d943efc239ad1f4.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iebrowseweb_e2468f1fdde27cf7.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iebrowseweb_fr-fr_ecd29bf71c0c47c6.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_printer_22190c3ab8798fd9.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_printer_fr-fr_211c07d5f7afbf28.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_homegroup_1909584eb21c73e3.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_homegroup_fr-fr_a570ceb1d3190832.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_devicecenter_0e1655bf357f4c22.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_devicecenter_fr-fr_63ad697e34ea0535.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_power_9d457dc1c7c54838.cdf-ms Handle ID: 0x2c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_power_fr-fr_73fffefa721e0dab.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_search_9d4b5385ff8f1ef3.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_search_fr-fr_0b0015f58595f73a.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerplaydvd_3aa04961f831b79d.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerplaydvd_fr-fr_19bd8e8bc81cbabe.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iesecurity_25644a5ef81c9ef5.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iesecurity_fr-fr_bd14c51e3912b744.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsupdate_0862ad88ff233b9d.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsupdate_fr-fr_6fa6342861a2949a.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_performance_d48bf95b5c828123.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_performance_fr-fr_0e1b291ac5a8194e.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_audio_9d2751b7c84ca0f1.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_audio_fr-fr_a198cdfb5d7cc6b4.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_aero_8b2c42561936b3f0.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_aero_fr-fr_1a66923f20a53285.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_pcw_2115168e47eaddb7.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_pcw_fr-fr_30abf1b4796d3b52.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerconfiguration_537e287f67955d9f.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerconfiguration_fr-fr_b559bb1f58a033e4.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_device_9d2d754600160183.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_device_fr-fr_3d73fcdaee8dd7de.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayermedialibrary_64611465e9119df8.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayermedialibrary_fr-fr_8fe44acee0ee7563.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_3f581daba4c8c835.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_windows_workflow_foundation_3.0.0.0_040c_c87be971a75f6c6c.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_servicemodeloperation_3.0.0.0_040c_9b92dfb4d51f3a94.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_smsvchost_3.0.0.0_040c_2d6db48d5cb5e141.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_bits_0ef6f148bde367d9.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_bits_040c_a03dbeed63e83514.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_d061836896f4f29d.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_040c_417ab2b890926456.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_data_0864fda87da3c851.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_data_040c_9335053bf0274832.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugthrsvc_9c5b081f28f83f11.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugthrsvc_040c_8451c270df70bfb6.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_oracle_07838adde9419766.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_oracle_040c_1ac898a2f00af4b1.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_smsvchost_4.0.0.0_13299f3c208ca635.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_smsvchost_4.0.0.0_040c_1bb386698498c912.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_tapisrv_20c65cafb424239c.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_tapisrv_040c_2e999da81b86262f.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_0ef70686e1d9b30c.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_040c_5b1ba5cf4f3691ef.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_usbhub_299dea1039e75d30.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_usbhub_040c_1bec310f3c8baefb.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_rdyboost_95e76b07334dd353.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_rdyboost_040c_50c6198d7330ca74.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_termservice_f0fb244350031192.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_termservice_040c_f96d64a36bc763b9.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_sqlserver_7cfd5f3e72497ce1.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_sqlserver_040c_22ef188981b08c82.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_remoteaccess_110554180baafc8b.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_remoteaccess_040c_86bc979ae65d5ea0.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugatherer_9f1f9c5b6cd50d98.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugatherer_040c_046b761df9ca08d5.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_bridge_3.0.0.0_040c_5d6037fd7f35c3b5.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_servicemodelservice_3.0.0.0_040c_2fd4dfb298bb9b5a.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_bridge_4.0.0.0_4d0c545c25fa998f.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_bridge_4.0.0.0_040c_4cb1a6e2183b9d5c.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_wsearchidxpi_a2c41dc1731a4204.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_wsearchidxpi_040c_2e6e3e8caf9fcb77.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_pnrpsvc_3932681b8fb41c9d.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_pnrpsvc_040c_437342c5fe2eac30.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_servicemodelendpoint_3.0.0.0_040c_1441b5536e0ddf5e.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_esent_0ef70656e1d1b1ac.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_esent_040c_5aeb99ff4bde3b4f.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_4.0.0.0_ea306c746014451b.cdf-ms Handle ID: 0x4c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_4.0.0.0_040c_fb64b0584648bbdc.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.netframework_266880c2626e99c6.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.netframework_040c_fd6b837d4926fcb5.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_windows_workflow_foundation_4.0.0.0_60d60271dbee3c46.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_windows_workflow_foundation_4.0.0.0_040c_c87be971a7dd7bed.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_desktoptileresources_b2a801db1c49551f.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_desktoptileresources_pris_fb9b991ef28508b5.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_policydefinitions_89130cdfc4d9c27c.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_policydefinitions_fr-fr_3af8366f8df212df.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_1e6ccf0e6a91b570.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_fr-fr_839e80c473f68359.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_pris_a05890fcf353f1d8.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_winrm_040c_a992612dfab42f6a.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:21    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_oobe_06655c95df2fa06f.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_oobe_fr-fr_e42bbc23f07c73c6.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migwiz_2650d8d30fee1fe9.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migwiz_fr-fr_b32d97ec52d4d5d4.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_fr-fr_448347788202c03b.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_fr-fr_licenses_oem_core_9816b9973c1ce0cb.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_fr-fr_licenses_default_core_bee720b565a6a12c.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_fr-fr_licenses_volume_core_64c54eff1cd90218.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_slmgr_040c_c09c70b40002fec0.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_boot_06654401df2fc50e.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_boot_fr-fr_bd2320ee2aca4d31.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_sysprep_f7b45b8dfed1b768.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_sysprep_fr-fr_ef66ef54a478c541.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migration_927a21df1acd7c18.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migration_fr-fr_815f132c89ff09b9.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_e92024d8b2d5d3b6.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_schema_869341856a9aa0c1.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_schema_msft_filedirectoryconfiguration_8324e8f8bda9c0f5.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_schema_msft_filedirectoryconfiguration_fr-fr_648627933ceae65e.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_baseregistration_f33ccae687b65dda.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_baseregistration_fr-fr_3a61680e5561b0d5.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_registration_fdfcf6ae03636dbf.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_registration_msft_filedirectoryconfiguration_e425053d94db5fd3.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_registration_msft_filedirectoryconfiguration_fr-fr_f35d5ce5b3646b74.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_xpsviewer_fr-fr_46781985b71985ae.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_fr-fr_4d9f89205bdfbc76.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_umdf_a531b5dc588477d3.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_umdf_fr-fr_b8967a317f6d7764.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_mui_040c_ecc96e0e9498d638.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wcn_06656d8dd047aafe.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wcn_fr-fr_f60f0d1104abebe3.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_fr_9da44a7e27ac6350.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dism_066548addf2fbd4b.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dism_fr-fr_062b15866d598704.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_driverstore_a531a9c6b3dfcf87.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_driverstore_fr-fr_f89b2012d73af418.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_printing_admin_scripts_fr-fr_f242a7bb737fae73.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_f1780fdbb7b569a2.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_8416c27bd490b8bd.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_fr-fr_cc276ef306e254c2.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_mui_040c_b123c2fce96d7533.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wbem_06656d9fdf2f8577.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wbem_fr-fr_45318c94b21276b4.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_fr-fr_028e70c3cac1447e.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_fr_5e58aa913822a9e3.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_a349059b05097caa.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_tls_36c96f1eb9feecc5.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_tls_fr-fr_ad27e03d154ce758.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_windowssearch_f5f5bf848a6aa07b.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_windowssearch_fr_499969b0c86b1543.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_secureboot_9d07353d2b857be7.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_secureboot_fr-fr_98b5d7afbfd1e962.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_fff314eba11c101c.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_fr-fr_204f13e59b49b311.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_ff9b33f72ef29061.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_groupresour_f89377aef0e3070d.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_groupresour_ef6291c702239550.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_scriptresou_9439642f1597caa3.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_scriptresou_5aff772efc12d48e.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_archivereso_76b8e47379b76aa0.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_archivereso_919a286d88402f27.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_registryres_edea8e2e2ccf59ab.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_registryres_6f00359868c32224.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_processreso_e9b5c28bf1698a37.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_processreso_2c1bc8ce8cea0fc4.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_roleresourc_76a4a3ef5d2c01a4.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_roleresourc_0d6170cf3a6d1b85.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_servicereso_fb85110125922f37.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_servicereso_e98c65c1017cea30.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_packagereso_7170c4cae89762bc.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_packagereso_94ebe822b39e7d67.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_logresource_55a4f1e43ab800fa.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_logresource_a1d183e92635cb99.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_userresourc_6c89372784f42be7.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_userresourc_c8401d237c108960.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_environment_f90a921d23087c69.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_environment_84d901a41af020fa.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_downloadmanager_dscfiledownlo_53cd0afeb4dff086.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_downloadmanager_dscfiledownlo_ddbcf9f527d797de.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_kds_36c95feeb9ff0384.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_kds_fr-fr_9df4236d27abf707.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_appx_6a827ca1d13e479b.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_appx_fr-fr_e59ef8a7b71c167a.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitstransfer_935cce3b0456eb87.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitstransfer_fr-fr_9153c846d5fcd184.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitlocker_a73047ff15e7584f.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitlocker_fr-fr_89f99730c781685c.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_netsecurity_1f2dcf39815a9f67.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_netsecurity_fr_cbf0753ec57d0b85.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_trustedplatformmodule_1b07dab5874a01a0.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_trustedplatformmodule_fr-fr_e7fd02942746fee3.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_msdtc_6a8283fc51a8e0dd.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_msdtc_fr-fr_82e4dbcb14f26cbe.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_msdtc_fr_bc81b5f7b9c3af17.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_dism_6a826ed5d13e5ce3.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_dism_fr_e7640108bafdab03.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_vpnclient_b543ca3d0a342edf.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_vpnclient_fr-fr_14c65d4f71a9ae3e.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_pki_36c96ea0b9feec70.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_pki_fr-fr_aca9c13b13039565.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_systemresetplatform_14fecc2716acccef.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_systemresetplatform_fr-fr_4c6c5cb8772a1ef6.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dsc_06654725d047e68c.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dsc_fr-fr_30ad3eefaeb11bcb.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_common_8c297630658eaa3d.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_common_fr-fr_fda6dace6086c198.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_engines_sr_f5f77fb9283237d8.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_engines_sr_fr-fr_50099e9a087d627b.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_speechux_bf4b53e8d47da913.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_speechux_fr-fr_86de50505660549e.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_com_066545e3d047e7c7.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_com_fr-fr_41fff867140cdc42.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_1e9f55b2d3f87dd3.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_pris_7badf1db07b249e7.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_reports_a2604845b2b380ca.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_reports_fr-fr_04eb889c9a79d515.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_rules_0bde462ce96f215e.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_rules_fr-fr_8cae8298513774d3.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_0307ca33e1cd9708.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsapp_041d35a886a9ab39.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsapp_pris_5b98fa23432d61fd.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingshandlers_5b3af40f40f8bda7.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingshandlers_pris_71ec33a38f3576eb.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_0e66dffb08041cab.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_pris_b9b6d478276f23e5.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsadminflowui_704aadb27d9f6f27.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsadminflowui_pris_73f1705cccdeb65b.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.search_ed9cc5a2b23bcffb.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.search_pris_6935df56eeeca635.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_6247a388787724b8.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_pris_a8c1f2a41196ba80.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:22    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_09ec0b99a5045113.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_fr-fr_f05e332ec1c4de0a.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_pris_f05e2f58ec689435.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_fbee56ab048ab239.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_themes_4d0d4910e83c2273.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_themes_aero_3fd78bf4cb5fa2c4.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_themes_aero_fr-fr_aaf261552095532b.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_apppatch_1143992cbbbebcab.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_apppatch_fr-fr_0b743d9675413c60.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_3b206622a946e834.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_common_76cd6f1aaba6e83b.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_common_fr-fr_11c7a7353ce16b54.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_8a294d630e90192b.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_tts_4e06b8e5aea05fb6.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_tts_fr-fr_5bd5d5f35660e80d.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_sr_fr-fr_31dda68dcd829b01.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_lexicon_fr-fr_bd73d7e3f64fda42.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_fr-fr_a61cd20eff9c2f56.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_dc4f6f92ba7f6fd4.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_indexstore_c4411e76b4b68bb5.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_indexstore_fr-fr_77aea1498b16ec22.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_contentstore_8ab00c4ac38e5298.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_contentstore_fr-fr_5bbb95c47755d8b7.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_mui_040c_c7942094fabea65b.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_fe5c6d762edd2110.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_b4e458a72482d5c6.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_common_coverpages_642a277e0ccb775c.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_common_coverpages_fr-fr_eea210bb844c0435.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_virtualinbox_343012079dc9af5d.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_virtualinbox_fr-fr_9e44d1e0f60f302c.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_07deb856-fc6e-4fb9-8add-d8f2cf8722c9__0ce7c057892d5774.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_07deb856-fc6e-4fb9-8add-d8f2cf8722c9_fr-fr_66e9414945040e25.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_e35be42d-f742-4d96-a50a-1775fb1a7a42__96ac8d0751fb5c2c.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_e35be42d-f742-4d96-a50a-1775fb1a7a42_fr-fr_98bc1fc303c72d5f.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Speech\Engines\Lexicon\fr-FR Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Speech\Engines\SR\fr-FR Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Speech\SpeechUX\fr-FR Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:23    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SystemResetPlatform\fr-FR Handle ID: 0x20 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:29    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\ImmersiveControlPanel\fr-FR Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:29    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\inf\TAPISRV\040C Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\WindowsMediaPlayerMediaLibrary\fr-FR Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Device\fr-FR Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\WindowsMediaPlayerConfiguration\fr-FR Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\PCW\fr-FR Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\AERO\fr-FR Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Audio\fr-FR Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Performance\fr-FR Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\WindowsUpdate\fr-FR Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\IESecurity\fr-FR Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\WindowsMediaPlayerPlayDVD\fr-FR Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Search\fr-FR Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Power\fr-FR Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\DeviceCenter\fr-FR Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\HomeGroup\fr-FR Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Printer\fr-FR Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\IEBrowseWeb\fr-FR Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Networking\fr-FR Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\UsbCore\fr-FR Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\scheduled\Maintenance\fr-FR Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_mail_e07902f329fe05e9.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_mail_es-es_4eecfbe283ba9fe6.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_a421d1bfaf856e2b.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_pris_3635310c72721a09.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_es-es_2650c78b8a48b9a6.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_media_player_da4e5f6eb3198de9.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_media_player_es-es_94ffa0f23fc60a20.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_6101456faac5015c.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_accessories_156d2b9b22040474.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_accessories_es-es_4cfa5e3cc24730b3.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_photo_viewer_6eb173d8debcda9a.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_photo_viewer_es-es_bb189cd28d42332f.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_journal_ada99bf7bc9c9733.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_journal_es-es_ff618b18bbb07eea.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_d7a65bb2f0e854e7.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_818c5a0e45020fba.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_ink_3c86e3db0b3b254c.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_ink_es-es_8a1612561a0cdf91.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_msinfo_817ad0c7c1c8e490.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_msinfo_es-es_98319ad2bb92ae5b.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_b13078daf1286f60.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ado_149a784bc852a2c0.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ado_es-es_9c126adac13608b7.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_msadc_48cda3763ecb3874.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_msadc_es-es_58bb029ba66b5951.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ole_db_48d1b11cd4e5cabe.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ole_db_es-es_5ff7121bfce07dd3.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_es-es_48bd798a3f1382e1.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_f89c5a39d351281a.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_a4ba21b6f468ca9e.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_61efdd9e2d0263ca.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.0_44577d982216c291.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.0_es_4221011f69c4940f.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.5_44577da22216c264.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.5_es_4221012969c493e2.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_defender_3e33901162166ae9.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_defender_es-es_a60804af0b9ff1e8.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_04445b88cf0b8e8d.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_pris_688b1d7050c30cf5.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_es-es_35aac3ee9d1392b2.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:33    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_servicing_fc2045b9046cc796.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_servicing_es-es_629380226cb8568b.cdf-ms Handle ID: 0x24 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_branding_1728f5d8b15e5263.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_branding_basebrd_9ee9a176c9fadab4.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_branding_basebrd_es-es_51c062694347f4d5.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_3296b36dbe4c7fa3.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_83386eac0379231b.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_5588a81f3fdc44c6.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_wpf_b56a2354fbfa0c31.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_wpf_es_389a8abd979d77c1.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_wpf_es-es_22092aaf8fc9dffa.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_windows_communication_foundation_e07323de19ff1b52.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_windows_communication_foundation_es_6024727f47753946.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_windows_communication_foundation_es-es_ff31583a5af857f5.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.5_5588a8293fdc4499.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.5_es_3cd01e709aaebab3.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.5_3082_b573e5d673d25b86.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_e9368840261e60ee.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_gac_es_9a1532e9c04b443d.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_es_9d42e4533d1bb69e.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_mui_0c0a_fbbb43a0c63bd503.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_3082_7994f4b60abd4595.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_c40c7a995ddd757b.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_es_7810d4bc74fdd3a5.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_bc1339ef8efa3c4c.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_es_634f6a099d7640ac.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_es-es_dc5fd365966af5b1.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_3082_46979853d7505448.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_sql_es_634773759d9b38b1.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_app_localresources_84df96316f150d4c.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_providers_app_localresources_7d34f2c02aed6be4.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_appconfig_app_localresources_aef413ce2370b549.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_app_localresources_4620d9e6e73b47b8.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_wizard_app_localresources_6e58d02b006cefe5.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_permissions_app_localresources_ac56057a6371bc94.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_users_app_localresources_1f849782c95d71ca.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_roles_app_localresources_8626c43b9128448f.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_app_globalresources_adb5dd0528d9b46e.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_es-es_632b350f56b7ce74.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_40104b85a18bfcb2.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_resources_0adab7ac98c3dc03.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_resources_es-es_3393f7c8464e4806.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_e6d66275c6e4d14a.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_scheduled_35e98acca7dbf9c7.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_scheduled_maintenance_6bb1b174b39bb442.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_scheduled_maintenance_es-es_1c0061d5579dbdb1.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_d78913b7f0741b59.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_usbcore_14d5b24ecc418e9a.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_usbcore_es-es_0c8374631fdf0e83.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_networking_29c6b61ce45e9171.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_networking_es-es_9db845d02349c126.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_printer_22190c3ab8798fd9.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_printer_es-es_211a077df7b8c106.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iebrowseweb_e2468f1fdde27cf7.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iebrowseweb_es-es_ecd09b9f1c1549a4.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_devicecenter_0e1655bf357f4c22.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_devicecenter_es-es_63ad6b6234e90227.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_power_9d457dc1c7c54838.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_power_es-es_7219892274f7be89.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_homegroup_1909584eb21c73e3.cdf-ms Handle ID: 0x34 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_homegroup_es-es_a38a58d9d5f2b910.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_search_9d4b5385ff8f1ef3.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_search_es-es_0b241cc98544e66c.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerplaydvd_3aa04961f831b79d.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerplaydvd_es-es_17d718b3caf66b9c.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iesecurity_25644a5ef81c9ef5.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iesecurity_es-es_bd38cbf238c1a676.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsupdate_0862ad88ff233b9d.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsupdate_es-es_6dbfbe50647c4578.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_performance_d48bf95b5c828123.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_performance_es-es_0e1928c2c5b11b2c.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerconfiguration_537e287f67955d9f.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerconfiguration_es-es_b557bac758a935c2.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_device_9d2d754600160183.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_device_es-es_3d9803aeee3cc710.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayermedialibrary_64611465e9119df8.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayermedialibrary_es-es_900851a2e09d6495.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_audio_9d2751b7c84ca0f1.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_audio_es-es_9fb2582360567792.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_aero_8b2c42561936b3f0.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_aero_es-es_1a66942320a42f77.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_pcw_2115168e47eaddb7.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_pcw_es-es_30a9f15c79763d30.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_ime_3f581be9a4c8cabd.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_ime_es-es_0d349ae6e45a49dc.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_3f581daba4c8c835.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_windows_workflow_foundation_3.0.0.0_0c0a_c87c05e7a75f41c7.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_servicemodeloperation_3.0.0.0_0c0a_9b92dc06d51f3fbf.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_smsvchost_3.0.0.0_0c0a_2d6db0df5cb5e66c.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_bits_0ef6f148bde367d9.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_bits_0c0a_a03dbcd163e839d1.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_data_0864fda87da3c851.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_data_0c0a_9335018df0274d5d.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_d061836896f4f29d.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_0c0a_417acf2e909239b1.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_oracle_07838adde9419766.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_oracle_0c0a_1ac894f4f00af9dc.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugthrsvc_9c5b081f28f83f11.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugthrsvc_0c0a_8451c054df70c473.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_smsvchost_4.0.0.0_13299f3c208ca635.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_smsvchost_4.0.0.0_0c0a_1bb382bb8498ce3d.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_0ef70686e1d9b30c.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_0c0a_5b1ba2214f36971a.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_usbhub_299dea1039e75d30.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_usbhub_0c0a_1bec31573c8bae68.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_tapisrv_20c65cafb424239c.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_tapisrv_0c0a_2e99ba1e1b85fb8a.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_termservice_f0fb244350031192.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_termservice_0c0a_f96d81196bc73914.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_sqlserver_7cfd5f3e72497ce1.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_sqlserver_0c0a_22ef166d81b0913f.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_rdyboost_95e76b07334dd353.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_rdyboost_0c0a_50c617717330cf31.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_bridge_3.0.0.0_0c0a_5d6035e17f35c872.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_servicemodelservice_3.0.0.0_0c0a_2fd4fc2898bb70b5.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_bridge_4.0.0.0_4d0c545c25fa998f.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_bridge_4.0.0.0_0c0a_4cb1a4c6183ba219.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_remoteaccess_110554180baafc8b.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_remoteaccess_0c0a_86bc957ee65d635d.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugatherer_9f1f9c5b6cd50d98.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugatherer_0c0a_046b726ff9ca0e00.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_servicemodelendpoint_3.0.0.0_0c0a_1441b3376e0de41b.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_esent_0ef70656e1d1b1ac.cdf-ms Handle ID: 0x30 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_esent_0c0a_5aeb96514bde407a.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_4.0.0.0_ea306c746014451b.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_4.0.0.0_0c0a_fb64ccce46489137.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_windows_workflow_foundation_4.0.0.0_60d60271dbee3c46.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_windows_workflow_foundation_4.0.0.0_0c0a_c87c05e7a7dd5148.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.netframework_266880c2626e99c6.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.netframework_0c0a_fd6b7fcf492701e0.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_wsearchidxpi_a2c41dc1731a4204.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_wsearchidxpi_0c0a_2e6e3c70af9fd034.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_pnrpsvc_3932681b8fb41c9d.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:34    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_pnrpsvc_0c0a_43735f3bfe2e818b.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_1e6ccf0e6a91b570.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_pris_a05890fcf353f1d8.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_es-es_83c2879873a5728b.cdf-ms Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_desktoptileresources_b2a801db1c49551f.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_desktoptileresources_pris_fb9b991ef28508b5.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_policydefinitions_89130cdfc4d9c27c.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_policydefinitions_es-es_3b1c3d438da10211.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_winrm_0c0a_a9926175fab42ed7.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migwiz_2650d8d30fee1fe9.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migwiz_es-es_b32d99d052d3d2c6.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_oobe_06655c95df2fa06f.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_oobe_es-es_e44fc2f7f02b62f8.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_sysprep_f7b45b8dfed1b768.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_sysprep_es-es_ed80797ca752761f.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_slmgr_0c0a_c09c70fc0002fe2d.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_es_9da4487427ac667a.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_boot_06654401df2fc50e.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_boot_es-es_bd4727c22a793c63.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migration_927a21df1acd7c18.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migration_es-es_815d12d48a080b97.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_e92024d8b2d5d3b6.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_schema_869341856a9aa0c1.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_schema_msft_filedirectoryconfiguration_8324e8f8bda9c0f5.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_schema_msft_filedirectoryconfiguration_es-es_64aa2e673c99d590.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_baseregistration_f33ccae687b65dda.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_baseregistration_es-es_3a6169f25560adc7.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_registration_fdfcf6ae03636dbf.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_registration_msft_filedirectoryconfiguration_e425053d94db5fd3.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_registration_msft_filedirectoryconfiguration_es-es_f35d5ec9b3636866.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_xpsviewer_es-es_4676192db722878c.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_umdf_a531b5dc588477d3.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_umdf_es-es_b8ba81057f1c6696.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_es-es_4bb913485eb96d54.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_mui_0c0a_ecc96bf29498daf5.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wcn_06656d8dd047aafe.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wcn_es-es_f428973907859cc1.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dism_066548addf2fbd4b.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dism_es-es_064f1c5a6d087636.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_driverstore_a531a9c6b3dfcf87.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_driverstore_es-es_f6b4aa3ada14a4f6.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_printing_admin_scripts_es-es_f242a99f737eab65.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_es_5e58ac773822a709.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_es-es_028e72a7cac04170.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_a349059b05097caa.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_tls_36c96f1eb9feecc5.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_tls_es-es_ad27e221154be44a.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_windowssearch_f5f5bf848a6aa07b.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_windowssearch_es_499969d6c86b14e9.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_secureboot_9d07353d2b857be7.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_secureboot_es-es_98b3d757bfdaeb40.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_fff314eba11c101c.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_ff9b33f72ef29061.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_groupresour_f89377aef0e3070d.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_groupresour_ef6293ab02229242.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_scriptresou_9439642f1597caa3.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_scriptresou_59190156feec856c.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_archivereso_76b8e47379b76aa0.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_archivereso_91be2f4187ef1e59.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_registryres_edea8e2e2ccf59ab.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_registryres_6efe354068cc2402.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_processreso_e9b5c28bf1698a37.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_processreso_2c3fcfa28c98fef6.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_roleresourc_76a4a3ef5d2c01a4.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_roleresourc_0d5f70773a761d63.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_servicereso_fb85110125922f37.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_servicereso_e9b06c95012bd962.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_packagereso_7170c4cae89762bc.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_packagereso_950feef6b34d6c99.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_logresource_55a4f1e43ab800fa.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_logresource_a1f58abd25e4bacb.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_userresourc_6c89372784f42be7.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_userresourc_c83e1ccb7c198b3e.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_environment_f90a921d23087c69.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_dscresources_msft_environment_84fd08781a9f102c.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_downloadmanager_dscfiledownlo_53cd0afeb4dff086.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_downloadmanager_dscfiledownlo_ddbcf9f327d797e8.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_es-es_204f15c99b48b003.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_kds_36c95feeb9ff0384.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_kds_es-es_9df4255127aaf3f9.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_appx_6a827ca1d13e479b.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_appx_es-es_e3b882cfb9f5c758.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitstransfer_935cce3b0456eb87.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitstransfer_es-es_8f6d526ed8d68262.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitlocker_a73047ff15e7584f.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitlocker_es-es_8a1d9e04c730578e.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_trustedplatformmodule_1b07dab5874a01a0.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_trustedplatformmodule_es-es_e821096826f5ee15.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_msdtc_6a8283fc51a8e0dd.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_msdtc_es_bc81b61db9c3aebd.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_msdtc_es-es_8308e29f14a15bf0.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_netsecurity_1f2dcf39815a9f67.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_netsecurity_es_cbf07724c57d08ab.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_dism_6a826ed5d13e5ce3.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_dism_es_e763fefebafdae2d.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_vpnclient_b543ca3d0a342edf.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_vpnclient_es-es_14ea642371589d70.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_pki_36c96ea0b9feec70.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_pki_es-es_aca9c31f13029257.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wbem_06656d9fdf2f8577.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wbem_es-es_45559368b1c165e6.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_f1780fdbb7b569a2.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_8416c27bd490b8bd.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_mui_0c0a_b123df72e96d4a8e.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_es-es_cc2770d706e151b4.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_es-es_429cd1a084dc7119.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_es-es_licenses_oem_core_5454cd64b481a947.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_es-es_licenses_default_core_239d6a820ef16a6e.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_es-es_licenses_volume_core_c97b98cc8622589c.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_com_066545e3d047e7c7.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_com_es-es_4019828f16e68d20.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_systemresetplatform_14fecc2716acccef.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_systemresetplatform_es-es_4a85e6e07a03cfd4.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dsc_06654725d047e68c.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dsc_es-es_2ec6c917b18acca9.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_common_8c297630658eaa3d.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_common_es-es_fda4da76608fc376.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_engines_sr_f5f77fb9283237d8.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_engines_sr_es-es_50079e4208866459.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_speechux_bf4b53e8d47da913.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_speechux_es-es_84f7da78593a057c.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_1e9f55b2d3f87dd3.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_pris_7badf1db07b249e7.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_reports_a2604845b2b380ca.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_reports_es-es_04eb8a809a78d207.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_rules_0bde462ce96f215e.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_rules_es-es_8cd2896c50e66405.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_es-es_401057c7a1d0f81f.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_0307ca33e1cd9708.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsapp_041d35a886a9ab39.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsapp_pris_5b98fa23432d61fd.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_0e66dffb08041cab.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_pris_b9b6d478276f23e5.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:35    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingshandlers_5b3af40f40f8bda7.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingshandlers_pris_71ec33a38f3576eb.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsadminflowui_704aadb27d9f6f27.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsadminflowui_pris_73f1705cccdeb65b.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_6247a388787724b8.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_pris_a8c1f2a41196ba80.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.search_ed9cc5a2b23bcffb.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.search_pris_6935df56eeeca635.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_fbee56ab048ab239.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_themes_4d0d4910e83c2273.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_themes_aero_3fd78bf4cb5fa2c4.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_themes_aero_es-es_ab1668292044425d.cdf-ms Handle ID: 0x14 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_apppatch_1143992cbbbebcab.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_apppatch_es-es_098dc7be781aed3e.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_09ec0b99a5045113.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_pris_f05e2f58ec689435.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_es-es_f05e3512c1c3dafc.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_3b206622a946e834.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_common_76cd6f1aaba6e83b.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_common_es-es_11ebae093c905a86.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_8a294d630e90192b.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_tts_4e06b8e5aea05fb6.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_tts_es-mx_5bd3d4855669ec46.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_tts_es-es_5bd3d59b5669e9eb.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_sr_es-es_3201ad61cd318a33.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_lexicon_es-es_bd71d78bf658dc20.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_dc4f6f92ba7f6fd4.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_indexstore_c4411e76b4b68bb5.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_indexstore_es-es_77aea32d8b15e914.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_contentstore_8ab00c4ac38e5298.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_contentstore_es-es_5bdf9c987704c7e9.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_mui_0c0a_c7941e78fabeab18.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_es-es_a4365c370275e034.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_fe5c6d762edd2110.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_b4e458a72482d5c6.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_common_coverpages_642a277e0ccb775c.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_common_coverpages_es-es_eec6178f83faf367.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_virtualinbox_343012079dc9af5d.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_virtualinbox_es-es_9c5e5c08f8e8e10a.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_07deb856-fc6e-4fb9-8add-d8f2cf8722c9__0ce7c057892d5774.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_07deb856-fc6e-4fb9-8add-d8f2cf8722c9_es-es_66e9432d45030b17.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_e35be42d-f742-4d96-a50a-1775fb1a7a42__96ac8d0751fb5c2c.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_e35be42d-f742-4d96-a50a-1775fb1a7a42_es-es_98bc21a703c62a51.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Speech\Engines\Lexicon\es-ES Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\Speech\Engines\SR\es-ES Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\Speech\SpeechUX\es-ES Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:36    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\SystemResetPlatform\es-ES Handle ID: 0x40 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\ImmersiveControlPanel\es-ES Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\inf\TAPISRV\0C0A Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\PCW\es-ES Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\AERO\es-ES Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Audio\es-ES Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\WindowsMediaPlayerMediaLibrary\es-ES Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Device\es-ES Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\WindowsMediaPlayerConfiguration\es-ES Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Performance\es-ES Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\WindowsUpdate\es-ES Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\IESecurity\es-ES Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\WindowsMediaPlayerPlayDVD\es-ES Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Search\es-ES Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\HomeGroup\es-ES Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Power\es-ES Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\DeviceCenter\es-ES Handle ID: 0x54 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\IEBrowseWeb\es-ES Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Printer\es-ES Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\Networking\es-ES Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\system\UsbCore\es-ES Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:42    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\diagnostics\scheduled\Maintenance\es-ES Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_fr-fr_448347788202c03b.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_en-us_429cd25484dc6f94.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_es-es_429cd1a084dc7119.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-hk_6a84939e4900ccf6.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-cn_6a8499504900c466.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_1e9f55b2d3f87dd3.cdf-ms Handle ID: 0x28 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x3c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_3f581daba4c8c835.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_3296b36dbe4c7fa3.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_83386eac0379231b.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_c40c7a995ddd757b.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_nativeimages_7f83bd6ed8241f3a.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_a421d1bfaf856e2b.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_3296b36dbe4c7fa3.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_83386eac0379231b.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_c40c7a995ddd757b.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_bc1339ef8efa3c4c.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_04445b88cf0b8e8d.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_fr-fr_379139c69a39e1d4.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_en-us_35aac4a29d13912d.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_es-es_35aac3ee9d1392b2.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_zh-cn_5d928b9e6137e5ff.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_zh-hk_5d9285ec6137ee8f.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_3f581daba4c8c835.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_policydefinitions_89130cdfc4d9c27c.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_inputmethod_shared_6eb54fb4ad19ef1c.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migwiz_2650d8d30fee1fe9.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-hk_6a84939e4900ccf6.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_fr-fr_448347788202c03b.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_es-es_429cd1a084dc7119.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-cn_6a8499504900c466.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spp_tokens_ppdlic_0f09ba294211a24b.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_en-us_429cd25484dc6f94.cdf-ms Handle ID: 0x5c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:46    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_apppatch_1143992cbbbebcab.cdf-ms Handle ID: 0x64 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms Handle ID: 0x1c Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_a421d1bfaf856e2b.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_fr-fr_28373d63876f08c8.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_en-us_2650c83f8a48b821.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_es-es_2650c78b8a48b9a6.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_zh-hk_4e3889894e6d1583.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_zh-cn_4e388f3b4e6d0cf3.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_d7a65bb2f0e854e7.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_818c5a0e45020fba.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_ink_3c86e3db0b3b254c.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_journal_ada99bf7bc9c9733.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_journal_zh-hk_ff8b94f2baf35197.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_journal_zh-cn_ff8b95acbaf34fe7.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_defender_3e33901162166ae9.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_3296b36dbe4c7fa3.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_83386eac0379231b.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_c40c7a995ddd757b.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_bc1339ef8efa3c4c.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_04445b88cf0b8e8d.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_fr-fr_379139c69a39e1d4.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_en-us_35aac4a29d13912d.cdf-ms Handle ID: 0x48 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_es-es_35aac3ee9d1392b2.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_zh-hk_5d9285ec6137ee8f.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_zh-cn_5d928b9e6137e5ff.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_mediaviewer_031bbf13c7a6f174.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_40104b85a18bfcb2.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_efi_0f890f82be247f42.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_pcat_0f8924c0debe64e4.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_vpnplugins_juniper_5202b8b12182e1c1.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_vpnplugins_f5_fdcbfdf645f834f9.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_vpnplugins_f5_f5vpnpluginappbg_978cbd3a7e028b77.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_vpnplugins_checkpoint_30967b7344988fbc.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_vpnplugins_sonicwall_508a4be0c07000ee.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_3f581daba4c8c835.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_1e6ccf0e6a91b570.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_a349059b05097caa.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_fff314eba11c101c.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_fr-fr_204f13e59b49b311.cdf-ms Handle ID: 0x50 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_en-us_204f0c6b9b48bdb0.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_72e61bb83a8f716f.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_groupresourc_2cdc5c5e9202d5eb.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_groupresourc_59e276d385c181c2.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_groupresourc_59e0743b85ca88ab.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_groupresourc_59e0767b85ca83a0.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_groupresourc_5a0a8055850d564d.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_groupresourc_5a0a810f850d549d.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_scriptresour_26725c890cc03aed.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_scriptresour_66d34180783b7cae.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_scriptresour_66d33a06783a874d.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_scriptresour_66d34364783a79a0.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_scriptresour_66d32e88784f9dfb.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_scriptresour_66d32e7e784f9e2b.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_archiveresou_547cec1c740fb34e.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_archiveresou_2e9ed7c881d2af01.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_archiveresou_2cb862a484ac5e5a.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_archiveresou_2cb861f084ac5fdf.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_archiveresou_54a023ee48d0bbbc.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_archiveresou_54a029a048d0b32c.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_registryreso_0e42dbd1801c7751.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_registryreso_991347dda5912fc4.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_registryreso_99376d07a53ff193.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_registryreso_99374eb1a5401ef6.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_registryreso_96429b61abe6b6e1.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_registryreso_96429177abe6c611.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_processresou_21e75bec564f071f.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_processresou_e53e73c804e6299c.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_processresou_e357fea407bfd8f5.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_processresou_e357fdf007bfda7a.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_processresou_0b3fbfedcbe43657.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_processresou_0b3fc59fcbe42dc7.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_roleresource_df559ab05daec448.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_roleresource_b9f610475c4f6aab.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_roleresource_ba1a35715bfe2c7a.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_roleresource_ba1a171b5bfe59dd.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_roleresource_b72563cb62a4f1c8.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_roleresource_b72559e162a500f8.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_serviceresou_0e75aa46c124c33f.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_serviceresou_55307bdac08d74f0.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_serviceresou_534a06b6c3672449.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:50    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_serviceresou_534a0602c36725ce.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_serviceresou_7b31c800878b81ab.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_serviceresou_7b31cdb2878b791b.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_packageresou_09398e9ab3481d72.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_packageresou_89f8a552607a81e1.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_packageresou_8812302e6354313a.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_packageresou_88122f7a635432bf.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_packageresou_aff9f17827788e9c.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_packageresou_aff9f72a2778860c.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_logresource_23cbd1e723298208.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_logresource__0cbf8647311338ff.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_logresource__0ad9112333ece858.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_logresource__0ad9106f33ece9dd.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_logresource__32c0d26cf81145ba.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_logresource__32c0d81ef8113d2a.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_userresource_5f7c55c0edb88acd.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_userresource_d1d64993df2e0318.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_userresource_d1fa6ebddedcc4e7.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_userresource_d1fa5067dedcf24a.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_userresource_cf059d17e5838a35.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_userresource_cf05932de5839965.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_environmentr_14bf79628283a3a1.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_environmentr_4063cc24757b6a16.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_environmentr_3e7d57007855196f.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_environmentr_3e7d564c78551af4.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_environmentr_6665184a3c7976d1.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_environmentr_66651dfc3c796e41.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_es-es_204f15c99b48b003.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_zh-hk_204f00ed9b5dd45e.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_zh-cn_204f00e39b5dd48e.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_f1780fdbb7b569a2.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_8416c27bd490b8bd.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_zh-cn_cc275bf106f6763f.cdf-ms Handle ID: 0x44 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_zh-hk_cc275bfb06f6760f.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-hk_6a84939e4900ccf6.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_boot_06654401df2fc50e.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migration_927a21df1acd7c18.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_fr-fr_448347788202c03b.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dism_066548addf2fbd4b.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_es-es_429cd1a084dc7119.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-cn_6a8499504900c466.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spp_tokens_ppdlic_0f09ba294211a24b.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_oobe_06655c95df2fa06f.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_common_8c297630658eaa3d.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_en-us_429cd25484dc6f94.cdf-ms Handle ID: 0x38 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_0307ca33e1cd9708.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_0e66dffb08041cab.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_inbox.media.shared_styles_0b8acc230dca130a.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_windowsinternal_inbox_media_viewer_cfc88b9afeef4188.cdf-ms Handle ID: 0x18 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_windowsinternal_inbox_media_viewer_edit_272c0da94a4002b4.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_windowsinternal_inbox_media_viewer_viewer_592c52ca633f93be.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_windowsinternal_inbox_media_viewer_camera_5bc8d30c5d8362b9.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_windowsinternal_inbox_media_viewer_pano_272c02994a40148c.cdf-ms Handle ID: 0x58 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_6247a388787724b8.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_pris_a8c1f2a41196ba80.cdf-ms Handle ID: 0x68 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_1e9f55b2d3f87dd3.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_apppatch_1143992cbbbebcab.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-28 18:06:51    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_09ec0b99a5045113.cdf-ms Handle ID: 0x60 Process Information: Process ID: 0x388 Process Name: C:\Windows\System32\poqexec.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  103  2013-11-28 18:08:24    Microsoft-Windows-Eventlog  1100: The event logging service has shut down.
Security  Audit Success  12288  2013-11-28 18:08:50    Microsoft-Windows-Security-Auditing  4608: Windows is starting up. This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Security  Audit Success  12544  2013-11-28 18:08:50    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Type: 0 Impersonation Level: - New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x4 Process Name: Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: - Authentication Package: - Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:08:51    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x298 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:08:51    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-20 Account Name: NETWORK SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e4 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x298 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:08:51    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 18:08:51    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-20 Account Name: NETWORK SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e4 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
Security  Audit Success  13568  2013-11-28 18:08:51    Microsoft-Windows-Security-Auditing  4902: The Per-user audit policy table was created. Number of Elements: 0 Policy ID: 0x87e0
Security  Audit Success  12544  2013-11-28 18:08:52    Microsoft-Windows-Security-Auditing  4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: DWM-1 Account Domain: Window Manager Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x270 Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: - Port: - This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Security  Audit Success  12544  2013-11-28 18:08:52    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 2 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xe2d9 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x270 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:08:52    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 2 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xe2fd Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x270 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:08:52    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x298 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:08:52    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x298 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:08:52    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x298 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:08:52    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xe2d9 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 18:08:52    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xe2fd Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege
Security  Audit Success  12548  2013-11-28 18:08:52    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 18:08:52    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 18:08:52    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 18:08:53    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x298 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:08:53    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12292  2013-11-28 18:08:56    Microsoft-Windows-Security-Auditing  5033: The Windows Firewall Driver started successfully.
Security  Audit Success  12544  2013-11-28 18:08:56    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x298 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:08:56    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 18:08:57    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x298 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:08:57    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Type: 3 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-7 Account Name: ANONYMOUS LOGON Account Domain: NT AUTHORITY Logon ID: 0x18782 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x0 Process Name: - Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: NtLmSsp Authentication Package: NTLM Transited Services: - Package Name (NTLM only): NTLM V1 Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:08:57    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12292  2013-11-28 18:08:58    Microsoft-Windows-Security-Auditing  5024: The Windows Firewall service started successfully.
Security  Audit Success  12544  2013-11-28 18:10:57    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x298 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:10:57    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 18:11:27    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x298 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:11:27    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  103  2013-11-28 18:32:31    Microsoft-Windows-Eventlog  1100: The event logging service has shut down.
Security  Audit Success  12288  2013-11-28 18:32:52    Microsoft-Windows-Security-Auditing  4608: Windows is starting up. This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Security  Audit Success  12544  2013-11-28 18:32:52    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Type: 0 Impersonation Level: - New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x4 Process Name: Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: - Authentication Package: - Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:32:52    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2b4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:32:52    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  13568  2013-11-28 18:32:52    Microsoft-Windows-Security-Auditing  4902: The Per-user audit policy table was created. Number of Elements: 0 Policy ID: 0x86db
Security  Audit Success  12544  2013-11-28 18:32:53    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-20 Account Name: NETWORK SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e4 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2b4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:32:53    Microsoft-Windows-Security-Auditing  4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: DWM-1 Account Domain: Window Manager Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x288 Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: - Port: - This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Security  Audit Success  12544  2013-11-28 18:32:53    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 2 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xe8b1 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x288 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:32:53    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 2 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xe8ee Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x288 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:32:53    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2b4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:32:53    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2b4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:32:53    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2b4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:32:53    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2b4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:32:53    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-20 Account Name: NETWORK SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e4 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 18:32:53    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xe8b1 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 18:32:53    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xe8ee Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege
Security  Audit Success  12548  2013-11-28 18:32:53    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 18:32:53    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 18:32:53    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 18:32:53    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12292  2013-11-28 18:32:56    Microsoft-Windows-Security-Auditing  5033: The Windows Firewall Driver started successfully.
Security  Audit Success  12544  2013-11-28 18:32:56    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2b4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:32:56    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12292  2013-11-28 18:32:57    Microsoft-Windows-Security-Auditing  5024: The Windows Firewall service started successfully.
Security  Audit Success  12544  2013-11-28 18:32:57    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2b4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:32:57    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Type: 3 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-7 Account Name: ANONYMOUS LOGON Account Domain: NT AUTHORITY Logon ID: 0x191a6 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x0 Process Name: - Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: NtLmSsp Authentication Package: NTLM Transited Services: - Package Name (NTLM only): NTLM V1 Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:32:57    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 18:34:57    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2b4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:34:57    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 18:35:27    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2b4 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:35:27    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  103  2013-11-28 18:56:30    Microsoft-Windows-Eventlog  1100: The event logging service has shut down.
Security  Audit Success  12288  2013-11-28 18:56:49    Microsoft-Windows-Security-Auditing  4608: Windows is starting up. This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Security  Audit Success  12544  2013-11-28 18:56:49    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Type: 0 Impersonation Level: - New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x4 Process Name: Network Information: Workstation Name: - Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: - Authentication Package: - Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:56:49    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:56:49    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  13568  2013-11-28 18:56:49    Microsoft-Windows-Security-Auditing  4902: The Per-user audit policy table was created. Number of Elements: 0 Policy ID: 0x87c3
Security  Audit Success  12544  2013-11-28 18:56:50    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-20 Account Name: NETWORK SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e4 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:56:50    Microsoft-Windows-Security-Auditing  4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: DWM-1 Account Domain: Window Manager Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x288 Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: - Port: - This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Security  Audit Success  12544  2013-11-28 18:56:50    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 2 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xe7c5 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x288 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:56:50    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 2 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xe7fb Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x288 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:56:50    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:56:50    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:56:50    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:56:50    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:56:50    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-20 Account Name: NETWORK SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e4 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 18:56:50    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xe7c5 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 18:56:50    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-90-1 Account Name: DWM-1 Account Domain: Window Manager Logon ID: 0xe7fb Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege
Security  Audit Success  12548  2013-11-28 18:56:50    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Privileges: SeAssignPrimaryTokenPrivilege SeAuditPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 18:56:50    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 18:56:50    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 18:56:50    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12292  2013-11-28 18:56:53    Microsoft-Windows-Security-Auditing  5033: The Windows Firewall Driver started successfully.
Security  Audit Success  12544  2013-11-28 18:56:53    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:56:53    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12292  2013-11-28 18:56:54    Microsoft-Windows-Security-Auditing  5024: The Windows Firewall service started successfully.
Security  Audit Success  12544  2013-11-28 18:56:54    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:56:54    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-0-0 Account Name: - Account Domain: - Logon ID: 0x0 Logon Type: 3 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-7 Account Name: ANONYMOUS LOGON Account Domain: NT AUTHORITY Logon ID: 0x192cd Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x0 Process Name: - Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: NtLmSsp Authentication Package: NTLM Transited Services: - Package Name (NTLM only): NTLM V1 Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:56:54    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 18:56:56    Microsoft-Windows-Security-Auditing  4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: Transformer T100 Account Domain: T100 Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x288 Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: 127.0.0.1 Port: 0 This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Security  Audit Success  12544  2013-11-28 18:56:56    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 2 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x242e6 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x288 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: T100 Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:56:56    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 2 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x24357 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x288 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: T100 Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:56:56    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x242e6 Privileges: SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 18:56:57    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-28 18:56:57    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:56:57    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-28 18:56:57    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 18:56:59    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 18:56:59    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  13824  2013-11-28 18:57:00    Microsoft-Windows-Security-Auditing  4797: An attempt was made to query the existence of a blank password for an account. Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x24357 Additional Information: Caller Workstation: T100 Target Account Name: Administrator Target Account Domain: T100
Security  Audit Success  13824  2013-11-28 18:57:00    Microsoft-Windows-Security-Auditing  4797: An attempt was made to query the existence of a blank password for an account. Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x24357 Additional Information: Caller Workstation: T100 Target Account Name: Guest Target Account Domain: T100
Security  Audit Success  13824  2013-11-28 18:57:00    Microsoft-Windows-Security-Auditing  4797: An attempt was made to query the existence of a blank password for an account. Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x24357 Additional Information: Caller Workstation: T100 Target Account Name: Administrator Target Account Domain: T100
Security  Audit Success  13824  2013-11-28 18:57:00    Microsoft-Windows-Security-Auditing  4797: An attempt was made to query the existence of a blank password for an account. Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x24357 Additional Information: Caller Workstation: T100 Target Account Name: Guest Target Account Domain: T100
Security  Audit Success  12544  2013-11-28 19:07:01    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 19:07:01    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 19:09:57    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 19:09:57    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-28 20:05:43    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-28 20:05:43    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-29 02:26:24    Microsoft-Windows-Security-Auditing  4648: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: Transformer T100 Account Domain: T100 Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x288 Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: 127.0.0.1 Port: 0 This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Security  Audit Success  12544  2013-11-29 02:26:24    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 7 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x11247d6 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x288 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: T100 Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-29 02:26:24    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 7 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x11247fd Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x288 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: T100 Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12545  2013-11-29 02:26:24    Microsoft-Windows-Security-Auditing  4634: An account was logged off. Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x11247fd Logon Type: 7 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
Security  Audit Success  12545  2013-11-29 02:26:24    Microsoft-Windows-Security-Auditing  4634: An account was logged off. Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x11247d6 Logon Type: 7 This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
Security  Audit Success  12548  2013-11-29 02:26:24    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-21-510496655-4205887700-2175606355-1001 Account Name: Transformer T100 Account Domain: T100 Logon ID: 0x11247d6 Privileges: SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-29 02:26:41    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-29 02:26:41    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-29 02:26:58    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-29 02:26:58    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-29 02:30:41    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12544  2013-11-29 02:30:41    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-29 02:30:41    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12548  2013-11-29 02:30:41    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-29 02:31:03    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-29 02:31:03    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  13568  2013-11-29 02:31:15    Microsoft-Windows-Security-Auditing  4904: An attempt was made to register a security event source. Subject : Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Process: Process ID: 0x166c Process Name: C:\Windows\System32\VSSVC.exe Event Source: Source Name: VSSAudit Event Source ID: 0x125c246
Security  Audit Success  13568  2013-11-29 02:31:15    Microsoft-Windows-Security-Auditing  4905: An attempt was made to unregister a security event source. Subject Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Process: Process ID: 0x166c Process Name: C:\Windows\System32\VSSVC.exe Event Source: Source Name: VSSAudit Event Source ID: 0x125c246
Security  Audit Success  13568  2013-11-29 02:31:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x848 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:31:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x97c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:31:30    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x96c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:31:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x2cc Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:31:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms Handle ID: 0xb80 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:31:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_a421d1bfaf856e2b.cdf-ms Handle ID: 0x8e4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:31:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x2cc Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:31:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0xb80 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:31:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spp_tokens_ppdlic_0f09ba294211a24b.cdf-ms Handle ID: 0x8e4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:31:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\System32\jscript9diag.dll Handle ID: 0xa48 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-29 02:31:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x132c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:31:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x9d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:31:48    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_1e9f55b2d3f87dd3.cdf-ms Handle ID: 0x61c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:00    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x5b0 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:00    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x6fc Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:00    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x668 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:04    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x17d0 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:04    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0xa70 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:04    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_apppatch_1143992cbbbebcab.cdf-ms Handle ID: 0xb24 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:04    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\apppatch\AcGenral.dll Handle ID: 0x17d0 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:04    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\apppatch\drvmain.sdb Handle ID: 0xef4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:04    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\apppatch\sysmain.sdb Handle ID: 0xc2c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:04    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\apppatch\msimain.sdb Handle ID: 0xb24 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:04    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\apppatch\AcSpecfc.dll Handle ID: 0x854 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: S:AI New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:12    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x9e4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:12    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0xdfc Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:12    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x6ac Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:12    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_fr-fr_448347788202c03b.cdf-ms Handle ID: 0x9e4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:12    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_en-us_429cd25484dc6f94.cdf-ms Handle ID: 0xdfc Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:12    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_es-es_429cd1a084dc7119.cdf-ms Handle ID: 0x6ac Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:12    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-hk_6a84939e4900ccf6.cdf-ms Handle ID: 0x9e4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:32:12    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-cn_6a8499504900c466.cdf-ms Handle ID: 0xdfc Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  12544  2013-11-29 02:33:09    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-29 02:33:09    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  12544  2013-11-29 02:33:10    Microsoft-Windows-Security-Auditing  4624: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 5 Impersonation Level: %%1833 New Logon: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2a8 Process Name: C:\Windows\System32\services.exe Network Information: Workstation Name: Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Advapi Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The impersonation level field indicates the extent to which a process in the logon session can impersonate. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Security  Audit Success  12548  2013-11-29 02:33:10    Microsoft-Windows-Security-Auditing  4672: Special privileges assigned to new logon. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Account Domain: NT AUTHORITY Logon ID: 0x3e7 Privileges: SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms Handle ID: 0x15d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms Handle ID: 0x73c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_mail_e07902f329fe05e9.cdf-ms Handle ID: 0x1d2c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_a421d1bfaf856e2b.cdf-ms Handle ID: 0x15d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_internet_explorer_pris_3635310c72721a09.cdf-ms Handle ID: 0x73c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_media_player_da4e5f6eb3198de9.cdf-ms Handle ID: 0x1d2c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_journal_ada99bf7bc9c9733.cdf-ms Handle ID: 0x15d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_6101456faac5015c.cdf-ms Handle ID: 0x73c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_tabletextservice_9475b2de2d92bc74.cdf-ms Handle ID: 0x1d2c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_nt_accessories_156d2b9b22040474.cdf-ms Handle ID: 0x15d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_d7a65bb2f0e854e7.cdf-ms Handle ID: 0x73c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_818c5a0e45020fba.cdf-ms Handle ID: 0x1d2c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_ink_3c86e3db0b3b254c.cdf-ms Handle ID: 0x15d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_ink_zh-cn_b1fdda05de3132de.cdf-ms Handle ID: 0x73c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_microsoft_shared_msinfo_817ad0c7c1c8e490.cdf-ms Handle ID: 0x1d2c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_b13078daf1286f60.cdf-ms Handle ID: 0x1d3c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ado_149a784bc852a2c0.cdf-ms Handle ID: 0x15d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_msadc_48cda3763ecb3874.cdf-ms Handle ID: 0xb48 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_common_files_system_ole_db_48d1b11cd4e5cabe.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_f89c5a39d351281a.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_a4ba21b6f468ca9e.cdf-ms Handle ID: 0xb48 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_61efdd9e2d0263ca.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.0_44577d982216c291.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.5_44577da22216c264.cdf-ms Handle ID: 0xb48 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_photo_viewer_6eb173d8debcda9a.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\program_files_windows_defender_3e33901162166ae9.cdf-ms Handle ID: 0x1c50 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_04445b88cf0b8e8d.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_winstore_pris_688b1d7050c30cf5.cdf-ms Handle ID: 0xb48 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_servicing_fc2045b9046cc796.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_branding_1728f5d8b15e5263.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_branding_basebrd_9ee9a176c9fadab4.cdf-ms Handle ID: 0xb48 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_3296b36dbe4c7fa3.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_83386eac0379231b.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_5588a81f3fdc44c6.cdf-ms Handle ID: 0xb48 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_wpf_b56a2354fbfa0c31.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_windows_communication_foundation_e07323de19ff1b52.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.5_5588a8293fdc4499.cdf-ms Handle ID: 0xb48 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_e9368840261e60ee.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_c40c7a995ddd757b.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_bc1339ef8efa3c4c.cdf-ms Handle ID: 0xb48 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_app_localresources_84df96316f150d4c.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_providers_app_localresources_7d34f2c02aed6be4.cdf-ms Handle ID: 0x980 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_appconfig_app_localresources_aef413ce2370b549.cdf-ms Handle ID: 0x1c50 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_app_localresources_4620d9e6e73b47b8.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_wizard_app_localresources_6e58d02b006cefe5.cdf-ms Handle ID: 0x980 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_permissions_app_localresources_ac56057a6371bc94.cdf-ms Handle ID: 0x1c50 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_users_app_localresources_1f849782c95d71ca.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_security_roles_app_localresources_8626c43b9128448f.cdf-ms Handle ID: 0x980 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_asp.netwebadminfiles_app_globalresources_adb5dd0528d9b46e.cdf-ms Handle ID: 0x1c50 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_40104b85a18bfcb2.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_boot_resources_0adab7ac98c3dc03.cdf-ms Handle ID: 0x980 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_ime_3f581be9a4c8cabd.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_e6d66275c6e4d14a.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_scheduled_35e98acca7dbf9c7.cdf-ms Handle ID: 0x1c50 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_scheduled_maintenance_6bb1b174b39bb442.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_d78913b7f0741b59.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_usbcore_14d5b24ecc418e9a.cdf-ms Handle ID: 0x1c50 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_networking_29c6b61ce45e9171.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iebrowseweb_e2468f1fdde27cf7.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_printer_22190c3ab8798fd9.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_power_9d457dc1c7c54838.cdf-ms Handle ID: 0x1c50 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_homegroup_1909584eb21c73e3.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_devicecenter_0e1655bf357f4c22.cdf-ms Handle ID: 0x1c50 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_search_9d4b5385ff8f1ef3.cdf-ms Handle ID: 0x182c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerplaydvd_3aa04961f831b79d.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_performance_d48bf95b5c828123.cdf-ms Handle ID: 0x1c50 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_iesecurity_25644a5ef81c9ef5.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsupdate_0862ad88ff233b9d.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayerconfiguration_537e287f67955d9f.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_windowsmediaplayermedialibrary_64611465e9119df8.cdf-ms Handle ID: 0x137c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_device_9d2d754600160183.cdf-ms Handle ID: 0x1c50 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:39    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_audio_9d2751b7c84ca0f1.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_aero_8b2c42561936b3f0.cdf-ms Handle ID: 0x137c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_diagnostics_system_pcw_2115168e47eaddb7.cdf-ms Handle ID: 0x1c50 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_3f581daba4c8c835.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_data_0864fda87da3c851.cdf-ms Handle ID: 0x137c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_d061836896f4f29d.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_bits_0ef6f148bde367d9.cdf-ms Handle ID: 0x1c50 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_oracle_07838adde9419766.cdf-ms Handle ID: 0x1d2c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugthrsvc_9c5b081f28f83f11.cdf-ms Handle ID: 0x137c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_smsvchost_4.0.0.0_13299f3c208ca635.cdf-ms Handle ID: 0x1c50 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_0ef70686e1d9b30c.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_usbhub_299dea1039e75d30.cdf-ms Handle ID: 0x137c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_tapisrv_20c65cafb424239c.cdf-ms Handle ID: 0x1c50 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_data_provider_for_sqlserver_7cfd5f3e72497ce1.cdf-ms Handle ID: 0x12d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_rdyboost_95e76b07334dd353.cdf-ms Handle ID: 0x268 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_termservice_f0fb244350031192.cdf-ms Handle ID: 0x137c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_msdtc_bridge_4.0.0.0_4d0c545c25fa998f.cdf-ms Handle ID: 0x12d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_remoteaccess_110554180baafc8b.cdf-ms Handle ID: 0x182c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_ugatherer_9f1f9c5b6cd50d98.cdf-ms Handle ID: 0x1820 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_esent_0ef70656e1d1b1ac.cdf-ms Handle ID: 0x12d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.net_clr_networking_4.0.0.0_ea306c746014451b.cdf-ms Handle ID: 0x182c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_windows_workflow_foundation_4.0.0.0_60d60271dbee3c46.cdf-ms Handle ID: 0x1820 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_.netframework_266880c2626e99c6.cdf-ms Handle ID: 0x12d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_wsearchidxpi_a2c41dc1731a4204.cdf-ms Handle ID: 0x182c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_inf_pnrpsvc_3932681b8fb41c9d.cdf-ms Handle ID: 0x1820 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_1e6ccf0e6a91b570.cdf-ms Handle ID: 0x12d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_immersivecontrolpanel_pris_a05890fcf353f1d8.cdf-ms Handle ID: 0x182c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_desktoptileresources_b2a801db1c49551f.cdf-ms Handle ID: 0x1820 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_desktoptileresources_pris_fb9b991ef28508b5.cdf-ms Handle ID: 0x12d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_policydefinitions_89130cdfc4d9c27c.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms Handle ID: 0x182c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_oobe_06655c95df2fa06f.cdf-ms Handle ID: 0x12d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migwiz_2650d8d30fee1fe9.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_boot_06654401df2fc50e.cdf-ms Handle ID: 0x182c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_sysprep_f7b45b8dfed1b768.cdf-ms Handle ID: 0x12d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_migration_927a21df1acd7c18.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_e92024d8b2d5d3b6.cdf-ms Handle ID: 0x12c8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_schema_869341856a9aa0c1.cdf-ms Handle ID: 0x1820 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_schema_msft_filedirectoryconfiguration_8324e8f8bda9c0f5.cdf-ms Handle ID: 0x12a8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_baseregistration_f33ccae687b65dda.cdf-ms Handle ID: 0x12d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_registration_fdfcf6ae03636dbf.cdf-ms Handle ID: 0x1820 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_configuration_registration_msft_filedirectoryconfiguration_e425053d94db5fd3.cdf-ms Handle ID: 0x12a8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_dc1b782427b5ee1b.cdf-ms Handle ID: 0x12d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_drivers_umdf_a531b5dc588477d3.cdf-ms Handle ID: 0x1820 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wcn_06656d8dd047aafe.cdf-ms Handle ID: 0x12a8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dism_066548addf2fbd4b.cdf-ms Handle ID: 0x12d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_driverstore_a531a9c6b3dfcf87.cdf-ms Handle ID: 0x1820 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_f1780fdbb7b569a2.cdf-ms Handle ID: 0x12a8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_spool_drivers_w32x86_3_8416c27bd490b8bd.cdf-ms Handle ID: 0x12d4 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms Handle ID: 0x1d2c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_a349059b05097caa.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_tls_36c96f1eb9feecc5.cdf-ms Handle ID: 0x268 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_windowssearch_f5f5bf848a6aa07b.cdf-ms Handle ID: 0x182c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_secureboot_9d07353d2b857be7.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_fff314eba11c101c.cdf-ms Handle ID: 0x704 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_72e61bb83a8f716f.cdf-ms Handle ID: 0x137c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_groupresourc_2cdc5c5e9202d5eb.cdf-ms Handle ID: 0x6dc Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_scriptresour_26725c890cc03aed.cdf-ms Handle ID: 0x704 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_archiveresou_547cec1c740fb34e.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_registryreso_0e42dbd1801c7751.cdf-ms Handle ID: 0x137c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_processresou_21e75bec564f071f.cdf-ms Handle ID: 0x704 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_roleresource_df559ab05daec448.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_serviceresou_0e75aa46c124c33f.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_packageresou_09398e9ab3481d72.cdf-ms Handle ID: 0x6dc Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_logresource_23cbd1e723298208.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_userresource_5f7c55c0edb88acd.cdf-ms Handle ID: 0x1c50 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_psproviders_msft_environmentr_14bf79628283a3a1.cdf-ms Handle ID: 0x980 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_psdesiredstateconfiguration_downloadmanager_dscfiledownlo_53cd0afeb4dff086.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_kds_36c95feeb9ff0384.cdf-ms Handle ID: 0x6dc Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitstransfer_935cce3b0456eb87.cdf-ms Handle ID: 0x980 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_appx_6a827ca1d13e479b.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_bitlocker_a73047ff15e7584f.cdf-ms Handle ID: 0x6dc Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_trustedplatformmodule_1b07dab5874a01a0.cdf-ms Handle ID: 0x980 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_netsecurity_1f2dcf39815a9f67.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_msdtc_6a8283fc51a8e0dd.cdf-ms Handle ID: 0x6dc Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_dism_6a826ed5d13e5ce3.cdf-ms Handle ID: 0x980 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_vpnclient_b543ca3d0a342edf.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_windowspowershell_v1.0_modules_pki_36c96ea0b9feec70.cdf-ms Handle ID: 0x6dc Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_wbem_06656d9fdf2f8577.cdf-ms Handle ID: 0x980 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_systemresetplatform_14fecc2716acccef.cdf-ms Handle ID: 0x182c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_common_8c297630658eaa3d.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_engines_sr_f5f77fb9283237d8.cdf-ms Handle ID: 0x6dc Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_speech_speechux_bf4b53e8d47da913.cdf-ms Handle ID: 0x268 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_dsc_06654725d047e68c.cdf-ms Handle ID: 0x12a8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_com_066545e3d047e7c7.cdf-ms Handle ID: 0x6dc Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_system32_zh-cn_6a8499504900c466.cdf-ms Handle ID: 0x182c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_1e9f55b2d3f87dd3.cdf-ms Handle ID: 0x268 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_camera_pris_7badf1db07b249e7.cdf-ms Handle ID: 0x980 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_reports_a2604845b2b380ca.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_pla_rules_0bde462ce96f215e.cdf-ms Handle ID: 0x268 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_0307ca33e1cd9708.cdf-ms Handle ID: 0x980 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsapp_041d35a886a9ab39.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsapp_pris_5b98fa23432d61fd.cdf-ms Handle ID: 0x268 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingshandlers_5b3af40f40f8bda7.cdf-ms Handle ID: 0x980 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingshandlers_pris_71ec33a38f3576eb.cdf-ms Handle ID: 0x1c5c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_0e66dffb08041cab.cdf-ms Handle ID: 0xb48 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.mediaviewer_pris_b9b6d478276f23e5.cdf-ms Handle ID: 0x1d40 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsadminflowui_704aadb27d9f6f27.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.settingsadminflowui_pris_73f1705cccdeb65b.cdf-ms Handle ID: 0x73c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.search_ed9cc5a2b23bcffb.cdf-ms Handle ID: 0x1d40 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.search_pris_6935df56eeeca635.cdf-ms Handle ID: 0x73c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_6247a388787724b8.cdf-ms Handle ID: 0x1d34 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_systemresources_windows.ui.skydrive_pris_a8c1f2a41196ba80.cdf-ms Handle ID: 0x1d44 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_3b206622a946e834.cdf-ms Handle ID: 0xad8 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_common_76cd6f1aaba6e83b.cdf-ms Handle ID: 0x1d34 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_8a294d630e90192b.cdf-ms Handle ID: 0x1d44 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_speech_engines_tts_4e06b8e5aea05fb6.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_09ec0b99a5045113.cdf-ms Handle ID: 0x1d34 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_pris_f05e2f58ec689435.cdf-ms Handle ID: 0x1d44 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_filemanager_zh-cn_f05e202cc1d8ff87.cdf-ms Handle ID: 0x73c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_fbee56ab048ab239.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_themes_4d0d4910e83c2273.cdf-ms Handle ID: 0x268 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_resources_themes_aero_3fd78bf4cb5fa2c4.cdf-ms Handle ID: 0x1d40 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_dc4f6f92ba7f6fd4.cdf-ms Handle ID: 0x73c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_indexstore_c4411e76b4b68bb5.cdf-ms Handle ID: 0x1d40 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_help_windows_contentstore_8ab00c4ac38e5298.cdf-ms Handle ID: 0x268 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\$$_apppatch_1143992cbbbebcab.cdf-ms Handle ID: 0x1d2c Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_fe5c6d762edd2110.cdf-ms Handle ID: 0x268 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_b4e458a72482d5c6.cdf-ms Handle ID: 0x1d40 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_common_coverpages_642a277e0ccb775c.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:40    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_windows_nt_msfax_virtualinbox_343012079dc9af5d.cdf-ms Handle ID: 0x268 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:41    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_07deb856-fc6e-4fb9-8add-d8f2cf8722c9__0ce7c057892d5774.cdf-ms Handle ID: 0x1d40 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Security  Audit Success  13568  2013-11-29 02:33:41    Microsoft-Windows-Security-Auditing  4907: Auditing settings on object were changed. Subject: Security ID: S-1-5-18 Account Name: T100$ Account Domain: WORKGROUP Logon ID: 0x3e7 Object: Object Server: Security Object Type: File Object Name: C:\Windows\WinSxS\FileMaps\programdata_microsoft_device_stage_task_e35be42d-f742-4d96-a50a-1775fb1a7a42__96ac8d0751fb5c2c.cdf-ms Handle ID: 0x698 Process Information: Process ID: 0x17c4 Process Name: C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_9dff25cfe2e40fa2\TiWorker.exe Auditing Settings: Original Security Descriptor: New Security Descriptor: S:ARAI(AU;SAFA;0x1f0116;;;WD)
System  Warning  1014  2013-11-22 03:06:22  NETWORK SERVICE  Microsoft-Windows-DNS-Client  1014: Name resolution for the name fe2.ws.microsoft.com timed out after none of the configured DNS servers responded.
System  Warning  1014  2013-11-22 05:06:31  NETWORK SERVICE  Microsoft-Windows-DNS-Client  1014: Name resolution for the name fe2.ws.microsoft.com timed out after none of the configured DNS servers responded.
System  Warning  None  2013-11-22 05:54:22  LOCAL SERVICE  Microsoft-Windows-Time-Service  36: The time service has not synchronized the system time for 86400 seconds because none of the time service providers provided a usable time stamp. The time service will not update the local system time until it is able to synchronize with a time source. If the local system is configured to act as a time server for clients, it will stop advertising as a time source to clients. The time service will continue to retry and sync time with its time sources. Check system event log for other W32time events for more details. Run 'w32tm /resync' to force an instant time synchronization.
System  Warning  1014  2013-11-22 07:05:18  NETWORK SERVICE  Microsoft-Windows-DNS-Client  1014: Name resolution for the name sls.update.microsoft.com timed out after none of the configured DNS servers responded.
System  Warning  1014  2013-11-22 09:05:24  NETWORK SERVICE  Microsoft-Windows-DNS-Client  1014: Name resolution for the name sls.update.microsoft.com timed out after none of the configured DNS servers responded.
System  Warning  1014  2013-11-22 11:04:17  NETWORK SERVICE  Microsoft-Windows-DNS-Client  1014: Name resolution for the name sls.update.microsoft.com timed out after none of the configured DNS servers responded.
System  Warning  None  2013-11-28 17:02:15    TXEI  1: Incorrect function.
System  Warning  None  2013-11-28 17:02:15    TXEI  1: Incorrect function.
System  Warning  None  2013-11-28 17:02:16    TXEI  1: Incorrect function.
System  Warning  None  2013-11-28 17:02:16  LOCAL SERVICE  Microsoft-Windows-Time-Service  134: NtpClient was unable to set a manual peer to use as a time source because of DNS resolution error on 'time.windows.com,0x9'. NtpClient will try again in 15 minutes and double the reattempt interval thereafter. The error was: No such host is known. (0x80072AF9)
System  Warning  None  2013-11-28 17:17:16  LOCAL SERVICE  Microsoft-Windows-Time-Service  134: NtpClient was unable to set a manual peer to use as a time source because of DNS resolution error on 'time.windows.com,0x9'. NtpClient will try again in 15 minutes and double the reattempt interval thereafter. The error was: No such host is known. (0x80072AF9)
System  Warning  None  2013-11-28 17:33:08    TXEI  1: Incorrect function.
System  Warning  212  2013-11-28 17:33:12  SYSTEM  Microsoft-Windows-Kernel-PnP  219: The driver \Driver\WudfRd failed to load for the device ACPI\CPLM3218\1.
System  Warning  212  2013-11-28 17:33:12  SYSTEM  Microsoft-Windows-Kernel-PnP  219: The driver \Driver\WudfRd failed to load for the device ACPI\INVN6500\3&35f3e24a&0.
System  Error  None  2013-11-28 17:35:45    EventLog  6008: The previous system shutdown at 17:29:45 on ?2013.?11.?28. was unexpected.
System  Warning  None  2013-11-28 17:35:55  SYSTEM  Microsoft-Windows-WLAN-AutoConfig  10002: WLAN Extensibility Module has stopped. Module Path: C:\Windows\System32\bcmihvsrv.dll
System  Warning  None  2013-11-28 17:36:20    TXEI  1: Incorrect function.
System  Warning  212  2013-11-28 17:36:20  SYSTEM  Microsoft-Windows-Kernel-PnP  219: The driver \Driver\WudfRd failed to load for the device ACPI\CPLM3218\1.
System  Warning  212  2013-11-28 17:36:20  SYSTEM  Microsoft-Windows-Kernel-PnP  219: The driver \Driver\WudfRd failed to load for the device ACPI\INVN6500\3&35f3e24a&0.
System  Error  None  2013-11-28 17:39:37  SYSTEM  DCOM  
System  Error  None  2013-11-28 17:41:37  SYSTEM  DCOM  
System  Error  None  2013-11-28 17:43:37  SYSTEM  DCOM  
System  Error  None  2013-11-28 17:45:37  SYSTEM  DCOM  
System  Error  None  2013-11-28 17:47:37  SYSTEM  DCOM  
System  Error  None  2013-11-28 17:49:37  SYSTEM  DCOM  
System  Error  None  2013-11-28 17:51:37  SYSTEM  DCOM  
System  Error  None  2013-11-28 17:53:37  SYSTEM  DCOM  
System  Error  None  2013-11-28 17:55:37  SYSTEM  DCOM  
System  Error  None  2013-11-28 17:57:37  SYSTEM  DCOM  
System  Error  None  2013-11-28 17:59:37  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:01:37  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:03:37  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:05:37  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:07:37  SYSTEM  DCOM  
System  Warning  None  2013-11-28 18:08:24  SYSTEM  Microsoft-Windows-WLAN-AutoConfig  10002: WLAN Extensibility Module has stopped. Module Path: C:\Windows\System32\bcmihvsrv.dll
System  Warning  None  2013-11-28 18:08:40    TXEI  1: Incorrect function.
System  Warning  212  2013-11-28 18:08:41  SYSTEM  Microsoft-Windows-Kernel-PnP  219: The driver \Driver\WudfRd failed to load for the device ACPI\CPLM3218\1.
System  Warning  212  2013-11-28 18:08:41  SYSTEM  Microsoft-Windows-Kernel-PnP  219: The driver \Driver\WudfRd failed to load for the device ACPI\INVN6500\3&35f3e24a&0.
System  Error  None  2013-11-28 18:11:09  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:13:09  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:15:09  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:17:09  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:19:09  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:21:09  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:23:09  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:25:09  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:27:09  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:29:09  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:31:09  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:31:58    Service Control Manager  7043: The Windows Update service did not shut down properly after receiving a preshutdown control.
System  Error  None  2013-11-28 18:32:30    Service Control Manager  7043: The Windows Modules Installer service did not shut down properly after receiving a preshutdown control.
System  Warning  None  2013-11-28 18:32:31  SYSTEM  Microsoft-Windows-WLAN-AutoConfig  10002: WLAN Extensibility Module has stopped. Module Path: C:\Windows\System32\bcmihvsrv.dll
System  Warning  None  2013-11-28 18:32:48    TXEI  1: Incorrect function.
System  Warning  212  2013-11-28 18:32:48  SYSTEM  Microsoft-Windows-Kernel-PnP  219: The driver \Driver\WudfRd failed to load for the device ACPI\CPLM3218\1.
System  Warning  212  2013-11-28 18:32:48  SYSTEM  Microsoft-Windows-Kernel-PnP  219: The driver \Driver\WudfRd failed to load for the device ACPI\INVN6500\3&35f3e24a&0.
System  Error  None  2013-11-28 18:35:07  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:37:07  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:39:07  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:41:07  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:43:07  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:45:07  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:47:07  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:49:07  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:51:08  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:53:08  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:55:08  SYSTEM  DCOM  
System  Error  None  2013-11-28 18:55:57    Service Control Manager  7043: The Windows Update service did not shut down properly after receiving a preshutdown control.
System  Error  None  2013-11-28 18:56:30    Service Control Manager  7043: The Windows Modules Installer service did not shut down properly after receiving a preshutdown control.
System  Warning  None  2013-11-28 18:56:31  SYSTEM  Microsoft-Windows-WLAN-AutoConfig  10002: WLAN Extensibility Module has stopped. Module Path: C:\Windows\System32\bcmihvsrv.dll
System  Warning  None  2013-11-28 18:56:46    TXEI  1: Incorrect function.
System  Warning  212  2013-11-28 18:56:46  SYSTEM  Microsoft-Windows-Kernel-PnP  219: The driver \Driver\WudfRd failed to load for the device ACPI\CPLM3218\1.
System  Warning  212  2013-11-28 18:56:46  SYSTEM  Microsoft-Windows-Kernel-PnP  219: The driver \Driver\WudfRd failed to load for the device ACPI\INVN6500\3&35f3e24a&0.
System  Error  1  2013-11-28 18:57:10  SYSTEM  Microsoft-Windows-WindowsUpdateClient  20: Installation Failure: Windows failed to install the following update with error 0x800f0841: Update for Windows 8.1 (KB2883200).
System  Warning  2  2013-11-28 19:18:54  SYSTEM  Microsoft-Windows-WindowsUpdateClient  16: Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection.
System  Error  None  2013-11-29 02:27:09  Transformer T100  DCOM  
System  Error  None  2013-11-29 02:31:11  Transformer T100  DCOM  
System  Warning  None  2013-11-29 02:43:45    Tcpip  4230: TCP/IP has chosen to restrict the congestion window for several connections due to a network condition. This could be related to a problem in the TCP global or supplemental configuration and will cause degraded throughput.


Database Software

 
Database Drivers:
Borland Database Engine  -
Borland InterBase Client  -
Easysoft ODBC-InterBase 6  -
Easysoft ODBC-InterBase 7  -
Firebird Client  -
Jet Engine  4.00.9765.0
MDAC  6.3.9600.16384 (winblue_rtm.130821-1623)
ODBC  6.3.9600.16384 (winblue_rtm.130821-1623)
MySQL Connector/ODBC  -
Oracle Client  -
PsqlODBC  -
Sybase ASE ODBC  -
 
Database Servers:
Borland InterBase Server  -
Firebird Server  -
Microsoft SQL Server  -
Microsoft SQL Server Compact Edition  -
Microsoft SQL Server Express Edition  -
MySQL Server  -
Oracle Server  -
PostgreSQL Server  -
Sybase SQL Server  -


ODBC Drivers

 
Driver Description  File Name  Version  File Extensions Supported
Driver da Microsoft para arquivos texto (*.txt; *.csv)  odbcjt32.dll  6.3.9600.16384 (winblue_rtm.130821-1623)  *.,*.asc,*.csv,*.tab,*.txt,*.csv
Driver do Microsoft Access (*.mdb)  odbcjt32.dll  6.3.9600.16384 (winblue_rtm.130821-1623)  *.mdb
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
Driver do Microsoft Excel(*.xls)  odbcjt32.dll  6.3.9600.16384 (winblue_rtm.130821-1623)  *.xls
Driver do Microsoft Paradox (*.db )  odbcjt32.dll  6.3.9600.16384 (winblue_rtm.130821-1623)  *.db
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
Microsoft Access-Treiber (*.mdb)  odbcjt32.dll  6.3.9600.16384 (winblue_rtm.130821-1623)  *.mdb
Microsoft dBase Driver (*.dbf)  odbcjt32.dll  6.3.9600.16384 (winblue_rtm.130821-1623)  *.dbf,*.ndx,*.mdx
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
Microsoft Excel Driver (*.xls)  odbcjt32.dll  6.3.9600.16384 (winblue_rtm.130821-1623)  *.xls
Microsoft Excel-Treiber (*.xls)  odbcjt32.dll  6.3.9600.16384 (winblue_rtm.130821-1623)  *.xls
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
Microsoft Paradox Driver (*.db )  odbcjt32.dll  6.3.9600.16384 (winblue_rtm.130821-1623)  *.db
Microsoft Paradox-Treiber (*.db )  odbcjt32.dll  6.3.9600.16384 (winblue_rtm.130821-1623)  *.db
[ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
Microsoft Text-Treiber (*.txt; *.csv)  odbcjt32.dll  6.3.9600.16384 (winblue_rtm.130821-1623)  *.,*.asc,*.csv,*.tab,*.txt,*.csv
SQL Server  sqlsrv32.dll  6.3.9600.16384 (winblue_rtm.130821-1623)  


Memory Read

 
CPU  CPU Clock  Motherboard  Chipset  Memory  CL-RCD-RP-RAS  Read Speed
6x Core i7-4930K HT  3400 MHz  Gigabyte GA-X79-UD3  X79  Quad DDR3-1866  9-10-9-27 CR2  52561 MB/s
6x Core i7-3960X Extreme HT  3300 MHz  Intel DX79SI  X79  Quad DDR3-1600  9-9-9-24 CR2  45640 MB/s
8x Xeon X5550 HT  2666 MHz  Supermicro X8DTN+  i5520  Triple DDR3-1333  9-9-9-24 CR1  38087 MB/s
8x FX-8350  4000 MHz  Asus M5A99X Evo R2.0  AMD990X  Dual DDR3-1866  9-10-9-27 CR2  26472 MB/s
8x FX-8150  3600 MHz  Asus M5A97  AMD970  Dual DDR3-1866  9-10-9-27 CR2  26305 MB/s
4x Core i7-3770K HT  3500 MHz  MSI Z77A-GD55  Z77 Int.  Dual DDR3-1600  9-9-9-24 CR2  23630 MB/s
4x Xeon E3-1245 v3 HT  3400 MHz  Supermicro X10SAE  C226 Int.  Dual DDR3-1600  11-11-11-28 CR1  23131 MB/s
6x Core i7-990X Extreme HT  3466 MHz  Intel DX58SO2  X58  Triple DDR3-1333  9-9-9-24 CR1  21525 MB/s
4x A10-5800K  3800 MHz  Asus F2A55-M  A55 Int.  Dual DDR3-1866  9-10-9-27 CR2  21522 MB/s
4x Core i7-965 Extreme HT  3200 MHz  Asus P6T Deluxe  X58  Triple DDR3-1333  9-9-9-24 CR1  21426 MB/s
4x A10-6800K  4100 MHz  Gigabyte GA-F2A85X-UP4  A85X Int.  Dual DDR3-2133  9-11-10-27 CR2  21184 MB/s
12x Opteron 2431  2400 MHz  Supermicro H8DI3+-F  SR5690  Unganged Dual DDR2-800R  6-6-6-18 CR1  19981 MB/s
4x Core i7-2600 HT  3400 MHz  Asus P8P67  P67  Dual DDR3-1333  9-9-9-24 CR1  19661 MB/s
8x Opteron 2378  2400 MHz  Tyan Thunder n3600R  nForcePro-3600  Unganged Dual DDR2-800R  6-6-6-18 CR1  19097 MB/s
4x Xeon X3430  2400 MHz  Supermicro X8SIL-F  i3420  Dual DDR3-1333  9-9-9-24 CR1  17907 MB/s
4x A8-3850  2900 MHz  Gigabyte GA-A75M-UD2H  A75 Int.  Dual DDR3-1333  9-9-9-24 CR1  16607 MB/s
6x Phenom II X6 Black 1100T  3300 MHz  Gigabyte GA-890GPA-UD3H v2  AMD890GX Int.  Unganged Dual DDR3-1333  9-9-9-24 CR2  14977 MB/s
8x Opteron 2344 HE  1700 MHz  Supermicro H8DME-2  nForcePro-3600  Unganged Dual DDR2-667R  5-5-5-15 CR1  13835 MB/s
4x Opteron 2210 HE  1800 MHz  Tyan Thunder h2000M  BCM5785  Dual DDR2-600R  5-5-5-15 CR1  12074 MB/s
4x Atom Z3740  1866 MHz  [ TRIAL VERSION ]  BayTrailT Int.  Dual DDR3-1066  8-10-8-32 CR1  11433 MB/s
2x Core i5-650 HT  3200 MHz  Supermicro C7SIM-Q  Q57 Int.  Dual DDR3-1333  9-9-9-24 CR1  11239 MB/s
4x Phenom II X4 Black 940  3000 MHz  Asus M3N78-EM  GeForce8300 Int.  Ganged Dual DDR2-800  5-5-5-18 CR2  10333 MB/s
2x Athlon64 X2 Black 6400+  3200 MHz  MSI K9N SLI Platinum  nForce570SLI  Dual DDR2-800  4-4-4-11 CR1  10142 MB/s
4x Phenom X4 9500  2200 MHz  Asus M3A  AMD770  Ganged Dual DDR2-800  5-5-5-18 CR2  9607 MB/s
4x Core 2 Extreme QX9650  3000 MHz  Gigabyte GA-EP35C-DS3R  P35  Dual DDR3-1066  8-8-8-20 CR2  9005 MB/s
2x Opteron 240  1400 MHz  MSI K8D Master3-133 FS  AMD8100  Dual DDR400R  3-4-4-8 CR1  8395 MB/s
2x Pentium EE 955 HT  3466 MHz  Intel D955XBK  i955X  Dual DDR2-667  4-4-4-11  8078 MB/s
P4EE HT  3733 MHz  Intel SE7230NH1LX  iE7230  Dual DDR2-667  5-5-5-15  7967 MB/s
2x Core 2 Extreme X6800  2933 MHz  Abit AB9  P965  Dual DDR2-800  5-5-5-18 CR2  7838 MB/s
2x Athlon64 X2 4000+  2100 MHz  ASRock ALiveNF7G-HDready  nForce7050-630a Int.  Dual DDR2-700  5-5-5-18 CR2  7572 MB/s
8x Xeon E5462  2800 MHz  Intel S5400SF  i5400  Quad DDR2-640FB  5-5-5-15  7535 MB/s
2x Core 2 Duo P8400  2266 MHz  MSI MegaBook PR201  GM45 Int.  Dual DDR2-667  5-5-5-15  6938 MB/s
4x Core 2 Extreme QX6700  2666 MHz  Intel D975XBX2  i975X  Dual DDR2-667  5-5-5-15  6563 MB/s
2x Atom D2500  1866 MHz  Intel D2500CC  NM10 Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  6320 MB/s
Nano X2 L4350  1600 MHz  VIA EPIA-M900  VX900H Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  6216 MB/s
2x Pentium D 820  2800 MHz  Abit Fatal1ty F-I90HD  RS600 Int.  Dual DDR2-800  5-5-5-18 CR2  6210 MB/s
2x E-350  1600 MHz  ASRock E350M1  A50M Int.  DDR3-1066 SDRAM  8-8-8-20 CR1  6072 MB/s
Athlon64 3200+  2000 MHz  ASRock 939S56-M  SiS756  Dual DDR400  2.5-3-3-8 CR2  6035 MB/s
Celeron 420  1600 MHz  Intel DQ965GF  Q965 Int.  Dual DDR2-667  5-5-5-15  5366 MB/s
2x Core Duo T2500  2000 MHz  Asus N4L-VM DH  i945GT Int.  Dual DDR2-667  5-5-5-15  4826 MB/s
2x Xeon HT  3400 MHz  Intel SE7320SP2  iE7320  Dual DDR333R  2.5-3-3-7  4547 MB/s
P4EE  3466 MHz  ASRock 775Dual-880Pro  PT880Pro  Dual DDR2-400  3-3-3-8 CR2  4387 MB/s
Opteron 248  2200 MHz  MSI K8T Master1-FAR  K8T800  Dual DDR266R  2-3-3-6 CR1  3931 MB/s
Celeron D 326  2533 MHz  ASRock 775Twins-HDTV  RC410 Ext.  DDR2-533 SDRAM  4-4-4-11  3917 MB/s
2x Xeon  3066 MHz  Asus PCH-DL  i875P + PAT  Dual DDR333  2.5-3-3-7  3871 MB/s
Pentium M 730  1600 MHz  AOpen i915Ga-HFS  i915G Int.  Dual DDR2-533  4-4-4-12  3715 MB/s
8x Xeon L5320  1866 MHz  Intel S5000VCL  i5000V  Dual DDR2-533FB  4-4-4-12  3657 MB/s
Atom 230 HT  1600 MHz  Intel D945GCLF  i945GC Int.  DDR2-533 SDRAM  4-4-4-12  3640 MB/s
Nano L2200  1600 MHz  VIA VB8001  CN896 Int.  DDR2-667 SDRAM  5-5-5-15 CR2  3467 MB/s
P4  2400 MHz  Abit SI7  SiSR658  Dual PC1066 RDRAM  -  3413 MB/s
4x Xeon 5140  2333 MHz  Intel S5000VSA  i5000V  Dual DDR2-667FB  5-5-5-15  3328 MB/s
AthlonXP 3200+  2200 MHz  Asus A7N8X-E  nForce2-U400  Dual DDR400  2.5-4-4-8 CR1  2979 MB/s
Sempron 2600+  1600 MHz  ASRock K8NF4G-SATA2  GeForce6100 Int.  DDR400 SDRAM  2.5-3-3-8 CR2  2945 MB/s
P4  2800 MHz  MSI 848P Neo-S  i848P  DDR400 SDRAM  2.5-3-3-8  2903 MB/s
Celeron  2000 MHz  Gigabyte GA-8TRS350MT  RS350 Int.  Dual DDR400  2-2-4-6 CR1  2765 MB/s
P4  1600 MHz  Abit TH7II  i850  Dual PC800 RDRAM  -  2751 MB/s
Celeron 215  1333 MHz  Intel D201GLY  SiS662 Int.  DDR2-533  5-4-4-12  2687 MB/s
Celeron M 320  1300 MHz  DFI 855GME-MGF  i855GME Int.  DDR333 SDRAM  2.5-3-3-7  2462 MB/s
Duron  1600 MHz  MSI KT6V-LSR  KT600  DDR400 SDRAM  3-3-3-8 CR2  1994 MB/s
Efficeon 8600  1000 MHz  ECS 532 Notebook  Efficeon  DDR266 SDRAM    1926 MB/s
Athlon  1400 MHz  PCChips M817LMR  MAGiK1  DDR266 SDRAM  2-2-2-6  1279 MB/s
Duron  600 MHz  Abit KG7-Lite  AMD-760  DDR200R SDRAM  2-2-2-5  1126 MB/s
C7  1500 MHz  VIA EPIA EN  CN700 Int.  DDR2-533 SDRAM  4-4-4-12 CR2  1110 MB/s
2x PIII-E  733 MHz  Tyan Thunder 2500  ServerSet3HE  PC133R SDRAM  3-3-3-6  1047 MB/s
Celeron  1700 MHz  Asus P4B  i845  PC133 SDRAM  3-3-3-6  1042 MB/s
2x PIII-S  1266 MHz  MSI Pro266TD Master-LR  ApolloPro266TD  DDR266 SDRAM  2-3-3-6 CR2  1041 MB/s
AthlonXP 1600+  1400 MHz  Acorp 7KMM1  KM133A Int.  PC133 SDRAM  3-3-3-6  932 MB/s
Crusoe 5800  1000 MHz  ECS A530 DeskNote  Crusoe  DDR266 SDRAM    893 MB/s
Athlon  750 MHz  Epox EP-7KXA  KX133  PC133 SDRAM  3-3-3-6  763 MB/s
C3  1333 MHz  VIA EPIA SP  CN400 Int.  DDR400 SDRAM  3-3-3-8 CR2  695 MB/s
2x PIII  500 MHz  Epox KP6-BS  i440BX  PC100R SDRAM  3-3-3-?  621 MB/s
C3  800 MHz  VIA EPIA  PLE133 Int.  PC133 SDRAM  3-3-3-6  604 MB/s
PIII  450 MHz  Asus P3C-S  i820  PC600 RDRAM  -  525 MB/s
2x PII  333 MHz  Intel DK440LX  i440LX  PC66 SDRAM  3-2-2-?  371 MB/s
Celeron  266 MHz  Epox P2-100B  ApolloPro  PC66 SDRAM  3-2-2-5  360 MB/s
K6-III  400 MHz  Epox EP-MVP3G-M  MVP3  PC100 SDRAM  2-2-2-5  262 MB/s
2x PentiumPro  200 MHz  Compaq ProLiant 800  i440FX  Dual EDO  -  259 MB/s
2x PentiumMMX  200 MHz  Gigabyte GA-586DX  i430HX  Dual EDO  -  231 MB/s
Pentium  166 MHz  Asus TX97-X  i430TX  PC66 SDRAM  2-2-3-4  228 MB/s
K5 PR166  116 MHz  Asus P5A  ALADDiN5  PC66 SDRAM  2-2-2-6  167 MB/s
K6-2  333 MHz  Amptron PM-9100LMR  SiS5597 Ext.  PC66 SDRAM  3-3-3-6  149 MB/s
Celeron  700 MHz  PCChips M758LT  SiS630ET Int.  PC100 SDRAM  3-3-3-6  116 MB/s
MediaGXm  233 MHz  ALD NPC6836  Cx5520  PC60 SDRAM  3-3-3-6  112 MB/s


Memory Write

 
CPU  CPU Clock  Motherboard  Chipset  Memory  CL-RCD-RP-RAS  Write Speed
6x Core i7-4930K HT  3400 MHz  Gigabyte GA-X79-UD3  X79  Quad DDR3-1866  9-10-9-27 CR2  53221 MB/s
6x Core i7-3960X Extreme HT  3300 MHz  Intel DX79SI  X79  Quad DDR3-1600  9-9-9-24 CR2  46057 MB/s
8x Xeon X5550 HT  2666 MHz  Supermicro X8DTN+  i5520  Triple DDR3-1333  9-9-9-24 CR1  27407 MB/s
4x Core i7-3770K HT  3500 MHz  MSI Z77A-GD55  Z77 Int.  Dual DDR3-1600  9-9-9-24 CR2  24109 MB/s
4x Xeon E3-1245 v3 HT  3400 MHz  Supermicro X10SAE  C226 Int.  Dual DDR3-1600  11-11-11-28 CR1  23244 MB/s
4x Core i7-2600 HT  3400 MHz  Asus P8P67  P67  Dual DDR3-1333  9-9-9-24 CR1  19334 MB/s
8x FX-8150  3600 MHz  Asus M5A97  AMD970  Dual DDR3-1866  9-10-9-27 CR2  18145 MB/s
8x FX-8350  4000 MHz  Asus M5A99X Evo R2.0  AMD990X  Dual DDR3-1866  9-10-9-27 CR2  17573 MB/s
4x Core i7-965 Extreme HT  3200 MHz  Asus P6T Deluxe  X58  Triple DDR3-1333  9-9-9-24 CR1  17100 MB/s
6x Core i7-990X Extreme HT  3466 MHz  Intel DX58SO2  X58  Triple DDR3-1333  9-9-9-24 CR1  16692 MB/s
12x Opteron 2431  2400 MHz  Supermicro H8DI3+-F  SR5690  Unganged Dual DDR2-800R  6-6-6-18 CR1  14910 MB/s
4x A8-3850  2900 MHz  Gigabyte GA-A75M-UD2H  A75 Int.  Dual DDR3-1333  9-9-9-24 CR1  14814 MB/s
4x Xeon X3430  2400 MHz  Supermicro X8SIL-F  i3420  Dual DDR3-1333  9-9-9-24 CR1  13225 MB/s
8x Opteron 2378  2400 MHz  Tyan Thunder n3600R  nForcePro-3600  Unganged Dual DDR2-800R  6-6-6-18 CR1  12788 MB/s
4x A10-6800K  4100 MHz  Gigabyte GA-F2A85X-UP4  A85X Int.  Dual DDR3-2133  9-11-10-27 CR2  10444 MB/s
4x A10-5800K  3800 MHz  Asus F2A55-M  A55 Int.  Dual DDR3-1866  9-10-9-27 CR2  10109 MB/s
2x Core i5-650 HT  3200 MHz  Supermicro C7SIM-Q  Q57 Int.  Dual DDR3-1333  9-9-9-24 CR1  9971 MB/s
8x Opteron 2344 HE  1700 MHz  Supermicro H8DME-2  nForcePro-3600  Unganged Dual DDR2-667R  5-5-5-15 CR1  8909 MB/s
2x Athlon64 X2 Black 6400+  3200 MHz  MSI K9N SLI Platinum  nForce570SLI  Dual DDR2-800  4-4-4-11 CR1  8867 MB/s
4x Atom Z3740  1866 MHz  [ TRIAL VERSION ]  BayTrailT Int.  Dual DDR3-1066  8-10-8-32 CR1  8307 MB/s
4x Opteron 2210 HE  1800 MHz  Tyan Thunder h2000M  BCM5785  Dual DDR2-600R  5-5-5-15 CR1  7833 MB/s
Nano X2 L4350  1600 MHz  VIA EPIA-M900  VX900H Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  7526 MB/s
6x Phenom II X6 Black 1100T  3300 MHz  Gigabyte GA-890GPA-UD3H v2  AMD890GX Int.  Unganged Dual DDR3-1333  9-9-9-24 CR2  7443 MB/s
4x Phenom II X4 Black 940  3000 MHz  Asus M3N78-EM  GeForce8300 Int.  Ganged Dual DDR2-800  5-5-5-18 CR2  7104 MB/s
4x Core 2 Extreme QX9650  3000 MHz  Gigabyte GA-EP35C-DS3R  P35  Dual DDR3-1066  8-8-8-20 CR2  7097 MB/s
8x Xeon E5462  2800 MHz  Intel S5400SF  i5400  Quad DDR2-640FB  5-5-5-15  6712 MB/s
2x Pentium EE 955 HT  3466 MHz  Intel D955XBK  i955X  Dual DDR2-667  4-4-4-11  5663 MB/s
P4EE HT  3733 MHz  Intel SE7230NH1LX  iE7230  Dual DDR2-667  5-5-5-15  5651 MB/s
2x Athlon64 X2 4000+  2100 MHz  ASRock ALiveNF7G-HDready  nForce7050-630a Int.  Dual DDR2-700  5-5-5-18 CR2  5641 MB/s
4x Phenom X4 9500  2200 MHz  Asus M3A  AMD770  Ganged Dual DDR2-800  5-5-5-18 CR2  5633 MB/s
2x Core 2 Duo P8400  2266 MHz  MSI MegaBook PR201  GM45 Int.  Dual DDR2-667  5-5-5-15  5471 MB/s
P4EE  3466 MHz  ASRock 775Dual-880Pro  PT880Pro  Dual DDR2-400  3-3-3-8 CR2  5432 MB/s
2x Core 2 Extreme X6800  2933 MHz  Abit AB9  P965  Dual DDR2-800  5-5-5-18 CR2  4875 MB/s
4x Core 2 Extreme QX6700  2666 MHz  Intel D975XBX2  i975X  Dual DDR2-667  5-5-5-15  4832 MB/s
2x Atom D2500  1866 MHz  Intel D2500CC  NM10 Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  4714 MB/s
2x Pentium D 820  2800 MHz  Abit Fatal1ty F-I90HD  RS600 Int.  Dual DDR2-800  5-5-5-18 CR2  4260 MB/s
2x Xeon HT  3400 MHz  Intel SE7320SP2  iE7320  Dual DDR333R  2.5-3-3-7  4233 MB/s
2x E-350  1600 MHz  ASRock E350M1  A50M Int.  DDR3-1066 SDRAM  8-8-8-20 CR1  4162 MB/s
Athlon64 3200+  2000 MHz  ASRock 939S56-M  SiS756  Dual DDR400  2.5-3-3-8 CR2  4106 MB/s
2x Opteron 240  1400 MHz  MSI K8D Master3-133 FS  AMD8100  Dual DDR400R  3-4-4-8 CR1  4050 MB/s
Opteron 248  2200 MHz  MSI K8T Master1-FAR  K8T800  Dual DDR266R  2-3-3-6 CR1  3823 MB/s
Celeron 420  1600 MHz  Intel DQ965GF  Q965 Int.  Dual DDR2-667  5-5-5-15  3589 MB/s
2x Core Duo T2500  2000 MHz  Asus N4L-VM DH  i945GT Int.  Dual DDR2-667  5-5-5-15  3553 MB/s
Nano L2200  1600 MHz  VIA VB8001  CN896 Int.  DDR2-667 SDRAM  5-5-5-15 CR2  3163 MB/s
AthlonXP 3200+  2200 MHz  Asus A7N8X-E  nForce2-U400  Dual DDR400  2.5-4-4-8 CR1  3119 MB/s
P4  2800 MHz  MSI 848P Neo-S  i848P  DDR400 SDRAM  2.5-3-3-8  2886 MB/s
P4  2400 MHz  Abit SI7  SiSR658  Dual PC1066 RDRAM  -  2845 MB/s
2x Xeon  3066 MHz  Asus PCH-DL  i875P + PAT  Dual DDR333  2.5-3-3-7  2838 MB/s
Pentium M 730  1600 MHz  AOpen i915Ga-HFS  i915G Int.  Dual DDR2-533  4-4-4-12  2837 MB/s
Atom 230 HT  1600 MHz  Intel D945GCLF  i945GC Int.  DDR2-533 SDRAM  4-4-4-12  2836 MB/s
Celeron D 326  2533 MHz  ASRock 775Twins-HDTV  RC410 Ext.  DDR2-533 SDRAM  4-4-4-11  2813 MB/s
4x Xeon 5140  2333 MHz  Intel S5000VSA  i5000V  Dual DDR2-667FB  5-5-5-15  2484 MB/s
Sempron 2600+  1600 MHz  ASRock K8NF4G-SATA2  GeForce6100 Int.  DDR400 SDRAM  2.5-3-3-8 CR2  2364 MB/s
8x Xeon L5320  1866 MHz  Intel S5000VCL  i5000V  Dual DDR2-533FB  4-4-4-12  2330 MB/s
Celeron  2000 MHz  Gigabyte GA-8TRS350MT  RS350 Int.  Dual DDR400  2-2-4-6 CR1  2151 MB/s
P4  1600 MHz  Abit TH7II  i850  Dual PC800 RDRAM  -  2134 MB/s
Celeron M 320  1300 MHz  DFI 855GME-MGF  i855GME Int.  DDR333 SDRAM  2.5-3-3-7  2134 MB/s
Duron  1600 MHz  MSI KT6V-LSR  KT600  DDR400 SDRAM  3-3-3-8 CR2  1944 MB/s
Celeron 215  1333 MHz  Intel D201GLY  SiS662 Int.  DDR2-533  5-4-4-12  1882 MB/s
C7  1500 MHz  VIA EPIA EN  CN700 Int.  DDR2-533 SDRAM  4-4-4-12 CR2  1590 MB/s
Athlon  1400 MHz  PCChips M817LMR  MAGiK1  DDR266 SDRAM  2-2-2-6  1323 MB/s
Duron  600 MHz  Abit KG7-Lite  AMD-760  DDR200R SDRAM  2-2-2-5  1194 MB/s
C3  1333 MHz  VIA EPIA SP  CN400 Int.  DDR400 SDRAM  3-3-3-8 CR2  1047 MB/s
2x PIII-S  1266 MHz  MSI Pro266TD Master-LR  ApolloPro266TD  DDR266 SDRAM  2-3-3-6 CR2  1040 MB/s
Celeron  1700 MHz  Asus P4B  i845  PC133 SDRAM  3-3-3-6  1040 MB/s
Athlon  750 MHz  Epox EP-7KXA  KX133  PC133 SDRAM  3-3-3-6  1026 MB/s
AthlonXP 1600+  1400 MHz  Acorp 7KMM1  KM133A Int.  PC133 SDRAM  3-3-3-6  943 MB/s
2x PIII-E  733 MHz  Tyan Thunder 2500  ServerSet3HE  PC133R SDRAM  3-3-3-6  840 MB/s
2x PIII  500 MHz  Epox KP6-BS  i440BX  PC100R SDRAM  3-3-3-?  769 MB/s
PIII  450 MHz  Asus P3C-S  i820  PC600 RDRAM  -  752 MB/s
Efficeon 8600  1000 MHz  ECS 532 Notebook  Efficeon  DDR266 SDRAM    751 MB/s
Crusoe 5800  1000 MHz  ECS A530 DeskNote  Crusoe  DDR266 SDRAM    355 MB/s
2x PII  333 MHz  Intel DK440LX  i440LX  PC66 SDRAM  3-2-2-?  213 MB/s
C3  800 MHz  VIA EPIA  PLE133 Int.  PC133 SDRAM  3-3-3-6  181 MB/s
2x PentiumMMX  200 MHz  Gigabyte GA-586DX  i430HX  Dual EDO  -  177 MB/s
Celeron  700 MHz  PCChips M758LT  SiS630ET Int.  PC100 SDRAM  3-3-3-6  171 MB/s
Pentium  166 MHz  Asus TX97-X  i430TX  PC66 SDRAM  2-2-3-4  149 MB/s
Celeron  266 MHz  Epox P2-100B  ApolloPro  PC66 SDRAM  3-2-2-5  139 MB/s
K6-III  400 MHz  Epox EP-MVP3G-M  MVP3  PC100 SDRAM  2-2-2-5  126 MB/s
2x PentiumPro  200 MHz  Compaq ProLiant 800  i440FX  Dual EDO  -  87 MB/s
K6-2  333 MHz  Amptron PM-9100LMR  SiS5597 Ext.  PC66 SDRAM  3-3-3-6  76 MB/s
MediaGXm  233 MHz  ALD NPC6836  Cx5520  PC60 SDRAM  3-3-3-6  70 MB/s
K5 PR166  116 MHz  Asus P5A  ALADDiN5  PC66 SDRAM  2-2-2-6  65 MB/s


Memory Copy

 
CPU  CPU Clock  Motherboard  Chipset  Memory  CL-RCD-RP-RAS  Copy Speed
6x Core i7-4930K HT  3400 MHz  Gigabyte GA-X79-UD3  X79  Quad DDR3-1866  9-10-9-27 CR2  50540 MB/s
6x Core i7-3960X Extreme HT  3300 MHz  Intel DX79SI  X79  Quad DDR3-1600  9-9-9-24 CR2  42756 MB/s
8x Xeon X5550 HT  2666 MHz  Supermicro X8DTN+  i5520  Triple DDR3-1333  9-9-9-24 CR1  35029 MB/s
6x Core i7-990X Extreme HT  3466 MHz  Intel DX58SO2  X58  Triple DDR3-1333  9-9-9-24 CR1  24271 MB/s
8x FX-8150  3600 MHz  Asus M5A97  AMD970  Dual DDR3-1866  9-10-9-27 CR2  23088 MB/s
4x Core i7-3770K HT  3500 MHz  MSI Z77A-GD55  Z77 Int.  Dual DDR3-1600  9-9-9-24 CR2  22890 MB/s
8x FX-8350  4000 MHz  Asus M5A99X Evo R2.0  AMD990X  Dual DDR3-1866  9-10-9-27 CR2  22344 MB/s
4x Core i7-965 Extreme HT  3200 MHz  Asus P6T Deluxe  X58  Triple DDR3-1333  9-9-9-24 CR1  21465 MB/s
4x Xeon E3-1245 v3 HT  3400 MHz  Supermicro X10SAE  C226 Int.  Dual DDR3-1600  11-11-11-28 CR1  20969 MB/s
4x A10-6800K  4100 MHz  Gigabyte GA-F2A85X-UP4  A85X Int.  Dual DDR3-2133  9-11-10-27 CR2  18377 MB/s
4x A10-5800K  3800 MHz  Asus F2A55-M  A55 Int.  Dual DDR3-1866  9-10-9-27 CR2  18034 MB/s
4x Core i7-2600 HT  3400 MHz  Asus P8P67  P67  Dual DDR3-1333  9-9-9-24 CR1  17426 MB/s
12x Opteron 2431  2400 MHz  Supermicro H8DI3+-F  SR5690  Unganged Dual DDR2-800R  6-6-6-18 CR1  17403 MB/s
8x Opteron 2378  2400 MHz  Tyan Thunder n3600R  nForcePro-3600  Unganged Dual DDR2-800R  6-6-6-18 CR1  17395 MB/s
4x Xeon X3430  2400 MHz  Supermicro X8SIL-F  i3420  Dual DDR3-1333  9-9-9-24 CR1  15611 MB/s
2x Core i5-650 HT  3200 MHz  Supermicro C7SIM-Q  Q57 Int.  Dual DDR3-1333  9-9-9-24 CR1  13979 MB/s
4x A8-3850  2900 MHz  Gigabyte GA-A75M-UD2H  A75 Int.  Dual DDR3-1333  9-9-9-24 CR1  13950 MB/s
6x Phenom II X6 Black 1100T  3300 MHz  Gigabyte GA-890GPA-UD3H v2  AMD890GX Int.  Unganged Dual DDR3-1333  9-9-9-24 CR2  13272 MB/s
8x Opteron 2344 HE  1700 MHz  Supermicro H8DME-2  nForcePro-3600  Unganged Dual DDR2-667R  5-5-5-15 CR1  12982 MB/s
4x Opteron 2210 HE  1800 MHz  Tyan Thunder h2000M  BCM5785  Dual DDR2-600R  5-5-5-15 CR1  9969 MB/s
4x Phenom II X4 Black 940  3000 MHz  Asus M3N78-EM  GeForce8300 Int.  Ganged Dual DDR2-800  5-5-5-18 CR2  9690 MB/s
4x Atom Z3740  1866 MHz  [ TRIAL VERSION ]  BayTrailT Int.  Dual DDR3-1066  8-10-8-32 CR1  9602 MB/s
2x Athlon64 X2 Black 6400+  3200 MHz  MSI K9N SLI Platinum  nForce570SLI  Dual DDR2-800  4-4-4-11 CR1  9015 MB/s
4x Phenom X4 9500  2200 MHz  Asus M3A  AMD770  Ganged Dual DDR2-800  5-5-5-18 CR2  8522 MB/s
8x Xeon E5462  2800 MHz  Intel S5400SF  i5400  Quad DDR2-640FB  5-5-5-15  8006 MB/s
4x Core 2 Extreme QX9650  3000 MHz  Gigabyte GA-EP35C-DS3R  P35  Dual DDR3-1066  8-8-8-20 CR2  7378 MB/s
2x Athlon64 X2 4000+  2100 MHz  ASRock ALiveNF7G-HDready  nForce7050-630a Int.  Dual DDR2-700  5-5-5-18 CR2  6997 MB/s
2x Opteron 240  1400 MHz  MSI K8D Master3-133 FS  AMD8100  Dual DDR400R  3-4-4-8 CR1  6816 MB/s
2x Pentium EE 955 HT  3466 MHz  Intel D955XBK  i955X  Dual DDR2-667  4-4-4-11  6356 MB/s
P4EE HT  3733 MHz  Intel SE7230NH1LX  iE7230  Dual DDR2-667  5-5-5-15  6292 MB/s
Nano X2 L4350  1600 MHz  VIA EPIA-M900  VX900H Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  5778 MB/s
2x Core 2 Extreme X6800  2933 MHz  Abit AB9  P965  Dual DDR2-800  5-5-5-18 CR2  5537 MB/s
2x Core 2 Duo P8400  2266 MHz  MSI MegaBook PR201  GM45 Int.  Dual DDR2-667  5-5-5-15  5476 MB/s
4x Core 2 Extreme QX6700  2666 MHz  Intel D975XBX2  i975X  Dual DDR2-667  5-5-5-15  5292 MB/s
2x E-350  1600 MHz  ASRock E350M1  A50M Int.  DDR3-1066 SDRAM  8-8-8-20 CR1  4995 MB/s
2x Pentium D 820  2800 MHz  Abit Fatal1ty F-I90HD  RS600 Int.  Dual DDR2-800  5-5-5-18 CR2  4922 MB/s
2x Atom D2500  1866 MHz  Intel D2500CC  NM10 Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  4825 MB/s
Athlon64 3200+  2000 MHz  ASRock 939S56-M  SiS756  Dual DDR400  2.5-3-3-8 CR2  4564 MB/s
2x Xeon HT  3400 MHz  Intel SE7320SP2  iE7320  Dual DDR333R  2.5-3-3-7  4277 MB/s
Celeron 420  1600 MHz  Intel DQ965GF  Q965 Int.  Dual DDR2-667  5-5-5-15  4195 MB/s
2x Core Duo T2500  2000 MHz  Asus N4L-VM DH  i945GT Int.  Dual DDR2-667  5-5-5-15  3968 MB/s
P4EE  3466 MHz  ASRock 775Dual-880Pro  PT880Pro  Dual DDR2-400  3-3-3-8 CR2  3955 MB/s
Opteron 248  2200 MHz  MSI K8T Master1-FAR  K8T800  Dual DDR266R  2-3-3-6 CR1  3803 MB/s
Nano L2200  1600 MHz  VIA VB8001  CN896 Int.  DDR2-667 SDRAM  5-5-5-15 CR2  3376 MB/s
2x Xeon  3066 MHz  Asus PCH-DL  i875P + PAT  Dual DDR333  2.5-3-3-7  3206 MB/s
Celeron D 326  2533 MHz  ASRock 775Twins-HDTV  RC410 Ext.  DDR2-533 SDRAM  4-4-4-11  3201 MB/s
Atom 230 HT  1600 MHz  Intel D945GCLF  i945GC Int.  DDR2-533 SDRAM  4-4-4-12  3072 MB/s
AthlonXP 3200+  2200 MHz  Asus A7N8X-E  nForce2-U400  Dual DDR400  2.5-4-4-8 CR1  3026 MB/s
8x Xeon L5320  1866 MHz  Intel S5000VCL  i5000V  Dual DDR2-533FB  4-4-4-12  2992 MB/s
4x Xeon 5140  2333 MHz  Intel S5000VSA  i5000V  Dual DDR2-667FB  5-5-5-15  2984 MB/s
Pentium M 730  1600 MHz  AOpen i915Ga-HFS  i915G Int.  Dual DDR2-533  4-4-4-12  2981 MB/s
P4  2400 MHz  Abit SI7  SiSR658  Dual PC1066 RDRAM  -  2706 MB/s
Sempron 2600+  1600 MHz  ASRock K8NF4G-SATA2  GeForce6100 Int.  DDR400 SDRAM  2.5-3-3-8 CR2  2610 MB/s
P4  2800 MHz  MSI 848P Neo-S  i848P  DDR400 SDRAM  2.5-3-3-8  2595 MB/s
P4  1600 MHz  Abit TH7II  i850  Dual PC800 RDRAM  -  2206 MB/s
Celeron  2000 MHz  Gigabyte GA-8TRS350MT  RS350 Int.  Dual DDR400  2-2-4-6 CR1  2186 MB/s
Celeron 215  1333 MHz  Intel D201GLY  SiS662 Int.  DDR2-533  5-4-4-12  2162 MB/s
Celeron M 320  1300 MHz  DFI 855GME-MGF  i855GME Int.  DDR333 SDRAM  2.5-3-3-7  2089 MB/s
Duron  1600 MHz  MSI KT6V-LSR  KT600  DDR400 SDRAM  3-3-3-8 CR2  1949 MB/s
C7  1500 MHz  VIA EPIA EN  CN700 Int.  DDR2-533 SDRAM  4-4-4-12 CR2  1259 MB/s
Athlon  1400 MHz  PCChips M817LMR  MAGiK1  DDR266 SDRAM  2-2-2-6  1253 MB/s
Duron  600 MHz  Abit KG7-Lite  AMD-760  DDR200R SDRAM  2-2-2-5  1175 MB/s
Celeron  1700 MHz  Asus P4B  i845  PC133 SDRAM  3-3-3-6  1024 MB/s
2x PIII-S  1266 MHz  MSI Pro266TD Master-LR  ApolloPro266TD  DDR266 SDRAM  2-3-3-6 CR2  1022 MB/s
AthlonXP 1600+  1400 MHz  Acorp 7KMM1  KM133A Int.  PC133 SDRAM  3-3-3-6  942 MB/s
2x PIII-E  733 MHz  Tyan Thunder 2500  ServerSet3HE  PC133R SDRAM  3-3-3-6  915 MB/s
Athlon  750 MHz  Epox EP-7KXA  KX133  PC133 SDRAM  3-3-3-6  854 MB/s
C3  1333 MHz  VIA EPIA SP  CN400 Int.  DDR400 SDRAM  3-3-3-8 CR2  743 MB/s
Efficeon 8600  1000 MHz  ECS 532 Notebook  Efficeon  DDR266 SDRAM    662 MB/s
PIII  450 MHz  Asus P3C-S  i820  PC600 RDRAM  -  580 MB/s
2x PIII  500 MHz  Epox KP6-BS  i440BX  PC100R SDRAM  3-3-3-?  549 MB/s
Crusoe 5800  1000 MHz  ECS A530 DeskNote  Crusoe  DDR266 SDRAM    488 MB/s
C3  800 MHz  VIA EPIA  PLE133 Int.  PC133 SDRAM  3-3-3-6  241 MB/s
2x PII  333 MHz  Intel DK440LX  i440LX  PC66 SDRAM  3-2-2-?  222 MB/s
2x PentiumMMX  200 MHz  Gigabyte GA-586DX  i430HX  Dual EDO  -  198 MB/s
Pentium  166 MHz  Asus TX97-X  i430TX  PC66 SDRAM  2-2-3-4  181 MB/s
K6-III  400 MHz  Epox EP-MVP3G-M  MVP3  PC100 SDRAM  2-2-2-5  160 MB/s
Celeron  266 MHz  Epox P2-100B  ApolloPro  PC66 SDRAM  3-2-2-5  142 MB/s
Celeron  700 MHz  PCChips M758LT  SiS630ET Int.  PC100 SDRAM  3-3-3-6  139 MB/s
2x PentiumPro  200 MHz  Compaq ProLiant 800  i440FX  Dual EDO  -  132 MB/s
K6-2  333 MHz  Amptron PM-9100LMR  SiS5597 Ext.  PC66 SDRAM  3-3-3-6  100 MB/s
MediaGXm  233 MHz  ALD NPC6836  Cx5520  PC60 SDRAM  3-3-3-6  85 MB/s
K5 PR166  116 MHz  Asus P5A  ALADDiN5  PC66 SDRAM  2-2-2-6  81 MB/s


Memory Latency

 
CPU  CPU Clock  Motherboard  Chipset  Memory  CL-RCD-RP-RAS  Latency
Athlon64 X2 Black 6400+  3200 MHz  MSI K9N SLI Platinum  nForce570SLI  Dual DDR2-800  4-4-4-11 CR1  54.9 ns
Core i7-3770K  3500 MHz  MSI Z77A-GD55  Z77 Int.  Dual DDR3-1600  9-9-9-24 CR2  57.6 ns
Xeon E3-1245 v3  3400 MHz  Supermicro X10SAE  C226 Int.  Dual DDR3-1600  11-11-11-28 CR1  58.6 ns
A10-6800K  4100 MHz  Gigabyte GA-F2A85X-UP4  A85X Int.  Dual DDR3-2133  9-11-10-27 CR2  59.6 ns
FX-8150  3600 MHz  Asus M5A97  AMD970  Dual DDR3-1866  9-10-9-27 CR2  61.0 ns
FX-8350  4000 MHz  Asus M5A99X Evo R2.0  AMD990X  Dual DDR3-1866  9-10-9-27 CR2  61.3 ns
A10-5800K  3800 MHz  Asus F2A55-M  A55 Int.  Dual DDR3-1866  9-10-9-27 CR2  62.0 ns
Core i7-4930K  3400 MHz  Gigabyte GA-X79-UD3  X79  Quad DDR3-1866  9-10-9-27 CR2  62.0 ns
Core i7-965 Extreme  3200 MHz  Asus P6T Deluxe  X58  Triple DDR3-1333  9-9-9-24 CR1  62.7 ns
Core i7-2600  3400 MHz  Asus P8P67  P67  Dual DDR3-1333  9-9-9-24 CR1  66.5 ns
Core i7-990X Extreme  3466 MHz  Intel DX58SO2  X58  Triple DDR3-1333  9-9-9-24 CR1  66.8 ns
Core i7-3960X Extreme  3300 MHz  Intel DX79SI  X79  Quad DDR3-1600  9-9-9-24 CR2  67.3 ns
Xeon X3430  2400 MHz  Supermicro X8SIL-F  i3420  Dual DDR3-1333  9-9-9-24 CR1  69.2 ns
Xeon X5550  2666 MHz  Supermicro X8DTN+  i5520  Triple DDR3-1333  9-9-9-24 CR1  69.8 ns
Phenom II X6 Black 1100T  3300 MHz  Gigabyte GA-890GPA-UD3H v2  AMD890GX Int.  Unganged Dual DDR3-1333  9-9-9-24 CR2  69.9 ns
Athlon64 3200+  2000 MHz  ASRock 939S56-M  SiS756  Dual DDR400  2.5-3-3-8 CR2  71.9 ns
Phenom II X4 Black 940  3000 MHz  Asus M3N78-EM  GeForce8300 Int.  Ganged Dual DDR2-800  5-5-5-18 CR2  75.5 ns
A8-3850  2900 MHz  Gigabyte GA-A75M-UD2H  A75 Int.  Dual DDR3-1333  9-9-9-24 CR1  75.8 ns
Sempron 2600+  1600 MHz  ASRock K8NF4G-SATA2  GeForce6100 Int.  DDR400 SDRAM  2.5-3-3-8 CR2  76.2 ns
Athlon64 X2 4000+  2100 MHz  ASRock ALiveNF7G-HDready  nForce7050-630a Int.  Dual DDR2-700  5-5-5-18 CR2  76.9 ns
Pentium EE 955  3466 MHz  Intel D955XBK  i955X  Dual DDR2-667  4-4-4-11  78.1 ns
Core 2 Extreme X6800  2933 MHz  Abit AB9  P965  Dual DDR2-800  5-5-5-18 CR2  79.6 ns
Xeon E5-2670  2600 MHz  Supermicro X9DR6-F  C600  Quad DDR3-1333  9-9-9-24  80.2 ns
Core 2 Extreme QX6700  2666 MHz  Intel D975XBX2  i975X  Dual DDR2-667  5-5-5-15  80.9 ns
P4EE  3733 MHz  Intel SE7230NH1LX  iE7230  Dual DDR2-667  5-5-5-15  82.1 ns
Opteron 248  2200 MHz  MSI K8T Master1-FAR  K8T800  Dual DDR266R  2-3-3-6 CR1  87.3 ns
Opteron 6274  2200 MHz  Supermicro H8DGI-F  SR5690  Dual DDR3-1600R  11-11-11-28 CR1  87.7 ns
Opteron 240  1400 MHz  MSI K8D Master3-133 FS  AMD8100  Dual DDR400R  3-4-4-8 CR1  89.0 ns
Core 2 Extreme QX9650  3000 MHz  Gigabyte GA-EP35C-DS3R  P35  Dual DDR3-1066  8-8-8-20 CR2  90.9 ns
Atom D2500  1866 MHz  Intel D2500CC  NM10 Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  93.1 ns
AthlonXP 3200+  2200 MHz  Asus A7N8X-E  nForce2-U400  Dual DDR400  2.5-4-4-8 CR1  93.3 ns
Opteron 2378  2400 MHz  Tyan Thunder n3600R  nForcePro-3600  Unganged Dual DDR2-800R  6-6-6-18 CR1  95.2 ns
Core i5-650  3200 MHz  Supermicro C7SIM-Q  Q57 Int.  Dual DDR3-1333  9-9-9-24 CR1  95.4 ns
Celeron 420  1600 MHz  Intel DQ965GF  Q965 Int.  Dual DDR2-667  5-5-5-15  99.3 ns
Core 2 Duo P8400  2266 MHz  MSI MegaBook PR201  GM45 Int.  Dual DDR2-667  5-5-5-15  101.0 ns
Pentium D 820  2800 MHz  Abit Fatal1ty F-I90HD  RS600 Int.  Dual DDR2-800  5-5-5-18 CR2  103.0 ns
Atom 230  1600 MHz  Intel D945GCLF  i945GC Int.  DDR2-533 SDRAM  4-4-4-12  104.8 ns
E-350  1600 MHz  ASRock E350M1  A50M Int.  DDR3-1066 SDRAM  8-8-8-20 CR1  107.4 ns
Opteron 2210 HE  1800 MHz  Tyan Thunder h2000M  BCM5785  Dual DDR2-600R  5-5-5-15 CR1  109.0 ns
Xeon 5140  2333 MHz  Intel S5000VSA  i5000V  Dual DDR2-667FB  5-5-5-15  112.3 ns
Pentium M 730  1600 MHz  AOpen i915Ga-HFS  i915G Int.  Dual DDR2-533  4-4-4-12  113.6 ns
Phenom X4 9500  2200 MHz  Asus M3A  AMD770  Ganged Dual DDR2-800  5-5-5-18 CR2  114.0 ns
Xeon E5462  2800 MHz  Intel S5400SF  i5400  Quad DDR2-640FB  5-5-5-15  114.0 ns
Opteron 2431  2400 MHz  Supermicro H8DI3+-F  SR5690  Unganged Dual DDR2-800R  6-6-6-18 CR1  118.3 ns
P4  2800 MHz  MSI 848P Neo-S  i848P  DDR400 SDRAM  2.5-3-3-8  118.6 ns
Core Duo T2500  2000 MHz  Asus N4L-VM DH  i945GT Int.  Dual DDR2-667  5-5-5-15  120.7 ns
Xeon  3066 MHz  Asus PCH-DL  i875P + PAT  Dual DDR333  2.5-3-3-7  121.6 ns
Nano X2 L4350  1600 MHz  VIA EPIA-M900  VX900H Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  121.8 ns
Atom Z3740  1866 MHz  [ TRIAL VERSION ]  BayTrailT Int.  Dual DDR3-1066  8-10-8-32 CR1  123.6 ns
Xeon  3400 MHz  Intel SE7320SP2  iE7320  Dual DDR333R  2.5-3-3-7  124.1 ns
Celeron M 320  1300 MHz  DFI 855GME-MGF  i855GME Int.  DDR333 SDRAM  2.5-3-3-7  124.6 ns
Xeon L5320  1866 MHz  Intel S5000VCL  i5000V  Dual DDR2-533FB  4-4-4-12  127.2 ns
Nano L2200  1600 MHz  VIA VB8001  CN896 Int.  DDR2-667 SDRAM  5-5-5-15 CR2  136.3 ns
PIII-S  1266 MHz  MSI Pro266TD Master-LR  ApolloPro266TD  DDR266 SDRAM  2-3-3-6 CR2  141.2 ns
P4EE  3466 MHz  ASRock 775Dual-880Pro  PT880Pro  Dual DDR2-400  3-3-3-8 CR2  142.0 ns
Opteron 2344 HE  1700 MHz  Supermicro H8DME-2  nForcePro-3600  Unganged Dual DDR2-667R  5-5-5-15 CR1  143.1 ns
Crusoe 5800  1000 MHz  ECS A530 DeskNote  Crusoe  DDR266 SDRAM    144.5 ns
Celeron D 326  2533 MHz  ASRock 775Twins-HDTV  RC410 Ext.  DDR2-533 SDRAM  4-4-4-11  151.1 ns
PIII-E  733 MHz  Tyan Thunder 2500  ServerSet3HE  PC133R SDRAM  3-3-3-6  154.6 ns
P4  2400 MHz  Abit SI7  SiSR658  Dual PC1066 RDRAM  -  157.9 ns
Celeron  2000 MHz  Gigabyte GA-8TRS350MT  RS350 Int.  Dual DDR400  2-2-4-6 CR1  158.0 ns
P4  1600 MHz  Abit TH7II  i850  Dual PC800 RDRAM  -  161.7 ns
Duron  1600 MHz  MSI KT6V-LSR  KT600  DDR400 SDRAM  3-3-3-8 CR2  166.4 ns
Efficeon 8600  1000 MHz  ECS 532 Notebook  Efficeon  DDR266 SDRAM    175.0 ns
C3  1333 MHz  VIA EPIA SP  CN400 Int.  DDR400 SDRAM  3-3-3-8 CR2  175.8 ns
Celeron  1700 MHz  Asus P4B  i845  PC133 SDRAM  3-3-3-6  186.0 ns
Duron  600 MHz  Abit KG7-Lite  AMD-760  DDR200R SDRAM  2-2-2-5  188.2 ns
Celeron 215  1333 MHz  Intel D201GLY  SiS662 Int.  DDR2-533  5-4-4-12  190.2 ns
PIII  500 MHz  Epox KP6-BS  i440BX  PC100R SDRAM  3-3-3-?  197.3 ns
Pentium  166 MHz  Asus TX97-X  i430TX  PC66 SDRAM  2-2-3-4  197.4 ns
C3  800 MHz  VIA EPIA  PLE133 Int.  PC133 SDRAM  3-3-3-6  198.0 ns
MediaGXm  233 MHz  ALD NPC6836  Cx5520  PC60 SDRAM  3-3-3-6  201.9 ns
C7  1500 MHz  VIA EPIA EN  CN700 Int.  DDR2-533 SDRAM  4-4-4-12 CR2  203.4 ns
Athlon  1400 MHz  PCChips M817LMR  MAGiK1  DDR266 SDRAM  2-2-2-6  210.1 ns
AthlonXP 1600+  1400 MHz  Acorp 7KMM1  KM133A Int.  PC133 SDRAM  3-3-3-6  214.6 ns
K6-2  333 MHz  Amptron PM-9100LMR  SiS5597 Ext.  PC66 SDRAM  3-3-3-6  215.2 ns
PentiumMMX  200 MHz  Gigabyte GA-586DX  i430HX  Dual EDO  -  218.3 ns
PIII  450 MHz  Asus P3C-S  i820  PC600 RDRAM  -  220.4 ns
PentiumPro  200 MHz  Compaq ProLiant 800  i440FX  Dual EDO  -  231.4 ns
Athlon  750 MHz  Epox EP-7KXA  KX133  PC133 SDRAM  3-3-3-6  241.7 ns
K5 PR166  116 MHz  Asus P5A  ALADDiN5  PC66 SDRAM  2-2-2-6  260.3 ns
K6-III  400 MHz  Epox EP-MVP3G-M  MVP3  PC100 SDRAM  2-2-2-5  288.0 ns
PII  333 MHz  Intel DK440LX  i440LX  PC66 SDRAM  3-2-2-?  299.3 ns
Celeron  700 MHz  PCChips M758LT  SiS630ET Int.  PC100 SDRAM  3-3-3-6  325.5 ns
Celeron  266 MHz  Epox P2-100B  ApolloPro  PC66 SDRAM  3-2-2-5  348.3 ns


CPU Queen

 
CPU  CPU Clock  Motherboard  Chipset  Memory  CL-RCD-RP-RAS  Score
16x Xeon E5-2670 HT  2600 MHz  Supermicro X9DR6-F  C600  Quad DDR3-1333  9-9-9-24  112181
6x Core i7-4930K HT  3400 MHz  Gigabyte GA-X79-UD3  X79  Quad DDR3-1866  9-10-9-27 CR2  63239
6x Core i7-3960X Extreme HT  3300 MHz  Intel DX79SI  X79  Quad DDR3-1600  9-9-9-24 CR2  61860
6x Core i7-990X Extreme HT  3466 MHz  Intel DX58SO2  X58  Triple DDR3-1333  9-9-9-24 CR1  57896
8x Xeon X5550 HT  2666 MHz  Supermicro X8DTN+  i5520  Triple DDR3-1333  9-9-9-24 CR1  57158
32x Opteron 6274  2200 MHz  Supermicro H8DGI-F  SR5690  Dual DDR3-1600R  11-11-11-28 CR1  54021
4x Xeon E3-1245 v3 HT  3400 MHz  Supermicro X10SAE  C226 Int.  Dual DDR3-1600  11-11-11-28 CR1  48447
4x Core i7-3770K HT  3500 MHz  MSI Z77A-GD55  Z77 Int.  Dual DDR3-1600  9-9-9-24 CR2  48066
4x Core i7-2600 HT  3400 MHz  Asus P8P67  P67  Dual DDR3-1333  9-9-9-24 CR1  45446
12x Opteron 2431  2400 MHz  Supermicro H8DI3+-F  SR5690  Unganged Dual DDR2-800R  6-6-6-18 CR1  42691
8x Xeon E5462  2800 MHz  Intel S5400SF  i5400  Quad DDR2-640FB  5-5-5-15  41396
4x Core i7-965 Extreme HT  3200 MHz  Asus P6T Deluxe  X58  Triple DDR3-1333  9-9-9-24 CR1  39033
8x FX-8350  4000 MHz  Asus M5A99X Evo R2.0  AMD990X  Dual DDR3-1866  9-10-9-27 CR2  36172
6x Phenom II X6 Black 1100T  3300 MHz  Gigabyte GA-890GPA-UD3H v2  AMD890GX Int.  Unganged Dual DDR3-1333  9-9-9-24 CR2  32616
8x FX-8150  3600 MHz  Asus M5A97  AMD970  Dual DDR3-1866  9-10-9-27 CR2  32296
8x Opteron 2378  2400 MHz  Tyan Thunder n3600R  nForcePro-3600  Unganged Dual DDR2-800R  6-6-6-18 CR1  30929
8x Xeon L5320  1866 MHz  Intel S5000VCL  i5000V  Dual DDR2-533FB  4-4-4-12  27840
4x Core 2 Extreme QX9650  3000 MHz  Gigabyte GA-EP35C-DS3R  P35  Dual DDR3-1066  8-8-8-20 CR2  25309
4x Core 2 Extreme QX6700  2666 MHz  Intel D975XBX2  i975X  Dual DDR2-667  5-5-5-15  22686
4x A8-3850  2900 MHz  Gigabyte GA-A75M-UD2H  A75 Int.  Dual DDR3-1333  9-9-9-24 CR1  22085
8x Opteron 2344 HE  1700 MHz  Supermicro H8DME-2  nForcePro-3600  Unganged Dual DDR2-667R  5-5-5-15 CR1  22053
4x Phenom II X4 Black 940  3000 MHz  Asus M3N78-EM  GeForce8300 Int.  Ganged Dual DDR2-800  5-5-5-18 CR2  22000
4x A10-6800K  4100 MHz  Gigabyte GA-F2A85X-UP4  A85X Int.  Dual DDR3-2133  9-11-10-27 CR2  21717
2x Core i5-650 HT  3200 MHz  Supermicro C7SIM-Q  Q57 Int.  Dual DDR3-1333  9-9-9-24 CR1  21390
4x Xeon X3430  2400 MHz  Supermicro X8SIL-F  i3420  Dual DDR3-1333  9-9-9-24 CR1  21086
4x A10-5800K  3800 MHz  Asus F2A55-M  A55 Int.  Dual DDR3-1866  9-10-9-27 CR2  20220
4x Xeon 5140  2333 MHz  Intel S5000VSA  i5000V  Dual DDR2-667FB  5-5-5-15  19830
4x Phenom X4 9500  2200 MHz  Asus M3A  AMD770  Ganged Dual DDR2-800  5-5-5-18 CR2  16151
4x Atom Z3740  1866 MHz  [ TRIAL VERSION ]  BayTrailT Int.  Dual DDR3-1066  8-10-8-32 CR1  13678
2x Core 2 Extreme X6800  2933 MHz  Abit AB9  P965  Dual DDR2-800  5-5-5-18 CR2  12562
4x Opteron 2210 HE  1800 MHz  Tyan Thunder h2000M  BCM5785  Dual DDR2-600R  5-5-5-15 CR1  12438
2x Athlon64 X2 Black 6400+  3200 MHz  MSI K9N SLI Platinum  nForce570SLI  Dual DDR2-800  4-4-4-11 CR1  11137
2x Core 2 Duo P8400  2266 MHz  MSI MegaBook PR201  GM45 Int.  Dual DDR2-667  5-5-5-15  9568
2x Core Duo T2500  2000 MHz  Asus N4L-VM DH  i945GT Int.  Dual DDR2-667  5-5-5-15  7796
2x Pentium EE 955 HT  3466 MHz  Intel D955XBK  i955X  Dual DDR2-667  4-4-4-11  7630
2x Xeon HT  3400 MHz  Intel SE7320SP2  iE7320  Dual DDR333R  2.5-3-3-7  7533
2x Athlon64 X2 4000+  2100 MHz  ASRock ALiveNF7G-HDready  nForce7050-630a Int.  Dual DDR2-700  5-5-5-18 CR2  7247
2x Xeon  3066 MHz  Asus PCH-DL  i875P + PAT  Dual DDR333  2.5-3-3-7  6218
2x Atom D2500  1866 MHz  Intel D2500CC  NM10 Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  5692
Nano X2 L4350  1600 MHz  VIA EPIA-M900  VX900H Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  5532
2x E-350  1600 MHz  ASRock E350M1  A50M Int.  DDR3-1066 SDRAM  8-8-8-20 CR1  4973
2x Opteron 240  1400 MHz  MSI K8D Master3-133 FS  AMD8100  Dual DDR400R  3-4-4-8 CR1  4846
2x PIII-S  1266 MHz  MSI Pro266TD Master-LR  ApolloPro266TD  DDR266 SDRAM  2-3-3-6 CR2  4843
P4EE HT  3733 MHz  Intel SE7230NH1LX  iE7230  Dual DDR2-667  5-5-5-15  4158
2x Pentium D 820  2800 MHz  Abit Fatal1ty F-I90HD  RS600 Int.  Dual DDR2-800  5-5-5-18 CR2  4150
Opteron 248  2200 MHz  MSI K8T Master1-FAR  K8T800  Dual DDR266R  2-3-3-6 CR1  3831
Atom 230 HT  1600 MHz  Intel D945GCLF  i945GC Int.  DDR2-533 SDRAM  4-4-4-12  3761
P4EE  3466 MHz  ASRock 775Dual-880Pro  PT880Pro  Dual DDR2-400  3-3-3-8 CR2  3506
Athlon64 3200+  2000 MHz  ASRock 939S56-M  SiS756  Dual DDR400  2.5-3-3-8 CR2  3484
AthlonXP 3200+  2200 MHz  Asus A7N8X-E  nForce2-U400  Dual DDR400  2.5-4-4-8 CR1  3470
Celeron 420  1600 MHz  Intel DQ965GF  Q965 Int.  Dual DDR2-667  5-5-5-15  3417
Pentium M 730  1600 MHz  AOpen i915Ga-HFS  i915G Int.  Dual DDR2-533  4-4-4-12  3107
P4  2800 MHz  MSI 848P Neo-S  i848P  DDR400 SDRAM  2.5-3-3-8  2838
2x PIII-E  733 MHz  Tyan Thunder 2500  ServerSet3HE  PC133R SDRAM  3-3-3-6  2803
Sempron 2600+  1600 MHz  ASRock K8NF4G-SATA2  GeForce6100 Int.  DDR400 SDRAM  2.5-3-3-8 CR2  2797
Celeron 215  1333 MHz  Intel D201GLY  SiS662 Int.  DDR2-533  5-4-4-12  2601
Nano L2200  1600 MHz  VIA VB8001  CN896 Int.  DDR2-667 SDRAM  5-5-5-15 CR2  2570
Celeron M 320  1300 MHz  DFI 855GME-MGF  i855GME Int.  DDR333 SDRAM  2.5-3-3-7  2539
Duron  1600 MHz  MSI KT6V-LSR  KT600  DDR400 SDRAM  3-3-3-8 CR2  2535
P4  2400 MHz  Abit SI7  SiSR658  Dual PC1066 RDRAM  -  2440
Athlon  1400 MHz  PCChips M817LMR  MAGiK1  DDR266 SDRAM  2-2-2-6  2221
AthlonXP 1600+  1400 MHz  Acorp 7KMM1  KM133A Int.  PC133 SDRAM  3-3-3-6  2202
Celeron  2000 MHz  Gigabyte GA-8TRS350MT  RS350 Int.  Dual DDR400  2-2-4-6 CR1  2042
2x PIII  500 MHz  Epox KP6-BS  i440BX  PC100R SDRAM  3-3-3-?  1922
Celeron D 326  2533 MHz  ASRock 775Twins-HDTV  RC410 Ext.  DDR2-533 SDRAM  4-4-4-11  1904
Celeron  1700 MHz  Asus P4B  i845  PC133 SDRAM  3-3-3-6  1762
P4  1600 MHz  Abit TH7II  i850  Dual PC800 RDRAM  -  1608
C7  1500 MHz  VIA EPIA EN  CN700 Int.  DDR2-533 SDRAM  4-4-4-12 CR2  1559
Efficeon 8600  1000 MHz  ECS 532 Notebook  Efficeon  DDR266 SDRAM    1459
Celeron  700 MHz  PCChips M758LT  SiS630ET Int.  PC100 SDRAM  3-3-3-6  1343
Athlon  750 MHz  Epox EP-7KXA  KX133  PC133 SDRAM  3-3-3-6  1185
2x PII  333 MHz  Intel DK440LX  i440LX  PC66 SDRAM  3-2-2-?  1142
C3  1333 MHz  VIA EPIA SP  CN400 Int.  DDR400 SDRAM  3-3-3-8 CR2  1096
Duron  600 MHz  Abit KG7-Lite  AMD-760  DDR200R SDRAM  2-2-2-5  951
Crusoe 5800  1000 MHz  ECS A530 DeskNote  Crusoe  DDR266 SDRAM    872
PIII  450 MHz  Asus P3C-S  i820  PC600 RDRAM  -  870
K6-III  400 MHz  Epox EP-MVP3G-M  MVP3  PC100 SDRAM  2-2-2-5  810
K6-2  333 MHz  Amptron PM-9100LMR  SiS5597 Ext.  PC66 SDRAM  3-3-3-6  692
2x PentiumMMX  200 MHz  Gigabyte GA-586DX  i430HX  Dual EDO  -  662
C3  800 MHz  VIA EPIA  PLE133 Int.  PC133 SDRAM  3-3-3-6  574
2x PentiumPro  200 MHz  Compaq ProLiant 800  i440FX  Dual EDO  -  533
Celeron  266 MHz  Epox P2-100B  ApolloPro  PC66 SDRAM  3-2-2-5  456
Pentium  166 MHz  Asus TX97-X  i430TX  PC66 SDRAM  2-2-3-4  231
K5 PR166  116 MHz  Asus P5A  ALADDiN5  PC66 SDRAM  2-2-2-6  202
MediaGXm  233 MHz  ALD NPC6836  Cx5520  PC60 SDRAM  3-3-3-6  184


CPU PhotoWorxx

 
CPU  CPU Clock  Motherboard  Chipset  Memory  CL-RCD-RP-RAS  Score
6x Core i7-4930K HT  3400 MHz  Gigabyte GA-X79-UD3  X79  Quad DDR3-1866  9-10-9-27 CR2  25667 MPixel/s
6x Core i7-3960X Extreme HT  3300 MHz  Intel DX79SI  X79  Quad DDR3-1600  9-9-9-24 CR2  22721 MPixel/s
8x Xeon X5550 HT  2666 MHz  Supermicro X8DTN+  i5520  Triple DDR3-1333  9-9-9-24 CR1  20506 MPixel/s
16x Xeon E5-2670 HT  2600 MHz  Supermicro X9DR6-F  C600  Quad DDR3-1333  9-9-9-24  19558 MPixel/s
4x Core i7-3770K HT  3500 MHz  MSI Z77A-GD55  Z77 Int.  Dual DDR3-1600  9-9-9-24 CR2  14009 MPixel/s
4x Xeon E3-1245 v3 HT  3400 MHz  Supermicro X10SAE  C226 Int.  Dual DDR3-1600  11-11-11-28 CR1  13344 MPixel/s
6x Core i7-990X Extreme HT  3466 MHz  Intel DX58SO2  X58  Triple DDR3-1333  9-9-9-24 CR1  12922 MPixel/s
8x FX-8150  3600 MHz  Asus M5A97  AMD970  Dual DDR3-1866  9-10-9-27 CR2  12482 MPixel/s
8x FX-8350  4000 MHz  Asus M5A99X Evo R2.0  AMD990X  Dual DDR3-1866  9-10-9-27 CR2  12319 MPixel/s
4x Core i7-965 Extreme HT  3200 MHz  Asus P6T Deluxe  X58  Triple DDR3-1333  9-9-9-24 CR1  11898 MPixel/s
12x Opteron 2431  2400 MHz  Supermicro H8DI3+-F  SR5690  Unganged Dual DDR2-800R  6-6-6-18 CR1  10949 MPixel/s
4x Core i7-2600 HT  3400 MHz  Asus P8P67  P67  Dual DDR3-1333  9-9-9-24 CR1  10703 MPixel/s
8x Opteron 2378  2400 MHz  Tyan Thunder n3600R  nForcePro-3600  Unganged Dual DDR2-800R  6-6-6-18 CR1  10060 MPixel/s
4x A10-6800K  4100 MHz  Gigabyte GA-F2A85X-UP4  A85X Int.  Dual DDR3-2133  9-11-10-27 CR2  9517 MPixel/s
4x A10-5800K  3800 MHz  Asus F2A55-M  A55 Int.  Dual DDR3-1866  9-10-9-27 CR2  9019 MPixel/s
4x Xeon X3430  2400 MHz  Supermicro X8SIL-F  i3420  Dual DDR3-1333  9-9-9-24 CR1  8548 MPixel/s
32x Opteron 6274  2200 MHz  Supermicro H8DGI-F  SR5690  Dual DDR3-1600R  11-11-11-28 CR1  8195 MPixel/s
4x A8-3850  2900 MHz  Gigabyte GA-A75M-UD2H  A75 Int.  Dual DDR3-1333  9-9-9-24 CR1  7677 MPixel/s
2x Core i5-650 HT  3200 MHz  Supermicro C7SIM-Q  Q57 Int.  Dual DDR3-1333  9-9-9-24 CR1  6886 MPixel/s
8x Opteron 2344 HE  1700 MHz  Supermicro H8DME-2  nForcePro-3600  Unganged Dual DDR2-667R  5-5-5-15 CR1  6879 MPixel/s
6x Phenom II X6 Black 1100T  3300 MHz  Gigabyte GA-890GPA-UD3H v2  AMD890GX Int.  Unganged Dual DDR3-1333  9-9-9-24 CR2  6621 MPixel/s
4x Phenom II X4 Black 940  3000 MHz  Asus M3N78-EM  GeForce8300 Int.  Ganged Dual DDR2-800  5-5-5-18 CR2  5247 MPixel/s
8x Xeon E5462  2800 MHz  Intel S5400SF  i5400  Quad DDR2-640FB  5-5-5-15  4747 MPixel/s
4x Core 2 Extreme QX9650  3000 MHz  Gigabyte GA-EP35C-DS3R  P35  Dual DDR3-1066  8-8-8-20 CR2  4183 MPixel/s
4x Atom Z3740  1866 MHz  [ TRIAL VERSION ]  BayTrailT Int.  Dual DDR3-1066  8-10-8-32 CR1  4050 MPixel/s
4x Phenom X4 9500  2200 MHz  Asus M3A  AMD770  Ganged Dual DDR2-800  5-5-5-18 CR2  3985 MPixel/s
4x Opteron 2210 HE  1800 MHz  Tyan Thunder h2000M  BCM5785  Dual DDR2-600R  5-5-5-15 CR1  3770 MPixel/s
2x Core 2 Extreme X6800  2933 MHz  Abit AB9  P965  Dual DDR2-800  5-5-5-18 CR2  3464 MPixel/s
2x Core 2 Duo P8400  2266 MHz  MSI MegaBook PR201  GM45 Int.  Dual DDR2-667  5-5-5-15  2924 MPixel/s
2x Athlon64 X2 Black 6400+  3200 MHz  MSI K9N SLI Platinum  nForce570SLI  Dual DDR2-800  4-4-4-11 CR1  2793 MPixel/s
4x Core 2 Extreme QX6700  2666 MHz  Intel D975XBX2  i975X  Dual DDR2-667  5-5-5-15  2786 MPixel/s
2x Pentium EE 955 HT  3466 MHz  Intel D955XBK  i955X  Dual DDR2-667  4-4-4-11  2683 MPixel/s
Nano X2 L4350  1600 MHz  VIA EPIA-M900  VX900H Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  2560 MPixel/s
2x Athlon64 X2 4000+  2100 MHz  ASRock ALiveNF7G-HDready  nForce7050-630a Int.  Dual DDR2-700  5-5-5-18 CR2  2378 MPixel/s
P4EE HT  3733 MHz  Intel SE7230NH1LX  iE7230  Dual DDR2-667  5-5-5-15  2024 MPixel/s
8x Xeon L5320  1866 MHz  Intel S5000VCL  i5000V  Dual DDR2-533FB  4-4-4-12  1913 MPixel/s
4x Xeon 5140  2333 MHz  Intel S5000VSA  i5000V  Dual DDR2-667FB  5-5-5-15  1880 MPixel/s
2x Opteron 240  1400 MHz  MSI K8D Master3-133 FS  AMD8100  Dual DDR400R  3-4-4-8 CR1  1865 MPixel/s
2x E-350  1600 MHz  ASRock E350M1  A50M Int.  DDR3-1066 SDRAM  8-8-8-20 CR1  1864 MPixel/s
Celeron 420  1600 MHz  Intel DQ965GF  Q965 Int.  Dual DDR2-667  5-5-5-15  1813 MPixel/s
2x Atom D2500  1866 MHz  Intel D2500CC  NM10 Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  1783 MPixel/s
2x Xeon  3066 MHz  Asus PCH-DL  i875P + PAT  Dual DDR333  2.5-3-3-7  1724 MPixel/s
2x Core Duo T2500  2000 MHz  Asus N4L-VM DH  i945GT Int.  Dual DDR2-667  5-5-5-15  1709 MPixel/s
2x Pentium D 820  2800 MHz  Abit Fatal1ty F-I90HD  RS600 Int.  Dual DDR2-800  5-5-5-18 CR2  1678 MPixel/s
P4EE  3466 MHz  ASRock 775Dual-880Pro  PT880Pro  Dual DDR2-400  3-3-3-8 CR2  1491 MPixel/s
2x Xeon HT  3400 MHz  Intel SE7320SP2  iE7320  Dual DDR333R  2.5-3-3-7  1336 MPixel/s
Nano L2200  1600 MHz  VIA VB8001  CN896 Int.  DDR2-667 SDRAM  5-5-5-15 CR2  1277 MPixel/s
Athlon64 3200+  2000 MHz  ASRock 939S56-M  SiS756  Dual DDR400  2.5-3-3-8 CR2  1196 MPixel/s
P4  2800 MHz  MSI 848P Neo-S  i848P  DDR400 SDRAM  2.5-3-3-8  1188 MPixel/s
P4  2400 MHz  Abit SI7  SiSR658  Dual PC1066 RDRAM  -  1141 MPixel/s
Opteron 248  2200 MHz  MSI K8T Master1-FAR  K8T800  Dual DDR266R  2-3-3-6 CR1  1086 MPixel/s
Atom 230 HT  1600 MHz  Intel D945GCLF  i945GC Int.  DDR2-533 SDRAM  4-4-4-12  1086 MPixel/s
Pentium M 730  1600 MHz  AOpen i915Ga-HFS  i915G Int.  Dual DDR2-533  4-4-4-12  952 MPixel/s
AthlonXP 3200+  2200 MHz  Asus A7N8X-E  nForce2-U400  Dual DDR400  2.5-4-4-8 CR1  902 MPixel/s
P4  1600 MHz  Abit TH7II  i850  Dual PC800 RDRAM  -  874 MPixel/s
Celeron D 326  2533 MHz  ASRock 775Twins-HDTV  RC410 Ext.  DDR2-533 SDRAM  4-4-4-11  827 MPixel/s
Sempron 2600+  1600 MHz  ASRock K8NF4G-SATA2  GeForce6100 Int.  DDR400 SDRAM  2.5-3-3-8 CR2  820 MPixel/s
Celeron  2000 MHz  Gigabyte GA-8TRS350MT  RS350 Int.  Dual DDR400  2-2-4-6 CR1  818 MPixel/s
Celeron 215  1333 MHz  Intel D201GLY  SiS662 Int.  DDR2-533  5-4-4-12  814 MPixel/s
Celeron M 320  1300 MHz  DFI 855GME-MGF  i855GME Int.  DDR333 SDRAM  2.5-3-3-7  714 MPixel/s
Duron  1600 MHz  MSI KT6V-LSR  KT600  DDR400 SDRAM  3-3-3-8 CR2  551 MPixel/s
Efficeon 8600  1000 MHz  ECS 532 Notebook  Efficeon  DDR266 SDRAM    537 MPixel/s
Celeron  1700 MHz  Asus P4B  i845  PC133 SDRAM  3-3-3-6  506 MPixel/s
C7  1500 MHz  VIA EPIA EN  CN700 Int.  DDR2-533 SDRAM  4-4-4-12 CR2  478 MPixel/s
2x PIII-S  1266 MHz  MSI Pro266TD Master-LR  ApolloPro266TD  DDR266 SDRAM  2-3-3-6 CR2  348 MPixel/s
AthlonXP 1600+  1400 MHz  Acorp 7KMM1  KM133A Int.  PC133 SDRAM  3-3-3-6  320 MPixel/s
Athlon  1400 MHz  PCChips M817LMR  MAGiK1  DDR266 SDRAM  2-2-2-6  304 MPixel/s
2x PIII-E  733 MHz  Tyan Thunder 2500  ServerSet3HE  PC133R SDRAM  3-3-3-6  285 MPixel/s
Duron  600 MHz  Abit KG7-Lite  AMD-760  DDR200R SDRAM  2-2-2-5  248 MPixel/s
2x PIII  500 MHz  Epox KP6-BS  i440BX  PC100R SDRAM  3-3-3-?  211 MPixel/s
Athlon  750 MHz  Epox EP-7KXA  KX133  PC133 SDRAM  3-3-3-6  202 MPixel/s
C3  1333 MHz  VIA EPIA SP  CN400 Int.  DDR400 SDRAM  3-3-3-8 CR2  181 MPixel/s
Crusoe 5800  1000 MHz  ECS A530 DeskNote  Crusoe  DDR266 SDRAM    163 MPixel/s
PIII  450 MHz  Asus P3C-S  i820  PC600 RDRAM  -  156 MPixel/s
2x PII  333 MHz  Intel DK440LX  i440LX  PC66 SDRAM  3-2-2-?  101 MPixel/s
C3  800 MHz  VIA EPIA  PLE133 Int.  PC133 SDRAM  3-3-3-6  99 MPixel/s
K6-III  400 MHz  Epox EP-MVP3G-M  MVP3  PC100 SDRAM  2-2-2-5  77 MPixel/s
2x PentiumPro  200 MHz  Compaq ProLiant 800  i440FX  Dual EDO  -  61 MPixel/s
Celeron  700 MHz  PCChips M758LT  SiS630ET Int.  PC100 SDRAM  3-3-3-6  60 MPixel/s
Celeron  266 MHz  Epox P2-100B  ApolloPro  PC66 SDRAM  3-2-2-5  54 MPixel/s
2x PentiumMMX  200 MHz  Gigabyte GA-586DX  i430HX  Dual EDO  -  52 MPixel/s
K6-2  333 MHz  Amptron PM-9100LMR  SiS5597 Ext.  PC66 SDRAM  3-3-3-6  43 MPixel/s
MediaGXm  233 MHz  ALD NPC6836  Cx5520  PC60 SDRAM  3-3-3-6  30 MPixel/s
Pentium  166 MHz  Asus TX97-X  i430TX  PC66 SDRAM  2-2-3-4  27 MPixel/s
K5 PR166  116 MHz  Asus P5A  ALADDiN5  PC66 SDRAM  2-2-2-6  26 MPixel/s


CPU ZLib

 
CPU  CPU Clock  Motherboard  Chipset  Memory  CL-RCD-RP-RAS  Score
6x Core i7-4930K HT  3400 MHz  Gigabyte GA-X79-UD3  X79  Quad DDR3-1866  9-10-9-27 CR2  438.2 MB/s
6x Core i7-3960X Extreme HT  3300 MHz  Intel DX79SI  X79  Quad DDR3-1600  9-9-9-24 CR2  427.9 MB/s
8x Xeon X5550 HT  2666 MHz  Supermicro X8DTN+  i5520  Triple DDR3-1333  9-9-9-24 CR1  366.2 MB/s
6x Core i7-990X Extreme HT  3466 MHz  Intel DX58SO2  X58  Triple DDR3-1333  9-9-9-24 CR1  361.1 MB/s
12x Opteron 2431  2400 MHz  Supermicro H8DI3+-F  SR5690  Unganged Dual DDR2-800R  6-6-6-18 CR1  350.5 MB/s
8x FX-8350  4000 MHz  Asus M5A99X Evo R2.0  AMD990X  Dual DDR3-1866  9-10-9-27 CR2  334.9 MB/s
4x Core i7-3770K HT  3500 MHz  MSI Z77A-GD55  Z77 Int.  Dual DDR3-1600  9-9-9-24 CR2  304.1 MB/s
4x Xeon E3-1245 v3 HT  3400 MHz  Supermicro X10SAE  C226 Int.  Dual DDR3-1600  11-11-11-28 CR1  297.9 MB/s
4x Core i7-2600 HT  3400 MHz  Asus P8P67  P67  Dual DDR3-1333  9-9-9-24 CR1  278.6 MB/s
8x Xeon E5462  2800 MHz  Intel S5400SF  i5400  Quad DDR2-640FB  5-5-5-15  266.9 MB/s
8x FX-8150  3600 MHz  Asus M5A97  AMD970  Dual DDR3-1866  9-10-9-27 CR2  264.7 MB/s
6x Phenom II X6 Black 1100T  3300 MHz  Gigabyte GA-890GPA-UD3H v2  AMD890GX Int.  Unganged Dual DDR3-1333  9-9-9-24 CR2  244.8 MB/s
8x Opteron 2378  2400 MHz  Tyan Thunder n3600R  nForcePro-3600  Unganged Dual DDR2-800R  6-6-6-18 CR1  232.8 MB/s
4x Core i7-965 Extreme HT  3200 MHz  Asus P6T Deluxe  X58  Triple DDR3-1333  9-9-9-24 CR1  228.5 MB/s
8x Xeon L5320  1866 MHz  Intel S5000VCL  i5000V  Dual DDR2-533FB  4-4-4-12  180.9 MB/s
4x A10-6800K  4100 MHz  Gigabyte GA-F2A85X-UP4  A85X Int.  Dual DDR3-2133  9-11-10-27 CR2  175.7 MB/s
8x Opteron 2344 HE  1700 MHz  Supermicro H8DME-2  nForcePro-3600  Unganged Dual DDR2-667R  5-5-5-15 CR1  168.6 MB/s
4x A10-5800K  3800 MHz  Asus F2A55-M  A55 Int.  Dual DDR3-1866  9-10-9-27 CR2  160.4 MB/s
4x Phenom II X4 Black 940  3000 MHz  Asus M3N78-EM  GeForce8300 Int.  Ganged Dual DDR2-800  5-5-5-18 CR2  147.0 MB/s
4x A8-3850  2900 MHz  Gigabyte GA-A75M-UD2H  A75 Int.  Dual DDR3-1333  9-9-9-24 CR1  144.9 MB/s
4x Core 2 Extreme QX9650  3000 MHz  Gigabyte GA-EP35C-DS3R  P35  Dual DDR3-1066  8-8-8-20 CR2  144.5 MB/s
4x Core 2 Extreme QX6700  2666 MHz  Intel D975XBX2  i975X  Dual DDR2-667  5-5-5-15  130.1 MB/s
4x Xeon 5140  2333 MHz  Intel S5000VSA  i5000V  Dual DDR2-667FB  5-5-5-15  112.9 MB/s
4x Phenom X4 9500  2200 MHz  Asus M3A  AMD770  Ganged Dual DDR2-800  5-5-5-18 CR2  108.2 MB/s
4x Xeon X3430  2400 MHz  Supermicro X8SIL-F  i3420  Dual DDR3-1333  9-9-9-24 CR1  107.4 MB/s
2x Core i5-650 HT  3200 MHz  Supermicro C7SIM-Q  Q57 Int.  Dual DDR3-1333  9-9-9-24 CR1  104.5 MB/s
4x Opteron 2210 HE  1800 MHz  Tyan Thunder h2000M  BCM5785  Dual DDR2-600R  5-5-5-15 CR1  79.5 MB/s
2x Core 2 Extreme X6800  2933 MHz  Abit AB9  P965  Dual DDR2-800  5-5-5-18 CR2  71.6 MB/s
2x Athlon64 X2 Black 6400+  3200 MHz  MSI K9N SLI Platinum  nForce570SLI  Dual DDR2-800  4-4-4-11 CR1  70.8 MB/s
4x Atom Z3740  1866 MHz  [ TRIAL VERSION ]  BayTrailT Int.  Dual DDR3-1066  8-10-8-32 CR1  68.4 MB/s
2x Pentium EE 955 HT  3466 MHz  Intel D955XBK  i955X  Dual DDR2-667  4-4-4-11  63.9 MB/s
2x Xeon HT  3400 MHz  Intel SE7320SP2  iE7320  Dual DDR333R  2.5-3-3-7  62.1 MB/s
2x Core 2 Duo P8400  2266 MHz  MSI MegaBook PR201  GM45 Int.  Dual DDR2-667  5-5-5-15  54.1 MB/s
2x Xeon  3066 MHz  Asus PCH-DL  i875P + PAT  Dual DDR333  2.5-3-3-7  50.3 MB/s
2x Athlon64 X2 4000+  2100 MHz  ASRock ALiveNF7G-HDready  nForce7050-630a Int.  Dual DDR2-700  5-5-5-18 CR2  45.3 MB/s
2x Core Duo T2500  2000 MHz  Asus N4L-VM DH  i945GT Int.  Dual DDR2-667  5-5-5-15  43.7 MB/s
2x Pentium D 820  2800 MHz  Abit Fatal1ty F-I90HD  RS600 Int.  Dual DDR2-800  5-5-5-18 CR2  42.4 MB/s
P4EE HT  3733 MHz  Intel SE7230NH1LX  iE7230  Dual DDR2-667  5-5-5-15  34.2 MB/s
Nano X2 L4350  1600 MHz  VIA EPIA-M900  VX900H Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  32.3 MB/s
2x Opteron 240  1400 MHz  MSI K8D Master3-133 FS  AMD8100  Dual DDR400R  3-4-4-8 CR1  30.1 MB/s
2x E-350  1600 MHz  ASRock E350M1  A50M Int.  DDR3-1066 SDRAM  8-8-8-20 CR1  29.5 MB/s
2x Atom D2500  1866 MHz  Intel D2500CC  NM10 Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  29.4 MB/s
P4EE  3466 MHz  ASRock 775Dual-880Pro  PT880Pro  Dual DDR2-400  3-3-3-8 CR2  28.1 MB/s
2x PIII-S  1266 MHz  MSI Pro266TD Master-LR  ApolloPro266TD  DDR266 SDRAM  2-3-3-6 CR2  27.9 MB/s
Opteron 248  2200 MHz  MSI K8T Master1-FAR  K8T800  Dual DDR266R  2-3-3-6 CR1  23.7 MB/s
AthlonXP 3200+  2200 MHz  Asus A7N8X-E  nForce2-U400  Dual DDR400  2.5-4-4-8 CR1  23.6 MB/s
P4  2800 MHz  MSI 848P Neo-S  i848P  DDR400 SDRAM  2.5-3-3-8  22.9 MB/s
Athlon64 3200+  2000 MHz  ASRock 939S56-M  SiS756  Dual DDR400  2.5-3-3-8 CR2  22.1 MB/s
Celeron 420  1600 MHz  Intel DQ965GF  Q965 Int.  Dual DDR2-667  5-5-5-15  19.5 MB/s
P4  2400 MHz  Abit SI7  SiSR658  Dual PC1066 RDRAM  -  19.5 MB/s
Celeron D 326  2533 MHz  ASRock 775Twins-HDTV  RC410 Ext.  DDR2-533 SDRAM  4-4-4-11  17.9 MB/s
Pentium M 730  1600 MHz  AOpen i915Ga-HFS  i915G Int.  Dual DDR2-533  4-4-4-12  17.6 MB/s
Atom 230 HT  1600 MHz  Intel D945GCLF  i945GC Int.  DDR2-533 SDRAM  4-4-4-12  17.3 MB/s
Sempron 2600+  1600 MHz  ASRock K8NF4G-SATA2  GeForce6100 Int.  DDR400 SDRAM  2.5-3-3-8 CR2  15.9 MB/s
Nano L2200  1600 MHz  VIA VB8001  CN896 Int.  DDR2-667 SDRAM  5-5-5-15 CR2  15.0 MB/s
AthlonXP 1600+  1400 MHz  Acorp 7KMM1  KM133A Int.  PC133 SDRAM  3-3-3-6  14.7 MB/s
Athlon  1400 MHz  PCChips M817LMR  MAGiK1  DDR266 SDRAM  2-2-2-6  14.5 MB/s
Celeron 215  1333 MHz  Intel D201GLY  SiS662 Int.  DDR2-533  5-4-4-12  14.5 MB/s
Celeron M 320  1300 MHz  DFI 855GME-MGF  i855GME Int.  DDR333 SDRAM  2.5-3-3-7  14.4 MB/s
2x PIII-E  733 MHz  Tyan Thunder 2500  ServerSet3HE  PC133R SDRAM  3-3-3-6  14.3 MB/s
P4  1600 MHz  Abit TH7II  i850  Dual PC800 RDRAM  -  12.5 MB/s
Celeron  2000 MHz  Gigabyte GA-8TRS350MT  RS350 Int.  Dual DDR400  2-2-4-6 CR1  12.1 MB/s
Duron  1600 MHz  MSI KT6V-LSR  KT600  DDR400 SDRAM  3-3-3-8 CR2  11.1 MB/s
Efficeon 8600  1000 MHz  ECS 532 Notebook  Efficeon  DDR266 SDRAM    10.2 MB/s
2x PIII  500 MHz  Epox KP6-BS  i440BX  PC100R SDRAM  3-3-3-?  9.6 MB/s
Celeron  1700 MHz  Asus P4B  i845  PC133 SDRAM  3-3-3-6  9.2 MB/s
Crusoe 5800  1000 MHz  ECS A530 DeskNote  Crusoe  DDR266 SDRAM    9.2 MB/s
C7  1500 MHz  VIA EPIA EN  CN700 Int.  DDR2-533 SDRAM  4-4-4-12 CR2  7.5 MB/s
Athlon  750 MHz  Epox EP-7KXA  KX133  PC133 SDRAM  3-3-3-6  7.2 MB/s
2x PII  333 MHz  Intel DK440LX  i440LX  PC66 SDRAM  3-2-2-?  6.2 MB/s
Duron  600 MHz  Abit KG7-Lite  AMD-760  DDR200R SDRAM  2-2-2-5  5.1 MB/s
C3  1333 MHz  VIA EPIA SP  CN400 Int.  DDR400 SDRAM  3-3-3-8 CR2  4.7 MB/s
PIII  450 MHz  Asus P3C-S  i820  PC600 RDRAM  -  4.4 MB/s
K6-III  400 MHz  Epox EP-MVP3G-M  MVP3  PC100 SDRAM  2-2-2-5  3.8 MB/s
2x PentiumPro  200 MHz  Compaq ProLiant 800  i440FX  Dual EDO  -  3.7 MB/s
Celeron  700 MHz  PCChips M758LT  SiS630ET Int.  PC100 SDRAM  3-3-3-6  2.8 MB/s
C3  800 MHz  VIA EPIA  PLE133 Int.  PC133 SDRAM  3-3-3-6  2.8 MB/s
2x PentiumMMX  200 MHz  Gigabyte GA-586DX  i430HX  Dual EDO  -  2.4 MB/s
K6-2  333 MHz  Amptron PM-9100LMR  SiS5597 Ext.  PC66 SDRAM  3-3-3-6  2.0 MB/s
Celeron  266 MHz  Epox P2-100B  ApolloPro  PC66 SDRAM  3-2-2-5  1.7 MB/s
Pentium  166 MHz  Asus TX97-X  i430TX  PC66 SDRAM  2-2-3-4  1.0 MB/s
K5 PR166  116 MHz  Asus P5A  ALADDiN5  PC66 SDRAM  2-2-2-6  1.0 MB/s
MediaGXm  233 MHz  ALD NPC6836  Cx5520  PC60 SDRAM  3-3-3-6  0.9 MB/s


CPU AES

 
CPU  CPU Clock  Motherboard  Chipset  Memory  CL-RCD-RP-RAS  Score
16x Xeon E5-2670 HT  2600 MHz  Supermicro X9DR6-F  C600  Quad DDR3-1333  9-9-9-24  47041 MB/s
32x Opteron 6274  2200 MHz  Supermicro H8DGI-F  SR5690  Dual DDR3-1600R  11-11-11-28 CR1  36470 MB/s
6x Core i7-3960X Extreme HT  3300 MHz  Intel DX79SI  X79  Quad DDR3-1600  9-9-9-24 CR2  21169 MB/s
6x Core i7-4930K HT  3400 MHz  Gigabyte GA-X79-UD3  X79  Quad DDR3-1866  9-10-9-27 CR2  21151 MB/s
8x FX-8350  4000 MHz  Asus M5A99X Evo R2.0  AMD990X  Dual DDR3-1866  9-10-9-27 CR2  16926 MB/s
4x Xeon E3-1245 v3 HT  3400 MHz  Supermicro X10SAE  C226 Int.  Dual DDR3-1600  11-11-11-28 CR1  16195 MB/s
8x FX-8150  3600 MHz  Asus M5A97  AMD970  Dual DDR3-1866  9-10-9-27 CR2  14798 MB/s
4x Core i7-3770K HT  3500 MHz  MSI Z77A-GD55  Z77 Int.  Dual DDR3-1600  9-9-9-24 CR2  14492 MB/s
4x Core i7-2600 HT  3400 MHz  Asus P8P67  P67  Dual DDR3-1333  9-9-9-24 CR1  13721 MB/s
6x Core i7-990X Extreme HT  3466 MHz  Intel DX58SO2  X58  Triple DDR3-1333  9-9-9-24 CR1  12257 MB/s
4x A10-6800K  4100 MHz  Gigabyte GA-F2A85X-UP4  A85X Int.  Dual DDR3-2133  9-11-10-27 CR2  8907 MB/s
4x A10-5800K  3800 MHz  Asus F2A55-M  A55 Int.  Dual DDR3-1866  9-10-9-27 CR2  8217 MB/s
2x Core i5-650 HT  3200 MHz  Supermicro C7SIM-Q  Q57 Int.  Dual DDR3-1333  9-9-9-24 CR1  3784 MB/s
Nano X2 L4350  1600 MHz  VIA EPIA-M900  VX900H Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  2916 MB/s
C7  1500 MHz  VIA EPIA EN  CN700 Int.  DDR2-533 SDRAM  4-4-4-12 CR2  1617 MB/s
12x Opteron 2431  2400 MHz  Supermicro H8DI3+-F  SR5690  Unganged Dual DDR2-800R  6-6-6-18 CR1  1526 MB/s
C3  1333 MHz  VIA EPIA SP  CN400 Int.  DDR400 SDRAM  3-3-3-8 CR2  1466 MB/s
Nano L2200  1600 MHz  VIA VB8001  CN896 Int.  DDR2-667 SDRAM  5-5-5-15 CR2  1455 MB/s
4x Atom Z3740  1866 MHz  [ TRIAL VERSION ]  BayTrailT Int.  Dual DDR3-1066  8-10-8-32 CR1  1395 MB/s
8x Xeon X5550 HT  2666 MHz  Supermicro X8DTN+  i5520  Triple DDR3-1333  9-9-9-24 CR1  1103 MB/s
6x Phenom II X6 Black 1100T  3300 MHz  Gigabyte GA-890GPA-UD3H v2  AMD890GX Int.  Unganged Dual DDR3-1333  9-9-9-24 CR2  1066 MB/s
8x Opteron 2378  2400 MHz  Tyan Thunder n3600R  nForcePro-3600  Unganged Dual DDR2-800R  6-6-6-18 CR1  1017 MB/s
8x Xeon E5462  2800 MHz  Intel S5400SF  i5400  Quad DDR2-640FB  5-5-5-15  1012 MB/s
8x Opteron 2344 HE  1700 MHz  Supermicro H8DME-2  nForcePro-3600  Unganged Dual DDR2-667R  5-5-5-15 CR1  694 MB/s
4x Core i7-965 Extreme HT  3200 MHz  Asus P6T Deluxe  X58  Triple DDR3-1333  9-9-9-24 CR1  691 MB/s
8x Xeon L5320  1866 MHz  Intel S5000VCL  i5000V  Dual DDR2-533FB  4-4-4-12  674 MB/s
4x Phenom II X4 Black 940  3000 MHz  Asus M3N78-EM  GeForce8300 Int.  Ganged Dual DDR2-800  5-5-5-18 CR2  643 MB/s
4x A8-3850  2900 MHz  Gigabyte GA-A75M-UD2H  A75 Int.  Dual DDR3-1333  9-9-9-24 CR1  643 MB/s
4x Core 2 Extreme QX9650  3000 MHz  Gigabyte GA-EP35C-DS3R  P35  Dual DDR3-1066  8-8-8-20 CR2  544 MB/s
4x Core 2 Extreme QX6700  2666 MHz  Intel D975XBX2  i975X  Dual DDR2-667  5-5-5-15  483 MB/s
4x Xeon X3430  2400 MHz  Supermicro X8SIL-F  i3420  Dual DDR3-1333  9-9-9-24 CR1  460 MB/s
4x Phenom X4 9500  2200 MHz  Asus M3A  AMD770  Ganged Dual DDR2-800  5-5-5-18 CR2  446 MB/s
4x Xeon 5140  2333 MHz  Intel S5000VSA  i5000V  Dual DDR2-667FB  5-5-5-15  419 MB/s
4x Opteron 2210 HE  1800 MHz  Tyan Thunder h2000M  BCM5785  Dual DDR2-600R  5-5-5-15 CR1  332 MB/s
2x Athlon64 X2 Black 6400+  3200 MHz  MSI K9N SLI Platinum  nForce570SLI  Dual DDR2-800  4-4-4-11 CR1  295 MB/s
2x Core 2 Extreme X6800  2933 MHz  Abit AB9  P965  Dual DDR2-800  5-5-5-18 CR2  266 MB/s
2x Xeon  3066 MHz  Asus PCH-DL  i875P + PAT  Dual DDR333  2.5-3-3-7  247 MB/s
2x Pentium EE 955 HT  3466 MHz  Intel D955XBK  i955X  Dual DDR2-667  4-4-4-11  245 MB/s
2x Xeon HT  3400 MHz  Intel SE7320SP2  iE7320  Dual DDR333R  2.5-3-3-7  238 MB/s
2x Pentium D 820  2800 MHz  Abit Fatal1ty F-I90HD  RS600 Int.  Dual DDR2-800  5-5-5-18 CR2  214 MB/s
2x Core 2 Duo P8400  2266 MHz  MSI MegaBook PR201  GM45 Int.  Dual DDR2-667  5-5-5-15  204 MB/s
2x Athlon64 X2 4000+  2100 MHz  ASRock ALiveNF7G-HDready  nForce7050-630a Int.  Dual DDR2-700  5-5-5-18 CR2  192 MB/s
2x Core Duo T2500  2000 MHz  Asus N4L-VM DH  i945GT Int.  Dual DDR2-667  5-5-5-15  179 MB/s
P4EE  3466 MHz  ASRock 775Dual-880Pro  PT880Pro  Dual DDR2-400  3-3-3-8 CR2  139 MB/s
P4EE HT  3733 MHz  Intel SE7230NH1LX  iE7230  Dual DDR2-667  5-5-5-15  131 MB/s
2x E-350  1600 MHz  ASRock E350M1  A50M Int.  DDR3-1066 SDRAM  8-8-8-20 CR1  130 MB/s
2x Opteron 240  1400 MHz  MSI K8D Master3-133 FS  AMD8100  Dual DDR400R  3-4-4-8 CR1  128 MB/s
P4  2800 MHz  MSI 848P Neo-S  i848P  DDR400 SDRAM  2.5-3-3-8  112 MB/s
2x PIII-S  1266 MHz  MSI Pro266TD Master-LR  ApolloPro266TD  DDR266 SDRAM  2-3-3-6 CR2  104 MB/s
Opteron 248  2200 MHz  MSI K8T Master1-FAR  K8T800  Dual DDR266R  2-3-3-6 CR1  102 MB/s
P4  2400 MHz  Abit SI7  SiSR658  Dual PC1066 RDRAM  -  97 MB/s
Celeron D 326  2533 MHz  ASRock 775Twins-HDTV  RC410 Ext.  DDR2-533 SDRAM  4-4-4-11  97 MB/s
Athlon64 3200+  2000 MHz  ASRock 939S56-M  SiS756  Dual DDR400  2.5-3-3-8 CR2  92 MB/s
AthlonXP 3200+  2200 MHz  Asus A7N8X-E  nForce2-U400  Dual DDR400  2.5-4-4-8 CR1  89 MB/s
Celeron  2000 MHz  Gigabyte GA-8TRS350MT  RS350 Int.  Dual DDR400  2-2-4-6 CR1  81 MB/s
Sempron 2600+  1600 MHz  ASRock K8NF4G-SATA2  GeForce6100 Int.  DDR400 SDRAM  2.5-3-3-8 CR2  74 MB/s
2x Atom D2500  1866 MHz  Intel D2500CC  NM10 Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  73 MB/s
Celeron 420  1600 MHz  Intel DQ965GF  Q965 Int.  Dual DDR2-667  5-5-5-15  72 MB/s
Pentium M 730  1600 MHz  AOpen i915Ga-HFS  i915G Int.  Dual DDR2-533  4-4-4-12  71 MB/s
Duron  1600 MHz  MSI KT6V-LSR  KT600  DDR400 SDRAM  3-3-3-8 CR2  65 MB/s
Celeron  1700 MHz  Asus P4B  i845  PC133 SDRAM  3-3-3-6  65 MB/s
P4  1600 MHz  Abit TH7II  i850  Dual PC800 RDRAM  -  63 MB/s
2x PIII-E  733 MHz  Tyan Thunder 2500  ServerSet3HE  PC133R SDRAM  3-3-3-6  60 MB/s
Celeron 215  1333 MHz  Intel D201GLY  SiS662 Int.  DDR2-533  5-4-4-12  60 MB/s
Celeron M 320  1300 MHz  DFI 855GME-MGF  i855GME Int.  DDR333 SDRAM  2.5-3-3-7  58 MB/s
Athlon  1400 MHz  PCChips M817LMR  MAGiK1  DDR266 SDRAM  2-2-2-6  57 MB/s
AthlonXP 1600+  1400 MHz  Acorp 7KMM1  KM133A Int.  PC133 SDRAM  3-3-3-6  57 MB/s
Atom 230 HT  1600 MHz  Intel D945GCLF  i945GC Int.  DDR2-533 SDRAM  4-4-4-12  43 MB/s
Efficeon 8600  1000 MHz  ECS 532 Notebook  Efficeon  DDR266 SDRAM    41 MB/s
2x PIII  500 MHz  Epox KP6-BS  i440BX  PC100R SDRAM  3-3-3-?  40 MB/s
Athlon  750 MHz  Epox EP-7KXA  KX133  PC133 SDRAM  3-3-3-6  30 MB/s
Celeron  700 MHz  PCChips M758LT  SiS630ET Int.  PC100 SDRAM  3-3-3-6  29 MB/s
2x PII  333 MHz  Intel DK440LX  i440LX  PC66 SDRAM  3-2-2-?  27 MB/s
Crusoe 5800  1000 MHz  ECS A530 DeskNote  Crusoe  DDR266 SDRAM    25 MB/s
Duron  600 MHz  Abit KG7-Lite  AMD-760  DDR200R SDRAM  2-2-2-5  24 MB/s
PIII  450 MHz  Asus P3C-S  i820  PC600 RDRAM  -  18 MB/s
2x PentiumPro  200 MHz  Compaq ProLiant 800  i440FX  Dual EDO  -  16 MB/s
K6-III  400 MHz  Epox EP-MVP3G-M  MVP3  PC100 SDRAM  2-2-2-5  13 MB/s
Celeron  266 MHz  Epox P2-100B  ApolloPro  PC66 SDRAM  3-2-2-5  10 MB/s
K6-2  333 MHz  Amptron PM-9100LMR  SiS5597 Ext.  PC66 SDRAM  3-3-3-6  9 MB/s
C3  800 MHz  VIA EPIA  PLE133 Int.  PC133 SDRAM  3-3-3-6  9 MB/s
2x PentiumMMX  200 MHz  Gigabyte GA-586DX  i430HX  Dual EDO  -  6 MB/s
K5 PR166  116 MHz  Asus P5A  ALADDiN5  PC66 SDRAM  2-2-2-6  4 MB/s
MediaGXm  233 MHz  ALD NPC6836  Cx5520  PC60 SDRAM  3-3-3-6  3 MB/s
Pentium  166 MHz  Asus TX97-X  i430TX  PC66 SDRAM  2-2-3-4  2 MB/s


CPU Hash

 
CPU  CPU Clock  Motherboard  Chipset  Memory  CL-RCD-RP-RAS  Score
32x Opteron 6274  2200 MHz  Supermicro H8DGI-F  SR5690  Dual DDR3-1600R  11-11-11-28 CR1  8923 MB/s
16x Xeon E5-2670 HT  2600 MHz  Supermicro X9DR6-F  C600  Quad DDR3-1333  9-9-9-24  8688 MB/s
12x Opteron 2431  2400 MHz  Supermicro H8DI3+-F  SR5690  Unganged Dual DDR2-800R  6-6-6-18 CR1  4806 MB/s
6x Core i7-4930K HT  3400 MHz  Gigabyte GA-X79-UD3  X79  Quad DDR3-1866  9-10-9-27 CR2  4371 MB/s
8x FX-8350  4000 MHz  Asus M5A99X Evo R2.0  AMD990X  Dual DDR3-1866  9-10-9-27 CR2  4077 MB/s
6x Core i7-3960X Extreme HT  3300 MHz  Intel DX79SI  X79  Quad DDR3-1600  9-9-9-24 CR2  3910 MB/s
8x FX-8150  3600 MHz  Asus M5A97  AMD970  Dual DDR3-1866  9-10-9-27 CR2  3661 MB/s
8x Xeon E5462  2800 MHz  Intel S5400SF  i5400  Quad DDR2-640FB  5-5-5-15  3559 MB/s
6x Phenom II X6 Black 1100T  3300 MHz  Gigabyte GA-890GPA-UD3H v2  AMD890GX Int.  Unganged Dual DDR3-1333  9-9-9-24 CR2  3315 MB/s
6x Core i7-990X Extreme HT  3466 MHz  Intel DX58SO2  X58  Triple DDR3-1333  9-9-9-24 CR1  3244 MB/s
8x Opteron 2378  2400 MHz  Tyan Thunder n3600R  nForcePro-3600  Unganged Dual DDR2-800R  6-6-6-18 CR1  3204 MB/s
8x Xeon X5550 HT  2666 MHz  Supermicro X8DTN+  i5520  Triple DDR3-1333  9-9-9-24 CR1  3198 MB/s
4x Core i7-3770K HT  3500 MHz  MSI Z77A-GD55  Z77 Int.  Dual DDR3-1600  9-9-9-24 CR2  2994 MB/s
4x Xeon E3-1245 v3 HT  3400 MHz  Supermicro X10SAE  C226 Int.  Dual DDR3-1600  11-11-11-28 CR1  2952 MB/s
4x Core i7-2600 HT  3400 MHz  Asus P8P67  P67  Dual DDR3-1333  9-9-9-24 CR1  2541 MB/s
8x Xeon L5320  1866 MHz  Intel S5000VCL  i5000V  Dual DDR2-533FB  4-4-4-12  2332 MB/s
8x Opteron 2344 HE  1700 MHz  Supermicro H8DME-2  nForcePro-3600  Unganged Dual DDR2-667R  5-5-5-15 CR1  2260 MB/s
4x A10-6800K  4100 MHz  Gigabyte GA-F2A85X-UP4  A85X Int.  Dual DDR3-2133  9-11-10-27 CR2  2143 MB/s
4x Core i7-965 Extreme HT  3200 MHz  Asus P6T Deluxe  X58  Triple DDR3-1333  9-9-9-24 CR1  2004 MB/s
4x Phenom II X4 Black 940  3000 MHz  Asus M3N78-EM  GeForce8300 Int.  Ganged Dual DDR2-800  5-5-5-18 CR2  2002 MB/s
4x A10-5800K  3800 MHz  Asus F2A55-M  A55 Int.  Dual DDR3-1866  9-10-9-27 CR2  1968 MB/s
4x A8-3850  2900 MHz  Gigabyte GA-A75M-UD2H  A75 Int.  Dual DDR3-1333  9-9-9-24 CR1  1935 MB/s
4x Core 2 Extreme QX9650  3000 MHz  Gigabyte GA-EP35C-DS3R  P35  Dual DDR3-1066  8-8-8-20 CR2  1911 MB/s
4x Xeon X3430  2400 MHz  Supermicro X8SIL-F  i3420  Dual DDR3-1333  9-9-9-24 CR1  1680 MB/s
4x Core 2 Extreme QX6700  2666 MHz  Intel D975XBX2  i975X  Dual DDR2-667  5-5-5-15  1677 MB/s
4x Xeon 5140  2333 MHz  Intel S5000VSA  i5000V  Dual DDR2-667FB  5-5-5-15  1461 MB/s
4x Phenom X4 9500  2200 MHz  Asus M3A  AMD770  Ganged Dual DDR2-800  5-5-5-18 CR2  1455 MB/s
4x Opteron 2210 HE  1800 MHz  Tyan Thunder h2000M  BCM5785  Dual DDR2-600R  5-5-5-15 CR1  1088 MB/s
2x Core i5-650 HT  3200 MHz  Supermicro C7SIM-Q  Q57 Int.  Dual DDR3-1333  9-9-9-24 CR1  998 MB/s
Nano X2 L4350  1600 MHz  VIA EPIA-M900  VX900H Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  978 MB/s
2x Athlon64 X2 Black 6400+  3200 MHz  MSI K9N SLI Platinum  nForce570SLI  Dual DDR2-800  4-4-4-11 CR1  969 MB/s
2x Core 2 Extreme X6800  2933 MHz  Abit AB9  P965  Dual DDR2-800  5-5-5-18 CR2  923 MB/s
2x Pentium EE 955 HT  3466 MHz  Intel D955XBK  i955X  Dual DDR2-667  4-4-4-11  769 MB/s
2x Xeon HT  3400 MHz  Intel SE7320SP2  iE7320  Dual DDR333R  2.5-3-3-7  752 MB/s
2x Core 2 Duo P8400  2266 MHz  MSI MegaBook PR201  GM45 Int.  Dual DDR2-667  5-5-5-15  717 MB/s
4x Atom Z3740  1866 MHz  [ TRIAL VERSION ]  BayTrailT Int.  Dual DDR3-1066  8-10-8-32 CR1  640 MB/s
2x Athlon64 X2 4000+  2100 MHz  ASRock ALiveNF7G-HDready  nForce7050-630a Int.  Dual DDR2-700  5-5-5-18 CR2  634 MB/s
2x Xeon  3066 MHz  Asus PCH-DL  i875P + PAT  Dual DDR333  2.5-3-3-7  614 MB/s
2x Pentium D 820  2800 MHz  Abit Fatal1ty F-I90HD  RS600 Int.  Dual DDR2-800  5-5-5-18 CR2  575 MB/s
Nano L2200  1600 MHz  VIA VB8001  CN896 Int.  DDR2-667 SDRAM  5-5-5-15 CR2  493 MB/s
2x Opteron 240  1400 MHz  MSI K8D Master3-133 FS  AMD8100  Dual DDR400R  3-4-4-8 CR1  423 MB/s
2x Core Duo T2500  2000 MHz  Asus N4L-VM DH  i945GT Int.  Dual DDR2-667  5-5-5-15  416 MB/s
P4EE HT  3733 MHz  Intel SE7230NH1LX  iE7230  Dual DDR2-667  5-5-5-15  412 MB/s
C7  1500 MHz  VIA EPIA EN  CN700 Int.  DDR2-533 SDRAM  4-4-4-12 CR2  360 MB/s
P4EE  3466 MHz  ASRock 775Dual-880Pro  PT880Pro  Dual DDR2-400  3-3-3-8 CR2  345 MB/s
2x Atom D2500  1866 MHz  Intel D2500CC  NM10 Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  343 MB/s
Opteron 248  2200 MHz  MSI K8T Master1-FAR  K8T800  Dual DDR266R  2-3-3-6 CR1  333 MB/s
2x E-350  1600 MHz  ASRock E350M1  A50M Int.  DDR3-1066 SDRAM  8-8-8-20 CR1  322 MB/s
Athlon64 3200+  2000 MHz  ASRock 939S56-M  SiS756  Dual DDR400  2.5-3-3-8 CR2  303 MB/s
AthlonXP 3200+  2200 MHz  Asus A7N8X-E  nForce2-U400  Dual DDR400  2.5-4-4-8 CR1  284 MB/s
P4  2800 MHz  MSI 848P Neo-S  i848P  DDR400 SDRAM  2.5-3-3-8  279 MB/s
Celeron D 326  2533 MHz  ASRock 775Twins-HDTV  RC410 Ext.  DDR2-533 SDRAM  4-4-4-11  259 MB/s
Celeron 420  1600 MHz  Intel DQ965GF  Q965 Int.  Dual DDR2-667  5-5-5-15  251 MB/s
2x PIII-S  1266 MHz  MSI Pro266TD Master-LR  ApolloPro266TD  DDR266 SDRAM  2-3-3-6 CR2  247 MB/s
Sempron 2600+  1600 MHz  ASRock K8NF4G-SATA2  GeForce6100 Int.  DDR400 SDRAM  2.5-3-3-8 CR2  243 MB/s
P4  2400 MHz  Abit SI7  SiSR658  Dual PC1066 RDRAM  -  241 MB/s
Duron  1600 MHz  MSI KT6V-LSR  KT600  DDR400 SDRAM  3-3-3-8 CR2  207 MB/s
Celeron  2000 MHz  Gigabyte GA-8TRS350MT  RS350 Int.  Dual DDR400  2-2-4-6 CR1  202 MB/s
Athlon  1400 MHz  PCChips M817LMR  MAGiK1  DDR266 SDRAM  2-2-2-6  181 MB/s
AthlonXP 1600+  1400 MHz  Acorp 7KMM1  KM133A Int.  PC133 SDRAM  3-3-3-6  181 MB/s
Efficeon 8600  1000 MHz  ECS 532 Notebook  Efficeon  DDR266 SDRAM    170 MB/s
Pentium M 730  1600 MHz  AOpen i915Ga-HFS  i915G Int.  Dual DDR2-533  4-4-4-12  166 MB/s
Atom 230 HT  1600 MHz  Intel D945GCLF  i945GC Int.  DDR2-533 SDRAM  4-4-4-12  162 MB/s
Celeron  1700 MHz  Asus P4B  i845  PC133 SDRAM  3-3-3-6  160 MB/s
P4  1600 MHz  Abit TH7II  i850  Dual PC800 RDRAM  -  150 MB/s
2x PIII-E  733 MHz  Tyan Thunder 2500  ServerSet3HE  PC133R SDRAM  3-3-3-6  143 MB/s
Celeron 215  1333 MHz  Intel D201GLY  SiS662 Int.  DDR2-533  5-4-4-12  139 MB/s
Celeron M 320  1300 MHz  DFI 855GME-MGF  i855GME Int.  DDR333 SDRAM  2.5-3-3-7  136 MB/s
2x PIII  500 MHz  Epox KP6-BS  i440BX  PC100R SDRAM  3-3-3-?  98 MB/s
Athlon  750 MHz  Epox EP-7KXA  KX133  PC133 SDRAM  3-3-3-6  97 MB/s
Crusoe 5800  1000 MHz  ECS A530 DeskNote  Crusoe  DDR266 SDRAM    88 MB/s
Duron  600 MHz  Abit KG7-Lite  AMD-760  DDR200R SDRAM  2-2-2-5  77 MB/s
Celeron  700 MHz  PCChips M758LT  SiS630ET Int.  PC100 SDRAM  3-3-3-6  68 MB/s
2x PII  333 MHz  Intel DK440LX  i440LX  PC66 SDRAM  3-2-2-?  63 MB/s
C3  1333 MHz  VIA EPIA SP  CN400 Int.  DDR400 SDRAM  3-3-3-8 CR2  59 MB/s
PIII  450 MHz  Asus P3C-S  i820  PC600 RDRAM  -  44 MB/s
C3  800 MHz  VIA EPIA  PLE133 Int.  PC133 SDRAM  3-3-3-6  35 MB/s
2x PentiumPro  200 MHz  Compaq ProLiant 800  i440FX  Dual EDO  -  34 MB/s
Celeron  266 MHz  Epox P2-100B  ApolloPro  PC66 SDRAM  3-2-2-5  25 MB/s
K6-III  400 MHz  Epox EP-MVP3G-M  MVP3  PC100 SDRAM  2-2-2-5  24 MB/s
2x PentiumMMX  200 MHz  Gigabyte GA-586DX  i430HX  Dual EDO  -  24 MB/s
K6-2  333 MHz  Amptron PM-9100LMR  SiS5597 Ext.  PC66 SDRAM  3-3-3-6  19 MB/s
K5 PR166  116 MHz  Asus P5A  ALADDiN5  PC66 SDRAM  2-2-2-6  11 MB/s
Pentium  166 MHz  Asus TX97-X  i430TX  PC66 SDRAM  2-2-3-4  10 MB/s
MediaGXm  233 MHz  ALD NPC6836  Cx5520  PC60 SDRAM  3-3-3-6  8 MB/s


FPU VP8

 
CPU  CPU Clock  Motherboard  Chipset  Memory  CL-RCD-RP-RAS  Score
6x Core i7-4930K HT  3400 MHz  Gigabyte GA-X79-UD3  X79  Quad DDR3-1866  9-10-9-27 CR2  5979
16x Xeon E5-2670 HT  2600 MHz  Supermicro X9DR6-F  C600  Quad DDR3-1333  9-9-9-24  5838
6x Core i7-3960X Extreme HT  3300 MHz  Intel DX79SI  X79  Quad DDR3-1600  9-9-9-24 CR2  5700
4x Core i7-3770K HT  3500 MHz  MSI Z77A-GD55  Z77 Int.  Dual DDR3-1600  9-9-9-24 CR2  5599
4x Xeon E3-1245 v3 HT  3400 MHz  Supermicro X10SAE  C226 Int.  Dual DDR3-1600  11-11-11-28 CR1  5455
6x Core i7-990X Extreme HT  3466 MHz  Intel DX58SO2  X58  Triple DDR3-1333  9-9-9-24 CR1  4936
8x FX-8350  4000 MHz  Asus M5A99X Evo R2.0  AMD990X  Dual DDR3-1866  9-10-9-27 CR2  4774
8x Xeon E5462  2800 MHz  Intel S5400SF  i5400  Quad DDR2-640FB  5-5-5-15  4600
4x Core i7-2600 HT  3400 MHz  Asus P8P67  P67  Dual DDR3-1333  9-9-9-24 CR1  4376
8x Xeon X5550 HT  2666 MHz  Supermicro X8DTN+  i5520  Triple DDR3-1333  9-9-9-24 CR1  4296
4x Core i7-965 Extreme HT  3200 MHz  Asus P6T Deluxe  X58  Triple DDR3-1333  9-9-9-24 CR1  4276
8x FX-8150  3600 MHz  Asus M5A97  AMD970  Dual DDR3-1866  9-10-9-27 CR2  4060
6x Phenom II X6 Black 1100T  3300 MHz  Gigabyte GA-890GPA-UD3H v2  AMD890GX Int.  Unganged Dual DDR3-1333  9-9-9-24 CR2  3968
12x Opteron 2431  2400 MHz  Supermicro H8DI3+-F  SR5690  Unganged Dual DDR2-800R  6-6-6-18 CR1  3592
4x Core 2 Extreme QX9650  3000 MHz  Gigabyte GA-EP35C-DS3R  P35  Dual DDR3-1066  8-8-8-20 CR2  3584
4x A10-6800K  4100 MHz  Gigabyte GA-F2A85X-UP4  A85X Int.  Dual DDR3-2133  9-11-10-27 CR2  3408
8x Opteron 2378  2400 MHz  Tyan Thunder n3600R  nForcePro-3600  Unganged Dual DDR2-800R  6-6-6-18 CR1  3381
4x Xeon X3430  2400 MHz  Supermicro X8SIL-F  i3420  Dual DDR3-1333  9-9-9-24 CR1  3298
32x Opteron 6274  2200 MHz  Supermicro H8DGI-F  SR5690  Dual DDR3-1600R  11-11-11-28 CR1  3125
4x A10-5800K  3800 MHz  Asus F2A55-M  A55 Int.  Dual DDR3-1866  9-10-9-27 CR2  3030
4x A8-3850  2900 MHz  Gigabyte GA-A75M-UD2H  A75 Int.  Dual DDR3-1333  9-9-9-24 CR1  3012
2x Core i5-650 HT  3200 MHz  Supermicro C7SIM-Q  Q57 Int.  Dual DDR3-1333  9-9-9-24 CR1  2906
4x Phenom II X4 Black 940  3000 MHz  Asus M3N78-EM  GeForce8300 Int.  Ganged Dual DDR2-800  5-5-5-18 CR2  2858
8x Opteron 2344 HE  1700 MHz  Supermicro H8DME-2  nForcePro-3600  Unganged Dual DDR2-667R  5-5-5-15 CR1  2336
4x Core 2 Extreme QX6700  2666 MHz  Intel D975XBX2  i975X  Dual DDR2-667  5-5-5-15  2320
8x Xeon L5320  1866 MHz  Intel S5000VCL  i5000V  Dual DDR2-533FB  4-4-4-12  2304
4x Phenom X4 9500  2200 MHz  Asus M3A  AMD770  Ganged Dual DDR2-800  5-5-5-18 CR2  2211
4x Xeon 5140  2333 MHz  Intel S5000VSA  i5000V  Dual DDR2-667FB  5-5-5-15  2196
2x Core 2 Extreme X6800  2933 MHz  Abit AB9  P965  Dual DDR2-800  5-5-5-18 CR2  1646
2x Core 2 Duo P8400  2266 MHz  MSI MegaBook PR201  GM45 Int.  Dual DDR2-667  5-5-5-15  1566
4x Atom Z3740  1866 MHz  [ TRIAL VERSION ]  BayTrailT Int.  Dual DDR3-1066  8-10-8-32 CR1  1531
2x Athlon64 X2 Black 6400+  3200 MHz  MSI K9N SLI Platinum  nForce570SLI  Dual DDR2-800  4-4-4-11 CR1  1508
4x Opteron 2210 HE  1800 MHz  Tyan Thunder h2000M  BCM5785  Dual DDR2-600R  5-5-5-15 CR1  1443
2x Xeon HT  3400 MHz  Intel SE7320SP2  iE7320  Dual DDR333R  2.5-3-3-7  1150
2x Pentium EE 955 HT  3466 MHz  Intel D955XBK  i955X  Dual DDR2-667  4-4-4-11  1127
2x Athlon64 X2 4000+  2100 MHz  ASRock ALiveNF7G-HDready  nForce7050-630a Int.  Dual DDR2-700  5-5-5-18 CR2  1095
Nano X2 L4350  1600 MHz  VIA EPIA-M900  VX900H Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  1018
2x Pentium D 820  2800 MHz  Abit Fatal1ty F-I90HD  RS600 Int.  Dual DDR2-800  5-5-5-18 CR2  1013
2x Core Duo T2500  2000 MHz  Asus N4L-VM DH  i945GT Int.  Dual DDR2-667  5-5-5-15  997
P4EE HT  3733 MHz  Intel SE7230NH1LX  iE7230  Dual DDR2-667  5-5-5-15  929
2x Xeon  3066 MHz  Asus PCH-DL  i875P + PAT  Dual DDR333  2.5-3-3-7  829
2x Atom D2500  1866 MHz  Intel D2500CC  NM10 Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  792
Athlon64 3200+  2000 MHz  ASRock 939S56-M  SiS756  Dual DDR400  2.5-3-3-8 CR2  755
2x E-350  1600 MHz  ASRock E350M1  A50M Int.  DDR3-1066 SDRAM  8-8-8-20 CR1  745
Celeron 420  1600 MHz  Intel DQ965GF  Q965 Int.  Dual DDR2-667  5-5-5-15  681
2x Opteron 240  1400 MHz  MSI K8D Master3-133 FS  AMD8100  Dual DDR400R  3-4-4-8 CR1  657
P4EE  3466 MHz  ASRock 775Dual-880Pro  PT880Pro  Dual DDR2-400  3-3-3-8 CR2  642
Sempron 2600+  1600 MHz  ASRock K8NF4G-SATA2  GeForce6100 Int.  DDR400 SDRAM  2.5-3-3-8 CR2  617
Opteron 248  2200 MHz  MSI K8T Master1-FAR  K8T800  Dual DDR266R  2-3-3-6 CR1  586
Celeron D 326  2533 MHz  ASRock 775Twins-HDTV  RC410 Ext.  DDR2-533 SDRAM  4-4-4-11  578
P4  2800 MHz  MSI 848P Neo-S  i848P  DDR400 SDRAM  2.5-3-3-8  544
Atom 230 HT  1600 MHz  Intel D945GCLF  i945GC Int.  DDR2-533 SDRAM  4-4-4-12  494
Celeron 215  1333 MHz  Intel D201GLY  SiS662 Int.  DDR2-533  5-4-4-12  489
P4  2400 MHz  Abit SI7  SiSR658  Dual PC1066 RDRAM  -  488
Nano L2200  1600 MHz  VIA VB8001  CN896 Int.  DDR2-667 SDRAM  5-5-5-15 CR2  487
Pentium M 730  1600 MHz  AOpen i915Ga-HFS  i915G Int.  Dual DDR2-533  4-4-4-12  487
AthlonXP 3200+  2200 MHz  Asus A7N8X-E  nForce2-U400  Dual DDR400  2.5-4-4-8 CR1  457
2x PIII-S  1266 MHz  MSI Pro266TD Master-LR  ApolloPro266TD  DDR266 SDRAM  2-3-3-6 CR2  400
Celeron M 320  1300 MHz  DFI 855GME-MGF  i855GME Int.  DDR333 SDRAM  2.5-3-3-7  386
Celeron  2000 MHz  Gigabyte GA-8TRS350MT  RS350 Int.  Dual DDR400  2-2-4-6 CR1  375
P4  1600 MHz  Abit TH7II  i850  Dual PC800 RDRAM  -  359
Duron  1600 MHz  MSI KT6V-LSR  KT600  DDR400 SDRAM  3-3-3-8 CR2  358
Celeron  1700 MHz  Asus P4B  i845  PC133 SDRAM  3-3-3-6  343
C7  1500 MHz  VIA EPIA EN  CN700 Int.  DDR2-533 SDRAM  4-4-4-12 CR2  315
AthlonXP 1600+  1400 MHz  Acorp 7KMM1  KM133A Int.  PC133 SDRAM  3-3-3-6  313
Athlon  1400 MHz  PCChips M817LMR  MAGiK1  DDR266 SDRAM  2-2-2-6  313
2x PIII-E  733 MHz  Tyan Thunder 2500  ServerSet3HE  PC133R SDRAM  3-3-3-6  269
Efficeon 8600  1000 MHz  ECS 532 Notebook  Efficeon  DDR266 SDRAM    239
Athlon  750 MHz  Epox EP-7KXA  KX133  PC133 SDRAM  3-3-3-6  199
Crusoe 5800  1000 MHz  ECS A530 DeskNote  Crusoe  DDR266 SDRAM    197
PIII  450 MHz  Asus P3C-S  i820  PC600 RDRAM  -  182
2x PIII  500 MHz  Epox KP6-BS  i440BX  PC100R SDRAM  3-3-3-?  180
Duron  600 MHz  Abit KG7-Lite  AMD-760  DDR200R SDRAM  2-2-2-5  163
Celeron  700 MHz  PCChips M758LT  SiS630ET Int.  PC100 SDRAM  3-3-3-6  148
C3  800 MHz  VIA EPIA  PLE133 Int.  PC133 SDRAM  3-3-3-6  139
K6-III  400 MHz  Epox EP-MVP3G-M  MVP3  PC100 SDRAM  2-2-2-5  137
2x PII  333 MHz  Intel DK440LX  i440LX  PC66 SDRAM  3-2-2-?  119
C3  1333 MHz  VIA EPIA SP  CN400 Int.  DDR400 SDRAM  3-3-3-8 CR2  104
K6-2  333 MHz  Amptron PM-9100LMR  SiS5597 Ext.  PC66 SDRAM  3-3-3-6  96
2x PentiumMMX  200 MHz  Gigabyte GA-586DX  i430HX  Dual EDO  -  95
Celeron  266 MHz  Epox P2-100B  ApolloPro  PC66 SDRAM  3-2-2-5  94
K5 PR166  116 MHz  Asus P5A  ALADDiN5  PC66 SDRAM  2-2-2-6  64
2x PentiumPro  200 MHz  Compaq ProLiant 800  i440FX  Dual EDO  -  60
Pentium  166 MHz  Asus TX97-X  i430TX  PC66 SDRAM  2-2-3-4  42


FPU Julia

 
CPU  CPU Clock  Motherboard  Chipset  Memory  CL-RCD-RP-RAS  Score
16x Xeon E5-2670 HT  2600 MHz  Supermicro X9DR6-F  C600  Quad DDR3-1333  9-9-9-24  58128
32x Opteron 6274  2200 MHz  Supermicro H8DGI-F  SR5690  Dual DDR3-1600R  11-11-11-28 CR1  28132
4x Xeon E3-1245 v3 HT  3400 MHz  Supermicro X10SAE  C226 Int.  Dual DDR3-1600  11-11-11-28 CR1  26912
6x Core i7-4930K HT  3400 MHz  Gigabyte GA-X79-UD3  X79  Quad DDR3-1866  9-10-9-27 CR2  26601
6x Core i7-3960X Extreme HT  3300 MHz  Intel DX79SI  X79  Quad DDR3-1600  9-9-9-24 CR2  25689
4x Core i7-3770K HT  3500 MHz  MSI Z77A-GD55  Z77 Int.  Dual DDR3-1600  9-9-9-24 CR2  18227
4x Core i7-2600 HT  3400 MHz  Asus P8P67  P67  Dual DDR3-1333  9-9-9-24 CR1  17624
6x Core i7-990X Extreme HT  3466 MHz  Intel DX58SO2  X58  Triple DDR3-1333  9-9-9-24 CR1  17015
8x Xeon X5550 HT  2666 MHz  Supermicro X8DTN+  i5520  Triple DDR3-1333  9-9-9-24 CR1  16843
12x Opteron 2431  2400 MHz  Supermicro H8DI3+-F  SR5690  Unganged Dual DDR2-800R  6-6-6-18 CR1  15624
8x Xeon E5462  2800 MHz  Intel S5400SF  i5400  Quad DDR2-640FB  5-5-5-15  13544
8x FX-8350  4000 MHz  Asus M5A99X Evo R2.0  AMD990X  Dual DDR3-1866  9-10-9-27 CR2  12012
8x FX-8150  3600 MHz  Asus M5A97  AMD970  Dual DDR3-1866  9-10-9-27 CR2  11280
6x Phenom II X6 Black 1100T  3300 MHz  Gigabyte GA-890GPA-UD3H v2  AMD890GX Int.  Unganged Dual DDR3-1333  9-9-9-24 CR2  10785
4x Core i7-965 Extreme HT  3200 MHz  Asus P6T Deluxe  X58  Triple DDR3-1333  9-9-9-24 CR1  10535
8x Opteron 2378  2400 MHz  Tyan Thunder n3600R  nForcePro-3600  Unganged Dual DDR2-800R  6-6-6-18 CR1  10416
8x Xeon L5320  1866 MHz  Intel S5000VCL  i5000V  Dual DDR2-533FB  4-4-4-12  8882
8x Opteron 2344 HE  1700 MHz  Supermicro H8DME-2  nForcePro-3600  Unganged Dual DDR2-667R  5-5-5-15 CR1  7411
4x Core 2 Extreme QX9650  3000 MHz  Gigabyte GA-EP35C-DS3R  P35  Dual DDR3-1066  8-8-8-20 CR2  7281
4x Xeon X3430  2400 MHz  Supermicro X8SIL-F  i3420  Dual DDR3-1333  9-9-9-24 CR1  7077
4x Phenom II X4 Black 940  3000 MHz  Asus M3N78-EM  GeForce8300 Int.  Ganged Dual DDR2-800  5-5-5-18 CR2  6508
4x Core 2 Extreme QX6700  2666 MHz  Intel D975XBX2  i975X  Dual DDR2-667  5-5-5-15  6373
4x A8-3850  2900 MHz  Gigabyte GA-A75M-UD2H  A75 Int.  Dual DDR3-1333  9-9-9-24 CR1  6274
4x A10-6800K  4100 MHz  Gigabyte GA-F2A85X-UP4  A85X Int.  Dual DDR3-2133  9-11-10-27 CR2  6245
4x A10-5800K  3800 MHz  Asus F2A55-M  A55 Int.  Dual DDR3-1866  9-10-9-27 CR2  5744
4x Xeon 5140  2333 MHz  Intel S5000VSA  i5000V  Dual DDR2-667FB  5-5-5-15  5552
2x Core i5-650 HT  3200 MHz  Supermicro C7SIM-Q  Q57 Int.  Dual DDR3-1333  9-9-9-24 CR1  5327
4x Phenom X4 9500  2200 MHz  Asus M3A  AMD770  Ganged Dual DDR2-800  5-5-5-18 CR2  4771
2x Core 2 Extreme X6800  2933 MHz  Abit AB9  P965  Dual DDR2-800  5-5-5-18 CR2  3509
4x Atom Z3740  1866 MHz  [ TRIAL VERSION ]  BayTrailT Int.  Dual DDR3-1066  8-10-8-32 CR1  3031
2x Core 2 Duo P8400  2266 MHz  MSI MegaBook PR201  GM45 Int.  Dual DDR2-667  5-5-5-15  2731
2x Pentium EE 955 HT  3466 MHz  Intel D955XBK  i955X  Dual DDR2-667  4-4-4-11  2307
2x Xeon HT  3400 MHz  Intel SE7320SP2  iE7320  Dual DDR333R  2.5-3-3-7  2255
2x Xeon  3066 MHz  Asus PCH-DL  i875P + PAT  Dual DDR333  2.5-3-3-7  2141
4x Opteron 2210 HE  1800 MHz  Tyan Thunder h2000M  BCM5785  Dual DDR2-600R  5-5-5-15 CR1  2039
2x Athlon64 X2 Black 6400+  3200 MHz  MSI K9N SLI Platinum  nForce570SLI  Dual DDR2-800  4-4-4-11 CR1  1815
2x Pentium D 820  2800 MHz  Abit Fatal1ty F-I90HD  RS600 Int.  Dual DDR2-800  5-5-5-18 CR2  1738
Nano X2 L4350  1600 MHz  VIA EPIA-M900  VX900H Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  1723
P4EE HT  3733 MHz  Intel SE7230NH1LX  iE7230  Dual DDR2-667  5-5-5-15  1239
P4EE  3466 MHz  ASRock 775Dual-880Pro  PT880Pro  Dual DDR2-400  3-3-3-8 CR2  1203
2x Athlon64 X2 4000+  2100 MHz  ASRock ALiveNF7G-HDready  nForce7050-630a Int.  Dual DDR2-700  5-5-5-18 CR2  1187
2x Atom D2500  1866 MHz  Intel D2500CC  NM10 Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  1086
2x Core Duo T2500  2000 MHz  Asus N4L-VM DH  i945GT Int.  Dual DDR2-667  5-5-5-15  1021
P4  2800 MHz  MSI 848P Neo-S  i848P  DDR400 SDRAM  2.5-3-3-8  974
Celeron 420  1600 MHz  Intel DQ965GF  Q965 Int.  Dual DDR2-667  5-5-5-15  954
2x E-350  1600 MHz  ASRock E350M1  A50M Int.  DDR3-1066 SDRAM  8-8-8-20 CR1  914
P4  2400 MHz  Abit SI7  SiSR658  Dual PC1066 RDRAM  -  839
Nano L2200  1600 MHz  VIA VB8001  CN896 Int.  DDR2-667 SDRAM  5-5-5-15 CR2  795
Celeron D 326  2533 MHz  ASRock 775Twins-HDTV  RC410 Ext.  DDR2-533 SDRAM  4-4-4-11  783
2x Opteron 240  1400 MHz  MSI K8D Master3-133 FS  AMD8100  Dual DDR400R  3-4-4-8 CR1  724
Celeron  2000 MHz  Gigabyte GA-8TRS350MT  RS350 Int.  Dual DDR400  2-2-4-6 CR1  703
Opteron 248  2200 MHz  MSI K8T Master1-FAR  K8T800  Dual DDR266R  2-3-3-6 CR1  624
AthlonXP 3200+  2200 MHz  Asus A7N8X-E  nForce2-U400  Dual DDR400  2.5-4-4-8 CR1  607
Celeron  1700 MHz  Asus P4B  i845  PC133 SDRAM  3-3-3-6  594
2x PIII-S  1266 MHz  MSI Pro266TD Master-LR  ApolloPro266TD  DDR266 SDRAM  2-3-3-6 CR2  578
Athlon64 3200+  2000 MHz  ASRock 939S56-M  SiS756  Dual DDR400  2.5-3-3-8 CR2  568
P4  1600 MHz  Abit TH7II  i850  Dual PC800 RDRAM  -  560
Atom 230 HT  1600 MHz  Intel D945GCLF  i945GC Int.  DDR2-533 SDRAM  4-4-4-12  550
Sempron 2600+  1600 MHz  ASRock K8NF4G-SATA2  GeForce6100 Int.  DDR400 SDRAM  2.5-3-3-8 CR2  456
Duron  1600 MHz  MSI KT6V-LSR  KT600  DDR400 SDRAM  3-3-3-8 CR2  443
Pentium M 730  1600 MHz  AOpen i915Ga-HFS  i915G Int.  Dual DDR2-533  4-4-4-12  403
AthlonXP 1600+  1400 MHz  Acorp 7KMM1  KM133A Int.  PC133 SDRAM  3-3-3-6  385
Athlon  1400 MHz  PCChips M817LMR  MAGiK1  DDR266 SDRAM  2-2-2-6  381
Celeron 215  1333 MHz  Intel D201GLY  SiS662 Int.  DDR2-533  5-4-4-12  340
Celeron M 320  1300 MHz  DFI 855GME-MGF  i855GME Int.  DDR333 SDRAM  2.5-3-3-7  332
Efficeon 8600  1000 MHz  ECS 532 Notebook  Efficeon  DDR266 SDRAM    327
2x PIII-E  733 MHz  Tyan Thunder 2500  ServerSet3HE  PC133R SDRAM  3-3-3-6  321
C7  1500 MHz  VIA EPIA EN  CN700 Int.  DDR2-533 SDRAM  4-4-4-12 CR2  231
2x PIII  500 MHz  Epox KP6-BS  i440BX  PC100R SDRAM  3-3-3-?  220
Athlon  750 MHz  Epox EP-7KXA  KX133  PC133 SDRAM  3-3-3-6  206
Duron  600 MHz  Abit KG7-Lite  AMD-760  DDR200R SDRAM  2-2-2-5  165
Celeron  700 MHz  PCChips M758LT  SiS630ET Int.  PC100 SDRAM  3-3-3-6  149
C3  1333 MHz  VIA EPIA SP  CN400 Int.  DDR400 SDRAM  3-3-3-8 CR2  146
PIII  450 MHz  Asus P3C-S  i820  PC600 RDRAM  -  100
K6-III  400 MHz  Epox EP-MVP3G-M  MVP3  PC100 SDRAM  2-2-2-5  86
C3  800 MHz  VIA EPIA  PLE133 Int.  PC133 SDRAM  3-3-3-6  80
K6-2  333 MHz  Amptron PM-9100LMR  SiS5597 Ext.  PC66 SDRAM  3-3-3-6  71
Crusoe 5800  1000 MHz  ECS A530 DeskNote  Crusoe  DDR266 SDRAM    61
2x PII  333 MHz  Intel DK440LX  i440LX  PC66 SDRAM  3-2-2-?  61
2x PentiumPro  200 MHz  Compaq ProLiant 800  i440FX  Dual EDO  -  37
2x PentiumMMX  200 MHz  Gigabyte GA-586DX  i430HX  Dual EDO  -  30
Celeron  266 MHz  Epox P2-100B  ApolloPro  PC66 SDRAM  3-2-2-5  25
Pentium  166 MHz  Asus TX97-X  i430TX  PC66 SDRAM  2-2-3-4  13
K5 PR166  116 MHz  Asus P5A  ALADDiN5  PC66 SDRAM  2-2-2-6  8
MediaGXm  233 MHz  ALD NPC6836  Cx5520  PC60 SDRAM  3-3-3-6  4


FPU Mandel

 
CPU  CPU Clock  Motherboard  Chipset  Memory  CL-RCD-RP-RAS  Score
16x Xeon E5-2670 HT  2600 MHz  Supermicro X9DR6-F  C600  Quad DDR3-1333  9-9-9-24  29515
32x Opteron 6274  2200 MHz  Supermicro H8DGI-F  SR5690  Dual DDR3-1600R  11-11-11-28 CR1  14493
4x Xeon E3-1245 v3 HT  3400 MHz  Supermicro X10SAE  C226 Int.  Dual DDR3-1600  11-11-11-28 CR1  14073
6x Core i7-4930K HT  3400 MHz  Gigabyte GA-X79-UD3  X79  Quad DDR3-1866  9-10-9-27 CR2  13559
6x Core i7-3960X Extreme HT  3300 MHz  Intel DX79SI  X79  Quad DDR3-1600  9-9-9-24 CR2  12984
4x Core i7-3770K HT  3500 MHz  MSI Z77A-GD55  Z77 Int.  Dual DDR3-1600  9-9-9-24 CR2  9288
4x Core i7-2600 HT  3400 MHz  Asus P8P67  P67  Dual DDR3-1333  9-9-9-24 CR1  8906
6x Core i7-990X Extreme HT  3466 MHz  Intel DX58SO2  X58  Triple DDR3-1333  9-9-9-24 CR1  8478
8x Xeon X5550 HT  2666 MHz  Supermicro X8DTN+  i5520  Triple DDR3-1333  9-9-9-24 CR1  8382
12x Opteron 2431  2400 MHz  Supermicro H8DI3+-F  SR5690  Unganged Dual DDR2-800R  6-6-6-18 CR1  8047
8x Xeon E5462  2800 MHz  Intel S5400SF  i5400  Quad DDR2-640FB  5-5-5-15  7074
8x FX-8350  4000 MHz  Asus M5A99X Evo R2.0  AMD990X  Dual DDR3-1866  9-10-9-27 CR2  6096
8x FX-8150  3600 MHz  Asus M5A97  AMD970  Dual DDR3-1866  9-10-9-27 CR2  5850
6x Phenom II X6 Black 1100T  3300 MHz  Gigabyte GA-890GPA-UD3H v2  AMD890GX Int.  Unganged Dual DDR3-1333  9-9-9-24 CR2  5555
8x Opteron 2378  2400 MHz  Tyan Thunder n3600R  nForcePro-3600  Unganged Dual DDR2-800R  6-6-6-18 CR1  5365
4x Core i7-965 Extreme HT  3200 MHz  Asus P6T Deluxe  X58  Triple DDR3-1333  9-9-9-24 CR1  5256
8x Xeon L5320  1866 MHz  Intel S5000VCL  i5000V  Dual DDR2-533FB  4-4-4-12  4481
8x Opteron 2344 HE  1700 MHz  Supermicro H8DME-2  nForcePro-3600  Unganged Dual DDR2-667R  5-5-5-15 CR1  3804
4x Core 2 Extreme QX9650  3000 MHz  Gigabyte GA-EP35C-DS3R  P35  Dual DDR3-1066  8-8-8-20 CR2  3802
4x Phenom II X4 Black 940  3000 MHz  Asus M3N78-EM  GeForce8300 Int.  Ganged Dual DDR2-800  5-5-5-18 CR2  3352
4x Xeon X3430  2400 MHz  Supermicro X8SIL-F  i3420  Dual DDR3-1333  9-9-9-24 CR1  3348
4x A10-6800K  4100 MHz  Gigabyte GA-F2A85X-UP4  A85X Int.  Dual DDR3-2133  9-11-10-27 CR2  3323
4x A8-3850  2900 MHz  Gigabyte GA-A75M-UD2H  A75 Int.  Dual DDR3-1333  9-9-9-24 CR1  3310
4x Core 2 Extreme QX6700  2666 MHz  Intel D975XBX2  i975X  Dual DDR2-667  5-5-5-15  3212
4x A10-5800K  3800 MHz  Asus F2A55-M  A55 Int.  Dual DDR3-1866  9-10-9-27 CR2  3042
4x Xeon 5140  2333 MHz  Intel S5000VSA  i5000V  Dual DDR2-667FB  5-5-5-15  2801
2x Core i5-650 HT  3200 MHz  Supermicro C7SIM-Q  Q57 Int.  Dual DDR3-1333  9-9-9-24 CR1  2618
4x Phenom X4 9500  2200 MHz  Asus M3A  AMD770  Ganged Dual DDR2-800  5-5-5-18 CR2  2446
2x Core 2 Extreme X6800  2933 MHz  Abit AB9  P965  Dual DDR2-800  5-5-5-18 CR2  1770
2x Core 2 Duo P8400  2266 MHz  MSI MegaBook PR201  GM45 Int.  Dual DDR2-667  5-5-5-15  1428
4x Opteron 2210 HE  1800 MHz  Tyan Thunder h2000M  BCM5785  Dual DDR2-600R  5-5-5-15 CR1  1180
2x Pentium EE 955 HT  3466 MHz  Intel D955XBK  i955X  Dual DDR2-667  4-4-4-11  1155
2x Xeon HT  3400 MHz  Intel SE7320SP2  iE7320  Dual DDR333R  2.5-3-3-7  1129
2x Xeon  3066 MHz  Asus PCH-DL  i875P + PAT  Dual DDR333  2.5-3-3-7  1096
4x Atom Z3740  1866 MHz  [ TRIAL VERSION ]  BayTrailT Int.  Dual DDR3-1066  8-10-8-32 CR1  1067
2x Athlon64 X2 Black 6400+  3200 MHz  MSI K9N SLI Platinum  nForce570SLI  Dual DDR2-800  4-4-4-11 CR1  1050
2x Pentium D 820  2800 MHz  Abit Fatal1ty F-I90HD  RS600 Int.  Dual DDR2-800  5-5-5-18 CR2  888
Nano X2 L4350  1600 MHz  VIA EPIA-M900  VX900H Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  808
2x Athlon64 X2 4000+  2100 MHz  ASRock ALiveNF7G-HDready  nForce7050-630a Int.  Dual DDR2-700  5-5-5-18 CR2  687
P4EE HT  3733 MHz  Intel SE7230NH1LX  iE7230  Dual DDR2-667  5-5-5-15  620
P4EE  3466 MHz  ASRock 775Dual-880Pro  PT880Pro  Dual DDR2-400  3-3-3-8 CR2  616
2x Core Duo T2500  2000 MHz  Asus N4L-VM DH  i945GT Int.  Dual DDR2-667  5-5-5-15  511
P4  2800 MHz  MSI 848P Neo-S  i848P  DDR400 SDRAM  2.5-3-3-8  498
Celeron 420  1600 MHz  Intel DQ965GF  Q965 Int.  Dual DDR2-667  5-5-5-15  481
P4  2400 MHz  Abit SI7  SiSR658  Dual PC1066 RDRAM  -  429
2x E-350  1600 MHz  ASRock E350M1  A50M Int.  DDR3-1066 SDRAM  8-8-8-20 CR1  427
Nano L2200  1600 MHz  VIA VB8001  CN896 Int.  DDR2-667 SDRAM  5-5-5-15 CR2  400
Celeron D 326  2533 MHz  ASRock 775Twins-HDTV  RC410 Ext.  DDR2-533 SDRAM  4-4-4-11  400
2x Opteron 240  1400 MHz  MSI K8D Master3-133 FS  AMD8100  Dual DDR400R  3-4-4-8 CR1  376
2x Atom D2500  1866 MHz  Intel D2500CC  NM10 Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  364
Opteron 248  2200 MHz  MSI K8T Master1-FAR  K8T800  Dual DDR266R  2-3-3-6 CR1  361
Celeron  2000 MHz  Gigabyte GA-8TRS350MT  RS350 Int.  Dual DDR400  2-2-4-6 CR1  360
Athlon64 3200+  2000 MHz  ASRock 939S56-M  SiS756  Dual DDR400  2.5-3-3-8 CR2  328
Celeron  1700 MHz  Asus P4B  i845  PC133 SDRAM  3-3-3-6  305
P4  1600 MHz  Abit TH7II  i850  Dual PC800 RDRAM  -  287
AthlonXP 3200+  2200 MHz  Asus A7N8X-E  nForce2-U400  Dual DDR400  2.5-4-4-8 CR1  278
Sempron 2600+  1600 MHz  ASRock K8NF4G-SATA2  GeForce6100 Int.  DDR400 SDRAM  2.5-3-3-8 CR2  264
Pentium M 730  1600 MHz  AOpen i915Ga-HFS  i915G Int.  Dual DDR2-533  4-4-4-12  206
Duron  1600 MHz  MSI KT6V-LSR  KT600  DDR400 SDRAM  3-3-3-8 CR2  203
2x PIII-S  1266 MHz  MSI Pro266TD Master-LR  ApolloPro266TD  DDR266 SDRAM  2-3-3-6 CR2  188
AthlonXP 1600+  1400 MHz  Acorp 7KMM1  KM133A Int.  PC133 SDRAM  3-3-3-6  177
Athlon  1400 MHz  PCChips M817LMR  MAGiK1  DDR266 SDRAM  2-2-2-6  176
Celeron 215  1333 MHz  Intel D201GLY  SiS662 Int.  DDR2-533  5-4-4-12  170
Efficeon 8600  1000 MHz  ECS 532 Notebook  Efficeon  DDR266 SDRAM    162
Atom 230 HT  1600 MHz  Intel D945GCLF  i945GC Int.  DDR2-533 SDRAM  4-4-4-12  158
Celeron M 320  1300 MHz  DFI 855GME-MGF  i855GME Int.  DDR333 SDRAM  2.5-3-3-7  154
2x PIII-E  733 MHz  Tyan Thunder 2500  ServerSet3HE  PC133R SDRAM  3-3-3-6  113
Athlon  750 MHz  Epox EP-7KXA  KX133  PC133 SDRAM  3-3-3-6  94
C7  1500 MHz  VIA EPIA EN  CN700 Int.  DDR2-533 SDRAM  4-4-4-12 CR2  88
2x PIII  500 MHz  Epox KP6-BS  i440BX  PC100R SDRAM  3-3-3-?  78
Duron  600 MHz  Abit KG7-Lite  AMD-760  DDR200R SDRAM  2-2-2-5  76
Crusoe 5800  1000 MHz  ECS A530 DeskNote  Crusoe  DDR266 SDRAM    70
C3  1333 MHz  VIA EPIA SP  CN400 Int.  DDR400 SDRAM  3-3-3-8 CR2  62
Celeron  700 MHz  PCChips M758LT  SiS630ET Int.  PC100 SDRAM  3-3-3-6  54
2x PII  333 MHz  Intel DK440LX  i440LX  PC66 SDRAM  3-2-2-?  51
PIII  450 MHz  Asus P3C-S  i820  PC600 RDRAM  -  35
2x PentiumPro  200 MHz  Compaq ProLiant 800  i440FX  Dual EDO  -  31
C3  800 MHz  VIA EPIA  PLE133 Int.  PC133 SDRAM  3-3-3-6  26
2x PentiumMMX  200 MHz  Gigabyte GA-586DX  i430HX  Dual EDO  -  24
Celeron  266 MHz  Epox P2-100B  ApolloPro  PC66 SDRAM  3-2-2-5  21
K6-III  400 MHz  Epox EP-MVP3G-M  MVP3  PC100 SDRAM  2-2-2-5  16
K6-2  333 MHz  Amptron PM-9100LMR  SiS5597 Ext.  PC66 SDRAM  3-3-3-6  13
Pentium  166 MHz  Asus TX97-X  i430TX  PC66 SDRAM  2-2-3-4  10
K5 PR166  116 MHz  Asus P5A  ALADDiN5  PC66 SDRAM  2-2-2-6  5
MediaGXm  233 MHz  ALD NPC6836  Cx5520  PC60 SDRAM  3-3-3-6  3


FPU SinJulia

 
CPU  CPU Clock  Motherboard  Chipset  Memory  CL-RCD-RP-RAS  Score
16x Xeon E5-2670 HT  2600 MHz  Supermicro X9DR6-F  C600  Quad DDR3-1333  9-9-9-24  16009
6x Core i7-990X Extreme HT  3466 MHz  Intel DX58SO2  X58  Triple DDR3-1333  9-9-9-24 CR1  7493
6x Core i7-4930K HT  3400 MHz  Gigabyte GA-X79-UD3  X79  Quad DDR3-1866  9-10-9-27 CR2  7267
6x Core i7-3960X Extreme HT  3300 MHz  Intel DX79SI  X79  Quad DDR3-1600  9-9-9-24 CR2  7205
8x Xeon X5550 HT  2666 MHz  Supermicro X8DTN+  i5520  Triple DDR3-1333  9-9-9-24 CR1  7042
32x Opteron 6274  2200 MHz  Supermicro H8DGI-F  SR5690  Dual DDR3-1600R  11-11-11-28 CR1  6904
4x Core i7-3770K HT  3500 MHz  MSI Z77A-GD55  Z77 Int.  Dual DDR3-1600  9-9-9-24 CR2  4975
4x Core i7-2600 HT  3400 MHz  Asus P8P67  P67  Dual DDR3-1333  9-9-9-24 CR1  4672
12x Opteron 2431  2400 MHz  Supermicro H8DI3+-F  SR5690  Unganged Dual DDR2-800R  6-6-6-18 CR1  4657
4x Core i7-965 Extreme HT  3200 MHz  Asus P6T Deluxe  X58  Triple DDR3-1333  9-9-9-24 CR1  4633
4x Xeon E3-1245 v3 HT  3400 MHz  Supermicro X10SAE  C226 Int.  Dual DDR3-1600  11-11-11-28 CR1  4577
8x Xeon E5462  2800 MHz  Intel S5400SF  i5400  Quad DDR2-640FB  5-5-5-15  4135
6x Phenom II X6 Black 1100T  3300 MHz  Gigabyte GA-890GPA-UD3H v2  AMD890GX Int.  Unganged Dual DDR3-1333  9-9-9-24 CR2  3215
8x Opteron 2378  2400 MHz  Tyan Thunder n3600R  nForcePro-3600  Unganged Dual DDR2-800R  6-6-6-18 CR1  3104
8x FX-8350  4000 MHz  Asus M5A99X Evo R2.0  AMD990X  Dual DDR3-1866  9-10-9-27 CR2  2847
8x FX-8150  3600 MHz  Asus M5A97  AMD970  Dual DDR3-1866  9-10-9-27 CR2  2668
8x Xeon L5320  1866 MHz  Intel S5000VCL  i5000V  Dual DDR2-533FB  4-4-4-12  2594
2x Core i5-650 HT  3200 MHz  Supermicro C7SIM-Q  Q57 Int.  Dual DDR3-1333  9-9-9-24 CR1  2314
4x Xeon X3430  2400 MHz  Supermicro X8SIL-F  i3420  Dual DDR3-1333  9-9-9-24 CR1  2271
4x Core 2 Extreme QX9650  3000 MHz  Gigabyte GA-EP35C-DS3R  P35  Dual DDR3-1066  8-8-8-20 CR2  2221
8x Opteron 2344 HE  1700 MHz  Supermicro H8DME-2  nForcePro-3600  Unganged Dual DDR2-667R  5-5-5-15 CR1  2208
4x Phenom II X4 Black 940  3000 MHz  Asus M3N78-EM  GeForce8300 Int.  Ganged Dual DDR2-800  5-5-5-18 CR2  1939
4x A8-3850  2900 MHz  Gigabyte GA-A75M-UD2H  A75 Int.  Dual DDR3-1333  9-9-9-24 CR1  1872
4x Core 2 Extreme QX6700  2666 MHz  Intel D975XBX2  i975X  Dual DDR2-667  5-5-5-15  1859
4x Xeon 5140  2333 MHz  Intel S5000VSA  i5000V  Dual DDR2-667FB  5-5-5-15  1619
4x A10-6800K  4100 MHz  Gigabyte GA-F2A85X-UP4  A85X Int.  Dual DDR3-2133  9-11-10-27 CR2  1482
4x Phenom X4 9500  2200 MHz  Asus M3A  AMD770  Ganged Dual DDR2-800  5-5-5-18 CR2  1422
4x A10-5800K  3800 MHz  Asus F2A55-M  A55 Int.  Dual DDR3-1866  9-10-9-27 CR2  1378
4x Opteron 2210 HE  1800 MHz  Tyan Thunder h2000M  BCM5785  Dual DDR2-600R  5-5-5-15 CR1  1179
2x Athlon64 X2 Black 6400+  3200 MHz  MSI K9N SLI Platinum  nForce570SLI  Dual DDR2-800  4-4-4-11 CR1  1049
2x Core 2 Extreme X6800  2933 MHz  Abit AB9  P965  Dual DDR2-800  5-5-5-18 CR2  1023
2x Pentium EE 955 HT  3466 MHz  Intel D955XBK  i955X  Dual DDR2-667  4-4-4-11  962
2x Xeon HT  3400 MHz  Intel SE7320SP2  iE7320  Dual DDR333R  2.5-3-3-7  941
2x Core 2 Duo P8400  2266 MHz  MSI MegaBook PR201  GM45 Int.  Dual DDR2-667  5-5-5-15  831
4x Atom Z3740  1866 MHz  [ TRIAL VERSION ]  BayTrailT Int.  Dual DDR3-1066  8-10-8-32 CR1  727
2x Athlon64 X2 4000+  2100 MHz  ASRock ALiveNF7G-HDready  nForce7050-630a Int.  Dual DDR2-700  5-5-5-18 CR2  685
2x Core Duo T2500  2000 MHz  Asus N4L-VM DH  i945GT Int.  Dual DDR2-667  5-5-5-15  663
2x Xeon  3066 MHz  Asus PCH-DL  i875P + PAT  Dual DDR333  2.5-3-3-7  658
P4EE HT  3733 MHz  Intel SE7230NH1LX  iE7230  Dual DDR2-667  5-5-5-15  516
2x E-350  1600 MHz  ASRock E350M1  A50M Int.  DDR3-1066 SDRAM  8-8-8-20 CR1  505
2x Opteron 240  1400 MHz  MSI K8D Master3-133 FS  AMD8100  Dual DDR400R  3-4-4-8 CR1  458
2x Pentium D 820  2800 MHz  Abit Fatal1ty F-I90HD  RS600 Int.  Dual DDR2-800  5-5-5-18 CR2  453
2x PIII-S  1266 MHz  MSI Pro266TD Master-LR  ApolloPro266TD  DDR266 SDRAM  2-3-3-6 CR2  421
P4EE  3466 MHz  ASRock 775Dual-880Pro  PT880Pro  Dual DDR2-400  3-3-3-8 CR2  370
Opteron 248  2200 MHz  MSI K8T Master1-FAR  K8T800  Dual DDR266R  2-3-3-6 CR1  361
AthlonXP 3200+  2200 MHz  Asus A7N8X-E  nForce2-U400  Dual DDR400  2.5-4-4-8 CR1  357
Athlon64 3200+  2000 MHz  ASRock 939S56-M  SiS756  Dual DDR400  2.5-3-3-8 CR2  328
P4  2800 MHz  MSI 848P Neo-S  i848P  DDR400 SDRAM  2.5-3-3-8  299
Nano X2 L4350  1600 MHz  VIA EPIA-M900  VX900H Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  286
Celeron 420  1600 MHz  Intel DQ965GF  Q965 Int.  Dual DDR2-667  5-5-5-15  278
Pentium M 730  1600 MHz  AOpen i915Ga-HFS  i915G Int.  Dual DDR2-533  4-4-4-12  272
Sempron 2600+  1600 MHz  ASRock K8NF4G-SATA2  GeForce6100 Int.  DDR400 SDRAM  2.5-3-3-8 CR2  263
2x Atom D2500  1866 MHz  Intel D2500CC  NM10 Int.  DDR3-1066 SDRAM  7-7-7-20 CR2  261
Duron  1600 MHz  MSI KT6V-LSR  KT600  DDR400 SDRAM  3-3-3-8 CR2  261
P4  2400 MHz  Abit SI7  SiSR658  Dual PC1066 RDRAM  -  258
2x PIII-E  733 MHz  Tyan Thunder 2500  ServerSet3HE  PC133R SDRAM  3-3-3-6  238
AthlonXP 1600+  1400 MHz  Acorp 7KMM1  KM133A Int.  PC133 SDRAM  3-3-3-6  227
Athlon  1400 MHz  PCChips M817LMR  MAGiK1  DDR266 SDRAM  2-2-2-6  225
Celeron M 320  1300 MHz  DFI 855GME-MGF  i855GME Int.  DDR333 SDRAM  2.5-3-3-7  224
Celeron 215  1333 MHz  Intel D201GLY  SiS662 Int.  DDR2-533  5-4-4-12  221
Celeron  2000 MHz  Gigabyte GA-8TRS350MT  RS350 Int.  Dual DDR400  2-2-4-6 CR1  216
Atom 230 HT  1600 MHz  Intel D945GCLF  i945GC Int.  DDR2-533 SDRAM  4-4-4-12  206
Celeron D 326  2533 MHz  ASRock 775Twins-HDTV  RC410 Ext.  DDR2-533 SDRAM  4-4-4-11  204
Celeron  1700 MHz  Asus P4B  i845  PC133 SDRAM  3-3-3-6  188
P4  1600 MHz  Abit TH7II  i850  Dual PC800 RDRAM  -  169
2x PIII  500 MHz  Epox KP6-BS  i440BX  PC100R SDRAM  3-3-3-?  163
Nano L2200  1600 MHz  VIA VB8001  CN896 Int.  DDR2-667 SDRAM  5-5-5-15 CR2  131
Athlon  750 MHz  Epox EP-7KXA  KX133  PC133 SDRAM  3-3-3-6  121
Celeron  700 MHz  PCChips M758LT  SiS630ET Int.  PC100 SDRAM  3-3-3-6  114
2x PII  333 MHz  Intel DK440LX  i440LX  PC66 SDRAM  3-2-2-?  109
Efficeon 8600  1000 MHz  ECS 532 Notebook  Efficeon  DDR266 SDRAM    106
Duron  600 MHz  Abit KG7-Lite  AMD-760  DDR200R SDRAM  2-2-2-5  96
PIII  450 MHz  Asus P3C-S  i820  PC600 RDRAM  -  74
Crusoe 5800  1000 MHz  ECS A530 DeskNote  Crusoe  DDR266 SDRAM    71
2x PentiumMMX  200 MHz  Gigabyte GA-586DX  i430HX  Dual EDO  -  65
2x PentiumPro  200 MHz  Compaq ProLiant 800  i440FX  Dual EDO  -  65
K6-III  400 MHz  Epox EP-MVP3G-M  MVP3  PC100 SDRAM  2-2-2-5  51
C7  1500 MHz  VIA EPIA EN  CN700 Int.  DDR2-533 SDRAM  4-4-4-12 CR2  46
Celeron  266 MHz  Epox P2-100B  ApolloPro  PC66 SDRAM  3-2-2-5  43
K6-2  333 MHz  Amptron PM-9100LMR  SiS5597 Ext.  PC66 SDRAM  3-3-3-6  41
C3  1333 MHz  VIA EPIA SP  CN400 Int.  DDR400 SDRAM  3-3-3-8 CR2  36
Pentium  166 MHz  Asus TX97-X  i430TX  PC66 SDRAM  2-2-3-4  27
C3  800 MHz  VIA EPIA  PLE133 Int.  PC133 SDRAM  3-3-3-6  21
MediaGXm  233 MHz  ALD NPC6836  Cx5520  PC60 SDRAM  3-3-3-6  17
K5 PR166  116 MHz  Asus P5A  ALADDiN5  PC66 SDRAM  2-2-2-6  6


Debug - PCI

 
B00 D00 F00:  Intel Bay Trail-T SoC - Transaction Router
  
Offset 000:  86 80 00 0F 07 00 00 00 09 00 00 06 00 00 00 00
Offset 010:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 020:  00 00 00 00 00 00 00 00 00 00 00 00 43 10 ED 14
Offset 030:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 040:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 050:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 060:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 070:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 080:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 090:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0A0:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0B0:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0C0:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0D0:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0E0:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0F0:  55 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
 
B00 D02 F00:  Intel Bay Trail-T SoC - Integrated Graphics Controller
  
Offset 000:  86 80 31 0F 07 04 10 00 09 00 00 03 00 00 00 00
Offset 010:  00 00 00 90 00 00 00 00 08 00 00 80 00 00 00 00
Offset 020:  01 10 00 00 00 00 00 00 00 00 00 00 43 10 ED 14
Offset 030:  00 00 00 00 D0 00 00 00 00 00 00 00 00 01 00 00
Offset 040:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 050:  11 02 00 00 00 00 00 00 00 00 00 00 01 00 F0 7A
Offset 060:  00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 070:  01 00 D0 7A 07 00 00 00 00 00 00 00 00 00 00 00
Offset 080:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 090:  05 B0 01 00 0C F0 E0 FE 85 49 00 00 00 00 00 00
Offset 0A0:  00 00 00 00 13 00 06 03 00 00 00 00 00 00 00 00
Offset 0B0:  09 00 07 01 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0C0:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0D0:  01 90 22 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0E0:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0F0:  00 00 00 00 00 00 00 00 D1 0F 01 00 00 00 00 00
 
B00 D14 F00:  Intel Bay Trail SoC - USB 3.0 xHCI Host Controller
  
Offset 000:  86 80 35 0F 06 04 90 02 09 30 03 0C 00 00 00 00
Offset 010:  04 00 80 90 00 00 00 00 00 00 00 00 00 00 00 00
Offset 020:  00 00 00 00 00 00 00 00 00 00 00 00 43 10 ED 14
Offset 030:  00 00 00 00 70 00 00 00 00 00 00 00 00 01 00 00
Offset 040:  FD 01 04 80 8F C6 CF 03 00 00 00 00 00 00 00 00
Offset 050:  5F 6E CE 0B 00 00 00 00 00 00 00 00 00 00 00 00
Offset 060:  30 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 070:  01 80 C2 C1 08 00 00 00 00 00 00 00 00 00 00 00
Offset 080:  05 00 B7 00 0C F0 E0 FE 00 00 00 00 B8 49 00 00
Offset 090:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0A0:  00 01 04 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0B0:  8F 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0C0:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0D0:  3F 00 00 00 3F 00 00 00 01 00 00 00 01 00 00 00
Offset 0E0:  30 2C 00 00 00 00 00 00 00 00 00 00 D8 D8 00 00
Offset 0F0:  00 00 00 00 00 00 00 00 1A 0F 09 01 00 00 00 00
 
B00 D1A F00:  Intel Bay Trail SoC - Trusted Execution Engine
  
Offset 000:  86 80 18 0F 00 05 10 00 09 00 80 10 00 00 00 00
Offset 010:  00 00 70 90 00 00 60 90 00 00 00 00 00 00 00 00
Offset 020:  00 00 00 00 00 00 00 00 00 00 00 00 43 10 ED 14
Offset 030:  00 00 00 00 80 00 00 00 00 00 00 00 00 01 00 00
Offset 040:  C5 00 00 1F 00 40 00 80 00 00 00 69 00 00 00 00
Offset 050:  41 00 F0 3E 04 01 00 00 00 00 00 00 00 00 00 00
Offset 060:  00 00 00 10 01 00 00 00 00 00 00 00 00 00 00 00
Offset 070:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 080:  01 A0 03 48 0B 01 00 00 00 00 00 00 01 00 00 00
Offset 090:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0A0:  05 00 00 00 0C F0 E0 FE B3 49 00 00 00 00 00 00
Offset 0B0:  00 00 00 40 02 00 00 00 00 00 00 00 00 00 00 00
Offset 0C0:  09 10 00 00 00 00 F0 7E 00 00 00 01 00 00 00 00
Offset 0D0:  09 10 00 00 00 00 F0 7F 00 10 00 00 00 00 00 00
Offset 0E0:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0F0:  00 00 00 00 00 00 00 00 1A 0F 09 01 00 00 00 00
 
B00 D1F F00:  Intel Bay Trail SoC - Platform Controller Unit - LPC Controller
  
Offset 000:  86 80 1C 0F 07 01 10 02 09 00 01 06 00 00 80 00
Offset 010:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 020:  00 00 00 00 00 00 00 00 00 00 00 00 43 10 ED 14
Offset 030:  00 00 00 00 E0 00 00 00 00 00 00 00 00 00 00 00
Offset 040:  03 04 00 00 02 30 D0 FE 03 05 00 00 02 C0 D0 FE
Offset 050:  02 80 D0 FE 02 10 D0 FE 02 00 F0 FE 02 50 D0 FE
Offset 060:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 070:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 080:  01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 090:  01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0A0:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0B0:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0C0:  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0D0:  00 00 00 00 00 00 00 00 CF FF 00 00 00 00 00 00
Offset 0E0:  09 00 0C 10 00 00 00 00 00 00 00 00 00 00 00 00
Offset 0F0:  01 C0 D1 FE 00 00 00 00 1A 0F 09 01 03 03 00 00


Debug - Video BIOS

 
C000:0000  ..C%.F.K.......-.8.."....%Nzo.3......P.@.V.C..P..?|....SZ.E....
C000:0040  ..S%.F.K.......-.).."....%nzo.3......P.@.V.a..P..?\....Sz.E....
C000:0080  ....L....~...?Rw.B...0..)......f....$.....~.w.?..uu.r.=6b.5.R.-.
C000:00C0  ....L.......?Rw.B...0..)......f....$.....^.w.?..tq.r.=6b.5.R.-.
C000:0100  ...`?...R.-...k..;h.....+`..*.}..k<}...^i+.]:......*$....{<u...
C000:0140  ...`?...R.....o..;x.....+@..*.}..k<}...^i+.]:...!..*$....K<u...
C000:0180  CB.I.p...uo.=;.nA3.Q..0t.........e+.Ay.!........Z...6.s.f...9X.
C000:01C0  OB.I.p...uO.=;.f@3.Q..0t.........e+.Ay.)........^...6.s.f...9X.
C000:0200  ..f...y...SE.~......'..........:n......k:N.O.{FQ..S.a..j7Z.U.~..
C000:0240  ..f...y..[SE.v......'..........:.......k:N.O.sFQ..S.a..j3z.U.~..
C000:0280  RE-*^A+H/..,@...............eP.@v.?.F.'.....[.)%..J.........J.!.
C000:02C0  R.-*^A+H+..,@.............Z.eP.@2...F.'.E.&.[.)%..Z.........J.!.
C000:0300  .\.f-w...P.@2t.R..c....+]..g.gJ[.........qs.q..6..k...Z/..K,mB..
C000:0340  .\.F-w...P.@2t.R..c....+]..g.gJ[U......&.qs.q..6......Z/..K,mB..
C000:0380  ...o..@.f..)....u.:.T..d..t...}!A.....H......T.B....9....G....T.
C000:03C0  ...o..@.f..)..M.y.8.T..d..t...}!I.....H......T.B....9....F....T.


Debug - Unknown

 
BIOS  Unknown
HDD  Hynix HCG8e
Monitor ID  CMN1001: Generic PnP Monitor [NoDB]
Monitor Model  N101BCG-GK1
PnP  BCM2E39: Broadcom Serial Bus Driver over UART Bus Enumerator [NoDB]
PnP  INT33F0: Camera Sensor MT9M114 [NoDB]
SPD  No SPD module found! (BusCount = 0)
SSD  Hynix HCG8e




The names of actual companies and products mentioned herein may be the trademarks of their respective owners.